Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

43.2k stars2.5k forksBSD-3-Clauselast commit Actively maintained

NetBird is a cloud-managed, WireGuard-based zero-trust networking service that creates encrypted overlay networks to connect users and devices. It provides access control, device management, SSO integration, and secure remote access to private resources.
Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

43.2k stars2.5k forksBSD-3-Clauselast commit Actively maintained
Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

26.8k stars2.6k forksAGPL-3.0last commit Actively maintained
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

22.5k stars765 forkslast commit Actively maintained
Open-source VPN client for desktop and mobile that can automatically set up a private VPN server and connect using WireGuard, OpenVPN, IKEv2, and obfuscated modes.

14.7k stars1.1k forksGPL-3.0last commit Actively maintained
iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

8k stars596 forksISClast commit Slowing down
OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

4.4k stars266 forksApache-2.0last commit Actively maintained
Self-hosted web dashboard for WireGuard and AmneziaWG to manage configs, peers, and access with a simple UI and optional 2FA.
3.7k stars452 forksApache-2.0last commit Actively maintained
Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

2.1k stars188 forksApache-2.0last commit Actively maintained
Self-hosted ingress platform that exposes internal HTTP/TCP services to the internet through reverse WireGuard tunnels, with NGINX routing and automatic TLS certificates.

1.6k stars77 forksApache-2.0last commit Actively maintained
Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 8 of 9 shipped a commit in the last six months. Licences in this list: BSD-3-Clause, AGPL-3.0, GPL-3.0, ISC, Apache-2.0. In exchange you take on hosting, backups and updates yourself.
Browse everything in Network Security (VPN, Firewall, WAF).