Perimeter 81 logo

17 self-hosted Perimeter 81 alternatives

Cloud-based network security platform providing Zero Trust Network Access (ZTNA), cloud VPN, firewall and secure web gateway capabilities. Centralizes access policy management, network segmentation and secure remote access to corporate resources with identity integrations.

Alternatives to Perimeter 81

Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

Headscale screenshot

43.2k stars2.5k forksBSD-3-Clauselast commit Actively maintained

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

NetBird screenshot

28.7k stars1.6k forkslast commit Actively maintained

Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

wg-easy screenshot

26.8k stars2.6k forksAGPL-3.0last commit Actively maintained

Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

Pangolin screenshot

22.5k stars765 forkslast commit Actively maintained

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

OAuth2 Proxy screenshot

14.9k stars2.2k forksMITlast commit Actively maintained

Open-source VPN client for desktop and mobile that can automatically set up a private VPN server and connect using WireGuard, OpenVPN, IKEv2, and obfuscated modes.

Amnezia screenshot

14.7k stars1.1k forksGPL-3.0last commit Actively maintained

OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.

OpenVPN screenshot

14.4k stars3.4k forkslast commit Actively maintained

Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

Firezone screenshot

9k stars450 forksApache-2.0last commit Actively maintained

iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

iodine screenshot

8k stars596 forksISClast commit Slowing down

Self-hosted transparent bastion host and PAM for SSH, HTTPS, MySQL and Postgres with RBAC, session recording, and SSO/2FA—no client-side software required.

Warpgate screenshot

7.7k stars356 forksApache-2.0last commit Actively maintained

OPNsense is an open source FreeBSD-based firewall and routing platform with a web GUI, API, VPN, traffic shaping, and security features for networks and homelabs.

OPNsense screenshot

4.7k stars983 forksBSD-2-Clauselast commit Actively maintained

OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

OpenZiti screenshot

4.4k stars266 forksApache-2.0last commit Actively maintained

Self-hosted web dashboard for WireGuard and AmneziaWG to manage configs, peers, and access with a simple UI and optional 2FA.

3.7k stars452 forksApache-2.0last commit Actively maintained

Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

Defguard screenshot

2.8k stars110 forkslast commit Actively maintained

Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

ShellHub screenshot

2.1k stars188 forksApache-2.0last commit Actively maintained

Self-hosted ingress platform that exposes internal HTTP/TCP services to the internet through reverse WireGuard tunnels, with NGINX routing and automatic TLS certificates.

Wiredoor screenshot

1.6k stars77 forksApache-2.0last commit Actively maintained

What replacing Perimeter 81 actually involves

Every option on this page is open source and free to run on your own hardware, so you own the data and there is no subscription to cancel. 16 of 17 shipped a commit in the last six months. Licences in this list: BSD-3-Clause, AGPL-3.0, Apache-2.0, MIT, GPL-3.0. In exchange you take on hosting, backups and updates yourself.

Browse everything in Network Security (VPN, Firewall, WAF).

Other tools people replace alongside Perimeter 81