Firezone logo

Firezone

Website

Zero-trust remote access platform built on WireGuard

9k stars 450 forks last commit first released Apache-2.0

Actively maintained

Last commit 27 Aug 2026.

Firezone screenshot

Firezone is an open source zero-trust access platform designed to replace traditional VPNs with identity-aware, least-privilege connectivity. It uses WireGuard-based tunnels and a gateway/relay architecture to securely connect users to specific resources instead of whole networks.

Key Features

  • Granular, group-based access policies for applications, subnets, and networks
  • Peer-to-peer, end-to-end encrypted tunnels with NAT traversal (hole punching)
  • Lightweight gateway component deployable in your infrastructure
  • Optional relay (STUN/TURN) to facilitate connectivity when direct paths fail
  • SSO and identity provider integration, including OIDC-based authentication
  • Admin portal for managing users, resources, and policies
  • Audit/activity logging for visibility and compliance needs

Use Cases

  • Secure access to internal web apps, databases, and services without exposing networks
  • Remote workforce connectivity as an alternative to OpenVPN-style VPN deployments
  • Contractor or partner access with strict, least-privilege, policy-based controls

Limitations and Considerations

  • Production self-hosting is not officially supported and internal APIs may change rapidly
  • Officially distributed clients may not always be compatible with a custom self-hosted control plane build

Firezone fits teams that want a modern, identity-aware approach to private access with WireGuard performance characteristics and centralized policy management. It is especially useful when you need to reduce broad network access while keeping connectivity fast and manageable.

Categories:

Tags:

Tech Stack:

Share:

Similar to Firezone

Defguard logo

Defguard

Zero-trust WireGuard VPN with protocol-level MFA and integrated SSO

2.8k
110
Last commit

Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

Actively maintained
Alternative to:
Defguard Cloud logo
Defguard Cloud
+19
Pangolin logo

Pangolin

Identity-aware VPN and reverse proxy for secure remote access

22.5k
765
Last commit

Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

Actively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+16
NetBird logo

NetBird

WireGuard-based overlay network with SSO/MFA and granular access controls.

28.7k
1.6k
Last commit

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

Actively maintained
Alternative to:
Tailscale logo
Tailscale
+17
OpenCloud logo

OpenCloud

Open source file sharing and collaboration platform

5.9k
234
Last commit

OpenCloud is an open source platform for file management, secure sharing, sync, and team collaboration with modern authentication and access controls.

Apache-2.0Actively maintained
Alternative to:
Dropbox logo
Dropbox
+19

Pomerium

Identity- and context-aware access proxy for zero trust access

5k
350
Last commit

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Apache-2.0Actively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+12
OpenZiti logo

OpenZiti

Open-source zero trust networking overlay for applications

4.4k
266
Last commit

OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.

Apache-2.0Actively maintained
Alternative to:
Zscaler Private Access logo
Zscaler Private Access
+14