17 repositorios
Technologies and protocols for establishing private, encrypted network tunnels to access services without public exposure.
Distinguishing note: Focuses on secure connectivity and tunneling rather than general network management.
Explore 17 awesome GitHub repositories matching networking & communication · Secure Remote Access. Refine with filters or upvote what's useful.
Khoj is a self-hosted artificial intelligence platform designed for personal knowledge management and semantic information retrieval. It functions as a private assistant that indexes your local documents, notes, and external workspaces, allowing you to interact with your data through natural language queries and conversational chat. By maintaining a local-first architecture, the system ensures that your information remains under your control while providing context-aware responses grounded in your personal knowledge base. The platform distinguishes itself through a modular, cross-platform int
Khoj establishes secure, private network connections between devices to access self-hosted services remotely without exposing them to the public internet.
NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce
Exposes internal applications to authorized users through secure tunnels without public internet exposure.
Awesome Tunneling is a curated directory of technologies designed to facilitate secure connectivity between distributed devices and local services. It serves as a comprehensive resource for identifying tools that enable remote access, private network creation, and the exposure of local environments to the public internet. The collection focuses on solutions that bypass network address translation and firewall restrictions through techniques such as reverse proxy tunneling, overlay network infrastructure, and peer-to-peer connectivity. It categorizes resources based on their ability to establi
Controls access to internal services by creating secure gateways that verify user identity.
Claude Code Templates is a comprehensive framework for orchestrating specialized AI agents and automating development workflows within local environments. It provides a structured system for defining, configuring, and deploying AI personas that handle specific technical tasks, ranging from backend architecture and frontend implementation to security auditing and infrastructure management. The project distinguishes itself through a configuration-driven approach that allows teams to standardize development environments and share reusable agent definitions across projects. It includes a robust C
Establishes encrypted connections to local dashboards and services to enable remote monitoring and management from any device.
This project is a bash-based installation script and deployer used to automate the setup and configuration of an OpenVPN server on Linux systems. It provides a guided setup process for deploying virtual private network software across various Debian and Red Hat based distributions. The tool functions as a user management interface, allowing for the creation, removal, and administration of client profiles and the security credentials required for network access. It orchestrates the deployment of secure tunnels to enable remote network access to private environments. The system manages the ins
Establishes secure, encrypted network tunnels to enable remote access to private home or office networks.
Chisel is a network tunneling tool that facilitates secure communication by encapsulating TCP and UDP traffic within HTTP requests. It functions as a connection multiplexer, consolidating multiple logical network streams into a single persistent connection to improve throughput and reduce overhead. By leveraging standard web protocols, the system enables firewall traversal and provides a mechanism for remote port forwarding and proxying. The project distinguishes itself through its focus on resilient connectivity and granular access control. It maintains persistent network sessions across uns
Exposes local services to remote networks through encrypted tunnels over standard web connections.
This project provides a shell-based automation utility for deploying and managing OpenVPN servers on Linux hosts. It functions as an orchestration tool that handles the installation of networking software, the configuration of system-level routing rules, and the generation of cryptographic credentials required to establish secure, encrypted tunnels for remote network access. The tool distinguishes itself by automating the entire lifecycle of a private network gateway, including the management of peer identities and the distribution of standardized configuration profiles. It simplifies the set
Enables secure remote access by routing device traffic through encrypted private tunnels.
SoftEtherVPN is a multi-protocol virtual private network server that provides secure remote access and site-to-site connectivity. It functions as a virtual network gateway, enabling encrypted communication across public internet connections while supporting both Layer 2 Ethernet bridging and Layer 3 IP routing to manage traffic between connected devices. The platform is designed to maintain connectivity in restrictive network environments by bypassing firewalls and NAT devices through techniques such as HTTPS, ICMP, and DNS-based tunneling. It eliminates the requirement for static public IP a
Creates encrypted tunnels over public internet connections to allow remote users to access private resources securely.
This project is a shell-based orchestration tool designed to automate the deployment and administration of WireGuard virtual private network servers on Linux hosts. It functions as a system-level networking utility that handles the installation of kernel modules, the configuration of secure tunnel interfaces, and the management of network routing rules to enable encrypted remote access. The tool provides an interactive command-line interface that simplifies the lifecycle management of network peers. It allows administrators to dynamically add or remove client access profiles, assign custom DN
Configures encrypted connections for remote clients to ensure private internet browsing and safe access to internal resources.
