Best Self-hosted Network Security (VPN, Firewall, WAF) tools in 2026

38 self-hosted open source alternatives in this category

38 services found

Pi-hole

Pi-hole

Network-wide DNS sinkhole for ad and tracker blocking

55.9k
3k
Last commit: 8d ago

Pi-hole is a network-wide DNS sinkhole that blocks ads and trackers for all devices on your network, with a web dashboard, query logs, and optional DHCP server.

Alternative to:
AdGuard
AdGuard
+7
Headscale

Headscale

Self-hosted control server for Tailscale-based WireGuard networks

35.8k
1.9k
Last commit: 5d ago

Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

Alternative to:
Tailscale
Tailscale
+9
AdGuard Home

AdGuard Home

Network-wide DNS server that blocks ads, trackers, phishing and malware

32.8k
2.3k
Last commit: 7h ago

Open-source DNS-based ad & tracker blocking server for networks. Offers per-device rules, parental controls, encrypted upstream DNS (DoH/DoT/DNSCrypt), web UI and API.

Alternative to:
AdGuard
AdGuard
+5
Web-Check

Web-Check

All-in-one OSINT tool for analyzing any website.

32.1k
2.5k
Last commit: 25d ago

Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

Alternative to:
Shodan
Shodan
+8
wg-easy

wg-easy

WireGuard VPN server with a web-based admin interface

24.7k
2.4k
Last commit: 2d ago

Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

Alternative to:
Tailscale
Tailscale
+14
NetBird

NetBird

WireGuard-based overlay network with SSO/MFA and granular access controls.

23.1k
1.1k
Last commit: 1d ago

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

Alternative to:
Tailscale
Tailscale
+17
SafeLine

SafeLine

Self-hosted WAF and reverse proxy for securing web apps

20.8k
1.3k
Last commit: 3mo ago

SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+7
Pangolin

Pangolin

Identity-aware VPN and reverse proxy for secure remote access

19.2k
578
Last commit: 18h ago

Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

Alternative to:
Cloudflare Access
Cloudflare Access
+16
Anubis

Anubis

Web AI firewall utility that challenges and blocks scraper bots

17.2k
506
Last commit: 6d ago

Anubis is a lightweight web AI firewall that protects sites from AI crawlers and scraping bots using configurable request challenges and bot policies.

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+10
Fail2Ban

Fail2Ban

Log-monitoring daemon that bans abusive IPs via firewall rules

17k
1.5k
Last commit: 13d ago

Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.

Alternative to:
CrowdSec
CrowdSec
OpenVPN

OpenVPN

Open-source VPN daemon for TLS-based secure tunneling

13.3k
3.3k
Last commit: 1d ago

OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.

Alternative to:
OpenVPN CloudConnexa
OpenVPN CloudConnexa
+18
Cloudflared

Cloudflared

Cloudflare Tunnel client to expose local services via Cloudflare's edge network.

13.2k
1.2k
Last commit: 1d ago

CLI tool to create Cloudflare Tunnels and route traffic through Cloudflare’s edge.

Alternative to:
ngrok
ngrok
+10
CrowdSec

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

12.6k
576
Last commit: 1d ago

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Alternative to:
Fail2Ban
Fail2Ban
+10
Amnezia

Amnezia

Cross-platform client to deploy and use your own VPN server

10.2k
720
Last commit: 1d ago

Open-source VPN client for desktop and mobile that can automatically set up a private VPN server and connect using WireGuard, OpenVPN, IKEv2, and obfuscated modes.

Alternative to:
NordVPN
NordVPN
+15
BunkerWeb

BunkerWeb

Open-source web application firewall and reverse proxy

10.1k
566
Last commit: 19d ago

BunkerWeb is an open-source WAF and NGINX-based reverse proxy to protect web apps and APIs with HTTPS automation, security policies, and extensible plugins.

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+10
MyIP (IPCheck.ing)

MyIP (IPCheck.ing)

Open-source IP toolbox for IP, DNS, WebRTC and network diagnostics

9.8k
1.1k
Last commit: 15d ago

MyIP (IPCheck.ing) is an open-source web IP toolbox that detects local/public IPs, runs DNS leak and WebRTC checks, speed/latency/MTR tests, availability and whois lookup...

