Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

42.2k stars2.4k forksBSD-3-Clauselast commit Actively maintained
Cloud-delivered Security Service Edge (SSE)/SASE platform that provides zero trust network access (ZTNA), secure web gateway (SWG), CASB, and VPN-as-a-Service to protect users, devices, and applications; includes identity integration and monitoring.
Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

42.2k stars2.4k forksBSD-3-Clauselast commit Actively maintained
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

27.8k stars1.5k forkslast commit Actively maintained
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

21.9k stars745 forkslast commit Actively maintained
CLI tool to create Cloudflare Tunnels and route traffic through Cloudflare’s edge.

15k stars1.4k forksApache-2.0last commit Actively maintained
OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

14.8k stars2.2k forksMITlast commit Actively maintained
OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.

14.3k stars3.4k forkslast commit Actively maintained
Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

8.9k stars436 forksApache-2.0last commit Actively maintained
iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

7.9k stars596 forksISClast commit Slowing down
Self-hosted transparent bastion host and PAM for SSH, HTTPS, MySQL and Postgres with RBAC, session recording, and SSO/2FA—no client-side software required.

7.4k stars317 forksApache-2.0last commit Actively maintained
OPNsense is an open source FreeBSD-based firewall and routing platform with a web GUI, API, VPN, traffic shaping, and security features for networks and homelabs.

4.5k stars975 forksBSD-2-Clauselast commit Actively maintained
OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

4.3k stars262 forksApache-2.0last commit Actively maintained
Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

2.8k stars107 forkslast commit Actively maintained
Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

2k stars186 forksApache-2.0last commit Actively maintained
Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 12 of 13 shipped a commit in the last six months. Licences in this list: BSD-3-Clause, Apache-2.0, MIT, ISC, BSD-2-Clause. In exchange you take on hosting, backups and updates yourself.
Browse everything in Network Security (VPN, Firewall, WAF).