Appgate SDP logo

13 self-hosted Appgate SDP alternatives

Cloud-delivered Software-Defined Perimeter (SDP) and Zero Trust Network Access (ZTNA) platform that enforces identity-centric, policy-based access to applications and infrastructure. Provides direct-routed, low-latency remote access, API integrations, and enterprise-scale management.

Alternatives to Appgate SDP

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

NetBird screenshot

28.7k stars1.6k forkslast commit Actively maintained

Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

Pangolin screenshot

22.5k stars765 forkslast commit Actively maintained

Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.

Teleport screenshot

20.9k stars2.1k forksAGPL-3.0last commit Actively maintained

OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.

OpenVPN screenshot

14.4k stars3.4k forkslast commit Actively maintained

Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

Firezone screenshot

9k stars450 forksApache-2.0last commit Actively maintained

iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

iodine screenshot

8k stars596 forksISClast commit Slowing down

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Pomerium screenshot

5k stars350 forksApache-2.0last commit Actively maintained

Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

Defguard screenshot

2.8k stars110 forkslast commit Actively maintained

Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

ShellHub screenshot

2.1k stars188 forksApache-2.0last commit Actively maintained

#11

Single-binary TLS reverse proxy for self-hosted apps that provides SSH- and Telegram-based authorization, simple SSO, Let's Encrypt support and whitelist access control.

188 stars9 forksGPL-3.0last commit Likely dormant

A minimal, Rust-based forward authentication middleware for reverse proxies (Traefik, Caddy, nginx) using a passwd file and signed auth tokens.

157 stars8 forksMITlast commit Actively maintained

Advanced SSH server and bastion that authenticates via OpenID Connect or keys, runs sessions inside Docker containers or Kubernetes pods, and supports automatic user provisioning.

Engity's Bifröst screenshot

83 stars2 forksApache-2.0last commit Actively maintained

What replacing Appgate SDP actually involves

Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 11 of 13 shipped a commit in the last six months. Licences in this list: AGPL-3.0, Apache-2.0, ISC, GPL-3.0, MIT. In exchange you take on hosting, backups and updates yourself.

Browse everything in Network Security (VPN, Firewall, WAF).

Other tools people replace alongside Appgate SDP