
Firezone
Zero-trust remote access platform built on WireGuard
9k stars 450 forks last commit first released Apache-2.0
Actively maintained
Last commit 27 Aug 2026.

Firezone is an open source zero-trust access platform designed to replace traditional VPNs with identity-aware, least-privilege connectivity. It uses WireGuard-based tunnels and a gateway/relay architecture to securely connect users to specific resources instead of whole networks.
Key Features
- Granular, group-based access policies for applications, subnets, and networks
- Peer-to-peer, end-to-end encrypted tunnels with NAT traversal (hole punching)
- Lightweight gateway component deployable in your infrastructure
- Optional relay (STUN/TURN) to facilitate connectivity when direct paths fail
- SSO and identity provider integration, including OIDC-based authentication
- Admin portal for managing users, resources, and policies
- Audit/activity logging for visibility and compliance needs
Use Cases
- Secure access to internal web apps, databases, and services without exposing networks
- Remote workforce connectivity as an alternative to OpenVPN-style VPN deployments
- Contractor or partner access with strict, least-privilege, policy-based controls
Limitations and Considerations
- Production self-hosting is not officially supported and internal APIs may change rapidly
- Officially distributed clients may not always be compatible with a custom self-hosted control plane build
Firezone fits teams that want a modern, identity-aware approach to private access with WireGuard performance characteristics and centralized policy management. It is especially useful when you need to reduce broad network access while keeping connectivity fast and manageable.
Categories:
Tags:
Tech Stack:
Similar to Firezone

Defguard
Zero-trust WireGuard VPN with protocol-level MFA and integrated SSO
Enterprise-grade zero-trust access management platform providing WireGuard VPN with true protocol-level 2FA/MFA, plus integrated OpenID Connect SSO and user/device controls.

Pangolin
Identity-aware VPN and reverse proxy for secure remote access
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

NetBird
WireGuard-based overlay network with SSO/MFA and granular access controls.
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

OpenCloud
Open source file sharing and collaboration platform
OpenCloud is an open source platform for file management, secure sharing, sync, and team collaboration with modern authentication and access controls.
Pomerium
Identity- and context-aware access proxy for zero trust access
Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

OpenZiti
Open-source zero trust networking overlay for applications
OpenZiti is an open-source zero trust networking platform that builds an identity-based overlay mesh with SDKs, tunnelers, and policy-based access controls.






