Not quite. Every device is its own npub, but given a master key, encryption etc it’s pretty easy to coordinate the sharing of these keys.
Then the actually traffic is identified via deterministic noise in the packet prior to decrypting which is where I was thinking about the firewall.
Although that bit I would need to build and test
