For un réseau mesh WireGuard auto-hébergé, the strongest matches are easytier/easytier (EasyTier is a self-hostable, decentralized peer-to-peer mesh VPN that), juanfont/headscale (Headscale is a self-hosted control plane that implements WireGuard-based) and tonarino/innernet (Innernet is a self-hostable WireGuard mesh orchestrator that automates). gravitl/netmaker and netbirdio/netbird round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Logiciels open source pour construire des réseaux peer-to-peer décentralisés et chiffrés afin de connecter les serveurs et les infrastructures privées en toute sécurité.
EasyTier is a decentralized peer-to-peer virtual private network and mesh networking tool. It functions as a layer 3 network overlay that establishes secure tunnels between devices without requiring a centralized server or coordinator. It also serves as a WireGuard-compatible VPN, capable of acting as a server for standard WireGuard clients. The project distinguishes itself through multipath latency-based routing and the use of KCP or QUIC proxies to mitigate packet loss and stabilize connections in high-loss environments. It provides a virtual networking manager featuring a web management co
EasyTier is a self-hostable, decentralized peer-to-peer mesh VPN that uses WireGuard-compatible tunnels and handles automatic connectivity and NAT traversal, making it exactly what you need for securely linking multiple servers in a private overlay network.
Headscale is a self-hosted control plane for private mesh networking that enables the creation of secure, encrypted peer-to-peer networks. By acting as a centralized coordination server, it manages device authentication, cryptographic key exchange, and network topology, allowing distributed infrastructure to communicate without relying on third-party services. It implements a zero-trust security architecture, verifying device and user identity before granting access to internal resources. The project distinguishes itself by providing a fully independent, self-hosted alternative for managing n
Headscale is a self-hosted control plane that implements WireGuard-based mesh networking with automatic key management, NAT traversal, and zero-trust security, directly matching the need for a private overlay VPN connecting multiple servers.
Innernet is a WireGuard VPN mesh orchestrator and control plane that automates the deployment of encrypted tunnels between distributed peers. It functions as a virtual private network that coordinates endpoint discovery and distributes network configurations from a centralized server to establish a private overlay network. The system differentiates itself through a structured peer management lifecycle, using single-use invitation files for secure onboarding and cryptographic key exchange. It provides granular network segmentation by organizing peers into named CIDR blocks, allowing administra
Innernet is a self-hostable WireGuard mesh orchestrator that automates encrypted peer-to-peer tunnels with invitation-based onboarding and CIDR-based segmentation, exactly matching your need for a private overlay network with key management and NAT traversal support.
Netmaker is a platform for automating and managing virtual mesh networks built on WireGuard. It functions as a centralized control plane that orchestrates encrypted, peer-to-peer tunnels across distributed infrastructure, including cloud environments, on-premise data centers, and containerized clusters. By automating the configuration of routing tables and access policies, the system enables secure, private connectivity between diverse devices and services without requiring manual network administration. The platform distinguishes itself through its focus on zero-trust network access and soft
Netmaker is a self-hosted platform that builds WireGuard-based mesh networks with automatic peer-to-peer tunnels, key management, and NAT traversal, making it a comprehensive fit for connecting servers in a private overlay network.
NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce
NetBird builds secure, encrypted peer-to-peer overlay networks using WireGuard with automatic mesh connectivity and NAT traversal, fitting your self-hosted server-to-server mesh VPN need.
Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted mesh network. By utilizing a high-performance, user-space implementation of the WireGuard protocol, it establishes secure peer-to-peer tunnels across diverse network topologies without requiring complex firewall configuration. The platform operates on a centralized control plane that manages global network state, authentication, and policy distribution, ensuring that connectivity is governed by identity rather than traditional IP-based rules. What distinguishes Tailscale is it
Tailscale is a WireGuard-based mesh VPN for connecting servers and devices into a private overlay network, but it relies on Tailscale's proprietary cloud control plane rather than being fully self-hostable, so it meets the mesh VPN requirement but not the self-hosting aspect.