Why NAT gets in the way
Most computers sit behind network address translation (NAT): a router that shares one public address among many private ones and only lets in packets that answer a connection started from inside. Two machines on different home or office networks therefore cannot simply open a connection to each other: each router drops the other side's first packet.
How hard the problem is depends on the router. RFC 4787 describes how NATs map and filter UDP traffic: when a router reuses the same public port for every destination, a direct path is usually easy to find; when it picks a new port for each destination (often called symmetric NAT), it is much harder.
How hole punching works
NAT traversal is the set of techniques that find a direct path anyway. First, each side learns how it looks from the outside, usually by asking a STUN server. The two sides exchange these candidate addresses through a coordination server, then both send packets towards each other at the same time. Each router sees an outgoing packet first and treats the reply as part of that flow, so a path opens in both directions. RFC 5128 surveys these techniques.
Routers can also be asked directly: UPnP IGD, NAT-PMP and its successor, the Port Control Protocol (RFC 6887), let an application request a port mapping. Some corporate firewalls and carrier-grade NAT defeat every technique. When nothing works, the session falls back to a relay that forwards traffic between the two sides.
How Vexaro Desk connects
A Vexaro Desk session connects directly wherever the network allows, and through an authenticated Vexaro relay when it doesn't. There is nothing to configure: the client finds a path on its own.
The installer adds a Windows Firewall rule so direct and local-network connections can work; a portable copy cannot add one, so its sessions are more likely to be relayed. Direct connections can be switched off in Settings, and the session window shows whether a session is direct or relayed. Direct sessions are end-to-end encrypted. When a network forces a relayed connection, traffic stays encrypted in transit through Vexaro-operated relays.