
Firezone
Zero-trust remote access platform built on WireGuard

Firezone is an open source zero-trust access platform designed to replace traditional VPNs with identity-aware, least-privilege connectivity. It uses WireGuard-based tunnels and a gateway/relay architecture to securely connect users to specific resources instead of whole networks.
Key Features
- Granular, group-based access policies for applications, subnets, and networks
- Peer-to-peer, end-to-end encrypted tunnels with NAT traversal (hole punching)
- Lightweight gateway component deployable in your infrastructure
- Optional relay (STUN/TURN) to facilitate connectivity when direct paths fail
- SSO and identity provider integration, including OIDC-based authentication
- Admin portal for managing users, resources, and policies
- Audit/activity logging for visibility and compliance needs
Use Cases
- Secure access to internal web apps, databases, and services without exposing networks
- Remote workforce connectivity as an alternative to OpenVPN-style VPN deployments
- Contractor or partner access with strict, least-privilege, policy-based controls
Limitations and Considerations
- Production self-hosting is not officially supported and internal APIs may change rapidly
- Officially distributed clients may not always be compatible with a custom self-hosted control plane build
Firezone fits teams that want a modern, identity-aware approach to private access with WireGuard performance characteristics and centralized policy management. It is especially useful when you need to reduce broad network access while keeping connectivity fast and manageable.
Categories:
Tags:
Tech Stack:
Similar Services

Pi-hole
Network-wide DNS sinkhole for ad and tracker blocking
Pi-hole is a network-wide DNS sinkhole that blocks ads and trackers for all devices on your network, with a web dashboard, query logs, and optional DHCP server.

Headscale
Self-hosted control server for Tailscale-based WireGuard networks
Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

AdGuard Home
Network-wide DNS server that blocks ads, trackers, phishing and malware
Open-source DNS-based ad & tracker blocking server for networks. Offers per-device rules, parental controls, encrypted upstream DNS (DoH/DoT/DNSCrypt), web UI and API.

Web-Check
All-in-one OSINT tool for analyzing any website.
Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

wg-easy
WireGuard VPN server with a web-based admin interface
Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

NetBird
WireGuard-based overlay network with SSO/MFA and granular access controls.
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.
Swift
Kotlin
Docker
TypeScript
Phoenix (Elixir)
Rust