Attack Vector against relay nodes from client machines run by Investigators

I’m reading this thread.

One thing it seems to me like is that relay nodes are used only for requests. Then I thought about this:

Now, the question becomes: is this handled on an individual basis, or do the NAE/Client managers become the endpoints with the relay nodes fixed? Almost like the managers function as a router (WAN) and the relay-client pair are on the private (LAN) side of things. That’s one thing that’s never been clear to me - if that happens for just requests, or both requests and receptions.