This project is a GitOps infrastructure framework designed for managing bare metal servers, container clusters, and networking. It serves as a declarative system for orchestrating the deployment and lifecycle of self-hosted services, using Git as the source of truth to synchronize the desired state of the environment. The framework differentiates itself through a comprehensive automation suite that covers the entire hardware-to-service pipeline. It includes a PXE-based bare metal provisioner for network booting and operating system installation, alongside a lightweight container orchestration
Establishes encrypted network tunnels to provide secure remote administrative access to the internal network.
GOAD is an Ansible-based automation tool and infrastructure orchestrator used to deploy pre-configured networks of vulnerable Windows virtual machines. It serves as a security training environment for practicing Active Directory penetration testing, privilege escalation, and lateral movement across various cloud platforms and local virtualization hypervisors. The project distinguishes itself through a multi-provider infrastructure model and a system of infrastructure recipes that simulate intentional security misconfigurations. It supports the deployment of varied attack scenarios, including
Establishes a secure shell connection to a management machine to route attack traffic into isolated segments.
This project is a containerized IPsec VPN server designed to provide secure remote network access. It functions as an IKEv2 VPN gateway, utilizing the StrongSwan daemon to manage security associations and establish encrypted tunnels between remote clients and a private network. The server acts as a certificate-based VPN manager, handling the generation and distribution of digital certificates and pre-shared keys to authenticate remote users. It includes tools for IKEv2 client management to automate the creation of configuration profiles and security keys for connecting devices. The system co
Provides secure, encrypted network tunnels to allow remote users to access private network resources.
SmarGate is a network utility designed as an intranet penetration tool, peer-to-peer network tunnel, and remote device management gateway. It functions as a system for bypassing NAT and firewalls to expose internal services to the public internet, while also providing SOCKS5 and HTTP proxy capabilities and SSL/TLS encrypted tunnels. The project distinguishes itself by implementing hybrid routing that combines direct peer-to-peer TCP links with cloud-based proxy relaying to reduce latency. It features real-time dynamic port mapping that allows network redirections to be updated via a mobile cl
Connects to internal servers and databases from remote locations using encrypted SSL/TLS network tunnels.
Otto es una plataforma de orquestación de nube híbrida diseñada para aprovisionar infraestructura y desplegar cargas de trabajo de aplicaciones a través de diversos entornos de nube utilizando infraestructura como código. Funciona como un aprovisionador de infraestructura como código que automatiza el despliegue de recursos consistentes a través de flujos de trabajo basados en políticas. El proyecto incluye una malla de servicios (service mesh) de nube híbrida para gestionar el descubrimiento de servicios y la comunicación segura entre aplicaciones, así como un controlador de acceso basado en identidad para gestionar secretos y aplicar controles de acceso granulares. También cuenta con un grafo de conocimiento de infraestructura que mapea los estados híbridos para visualizar dependencias e identificar oportunidades de remediación operativa. La plataforma cubre amplias áreas de capacidad, incluyendo la entrega automatizada de aplicaciones para microservicios y aplicaciones monolíticas, aprovisionamiento de infraestructura de nube híbrida y acceso seguro a la red mediante proxy consciente de la identidad. Además, proporciona herramientas para gestionar imágenes de máquinas y orquestar el escalado de cargas de trabajo a través de varios entornos.
Provides identity-aware proxying for secure connectivity to private resources without public internet exposure.
This project is an Android VPN client and privacy-focused network tool. It serves as a secure tunneling application designed to encrypt internet traffic and mask IP addresses on Android devices. The application provides mobile privacy protection by routing network traffic through a secure VPN infrastructure. It enables remote network access and secure connectivity for public Wi-Fi usage to mask device identity and location.
Enables secure remote access to private networks via encrypted tunnels.
Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,
Provides secure access to AI servers using client-based tunnels or clientless browser access.
WireGuard Manager is a system orchestration tool designed to automate the deployment, configuration, and lifecycle management of virtual private network infrastructure. It functions by translating high-level user intent into precise, declarative system configurations, managing kernel-level network interfaces, and enforcing firewall-based traffic control to ensure secure, isolated network routing. The project distinguishes itself by providing a centralized web-based management interface that abstracts the complexity of manual configuration files. It includes comprehensive administrative tools
Establishes encrypted remote access tunnels to private infrastructure for secure and reliable connectivity.