Alternative to:
WhatIsMyIPAddress.com
WhatIsMyIPAddress.com
+10
Firezone

Firezone

Zero-trust remote access platform built on WireGuard

8.4k
403
Last commit: 7h ago

Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

Alternative to:
Tailscale
Tailscale
+11
iodine

iodine

IPv4-over-DNS tunneling server and client

7.7k
575
Last commit: 5mo ago

iodine is a DNS tunneling tool that forwards IPv4 traffic through DNS queries and replies, providing a TUN interface to route IP traffic when only DNS is allowed.

Alternative to:
Cloudflare Tunnel
Cloudflare Tunnel
+15
WatchYourLAN

WatchYourLAN

Lightweight LAN IP scanner with web UI, alerts, and metrics export

6.8k
235
Last commit: 5mo ago

Self-hosted lightweight LAN IP/ARP scanner with web dashboard, new-host notifications, online/offline history, and metrics export to Prometheus or InfluxDB for Grafana.

Alternative to:
Fing
Fing
+9
Warpgate

Warpgate

Transparent bastion and PAM for SSH, HTTPS, MySQL and PostgreSQL

6.6k
239
Last commit: 7d ago

Self-hosted transparent bastion host and PAM for SSH, HTTPS, MySQL and Postgres with RBAC, session recording, and SSO/2FA—no client-side software required.

Alternative to:
Teleport
Teleport
+7
ClamAV

ClamAV

Open-source antivirus engine for gateway and file scanning

6.3k
835
Last commit: 5d ago

ClamAV is an open-source antivirus toolkit providing a multi-threaded daemon, command-line scanners, and automatic signature updates for mail gateways and file scanning.

Alternative to:
McAfee
McAfee
+8
Cap

Cap

Privacy-first proof-of-work CAPTCHA alternative for web and APIs

4.9k
294
Last commit: 11d ago

Lightweight, self-hostable CAPTCHA alternative using SHA-256 proof-of-work challenges to protect forms and APIs from bots without tracking or visual puzzles.

Alternative to:
Google reCAPTCHA
Google reCAPTCHA
+8
OPNsense

OPNsense

Open source firewall and routing platform for network security

4.3k
911
Last commit: 15h ago

OPNsense is an open source FreeBSD-based firewall and routing platform with a web GUI, API, VPN, traffic shaping, and security features for networks and homelabs.

Alternative to:
Fortinet FortiGate
Fortinet FortiGate
+12
OpenZiti

OpenZiti

Open-source zero trust networking overlay for applications

3.9k
237
Last commit: 7h ago

OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

Alternative to:
Zscaler Private Access
Zscaler Private Access
+14
WGDashboard

WGDashboard

Web dashboard to manage and monitor WireGuard VPN

3.4k
404
Last commit: 13d ago

Self-hosted web dashboard for WireGuard and AmneziaWG to manage configs, peers, and access with a simple UI and optional 2FA.

Alternative to:
Tailscale
Tailscale
+15
Defguard

Defguard

Zero-trust WireGuard VPN with protocol-level MFA and integrated SSO

2.6k
88
Last commit: 8d ago

Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device contro...

Alternative to:
Defguard Cloud
Defguard Cloud
+19
ShellHub

ShellHub

Centralized SSH gateway for remote access and device management

1.9k
173
Last commit: 1d ago

Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session rec...

Alternative to:
Teleport
Teleport
+14
Maza ad blocking

Maza ad blocking

Local DNS-based ad blocker using your operating system

1.9k
72
Last commit: 3mo ago

Simple local ad blocker that updates your system hosts or dnsmasq rules to block ad and tracking domains across any browser or application.

Alternative to:
AdGuard
AdGuard
+5
UUSEC WAF

UUSEC WAF

Web application firewall and API security gateway (WAAP)

1.6k
159
Last commit: 3d ago

High-performance web application firewall and API security gateway with semantic detection, rule management, and reverse-proxy deployment for protecting websites and APIs...

Alternative to:
Cloudflare Web Application Firewall (WAF)
Cloudflare Web Application Firewall (WAF)
+9
Wiredoor

Wiredoor

Ingress-as-a-service to expose private services via WireGuard and NGINX

1.6k
74
Last commit: 18h ago

Self-hosted ingress platform that exposes internal HTTP/TCP services to the internet through reverse WireGuard tunnels, with NGINX routing and automatic TLS certificates.

Alternative to:
ngrok
ngrok
+13