## Summary
- add independent install options for internet routing, client-to-client
access, and explicit server-side networks
- enforce the selected policy across firewalld, nftables, and iptables,
including DCO traffic
- use destination-scoped NAT for home LAN access and preserve client
routes and DNS in split-tunnel mode
- document the new defaults and add focused Docker policy coverage
Defaults remain internet access enabled, client-to-client access
disabled, and server-side network access disabled.
Related: #1496#443#385#624#547#1436#1103#1126#575#1434#1213#147