For a software tool for network traffic routing, the first results are projectcalico/calico, cloudflare/boringtun and softethervpn/softethervpn (SoftEtherVPN is a multi-protocol VPN server that includes some Layer 3 routing and bridging, but it is not a dedicated routing daemon—it lacks the dynamic routing protocols BGP, OSPF, etc. and policy-based routing that this search requires for managing network routing protocols). qdm12/gluetun and angristan/openvpn-install round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
We curate open-source GitHub repositories matching “network routing tools”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.
Calico is a cloud-native networking and security solution designed to connect containerized workloads across virtual machines, bare metal, and multi-cloud environments. It provides a routing solution based on the Border Gateway Protocol to manage cluster traffic and implement the Container Network Interface for pod connectivity and IP address management. The project distinguishes itself through a security layer that enforces network policies based on identities and labels rather than static addresses. It includes a policy engine for controlling traffic flow, a cluster network encryptor for se
Calico is a cloud-native networking solution that uses BGP for routing and includes a policy engine for traffic control, fitting the intent for managing routing protocols and policies, though it is focused on containerized environments and lacks support for protocols like OSPF or SNMP monitoring.
Boringtun is a Rust-based library and userspace implementation of the WireGuard protocol. It provides the necessary logic to establish encrypted network tunnels and route secure traffic across different operating systems without requiring kernel-level administrative privileges. The project is designed for embedding VPN logic into other applications. It achieves this through a C-compatible binary interface and cross-platform native bindings, allowing other programming languages to incorporate tunnel operations and peer management into their own software.
Boringtun is a WireGuard VPN tunnel library and userspace implementation, not a routing daemon — it handles encrypted tunnels but does not implement dynamic routing protocols like BGP or OSPF, nor does it provide policy-based routing, route redistribution, or a management interface for routing policies.
SoftEtherVPN is a multi-protocol virtual private network server that provides secure remote access and site-to-site connectivity. It functions as a virtual network gateway, enabling encrypted communication across public internet connections while supporting both Layer 2 Ethernet bridging and Layer 3 IP routing to manage traffic between connected devices. The platform is designed to maintain connectivity in restrictive network environments by bypassing firewalls and NAT devices through techniques such as HTTPS, ICMP, and DNS-based tunneling. It eliminates the requirement for static public IP a
SoftEtherVPN is a multi-protocol VPN server that includes some Layer 3 routing and bridging, but it is not a dedicated routing daemon—it lacks the dynamic routing protocols (BGP, OSPF, etc.) and policy-based routing that this search requires for managing network routing protocols.
Gluetun is a containerized network utility designed to route traffic from multiple Docker containers through a secure virtual private network tunnel. It functions as a network gateway that encapsulates outgoing internet traffic to provide privacy and security for isolated application services. The project distinguishes itself by utilizing Linux network namespaces to isolate container traffic, ensuring that all outgoing packets are forced through a dedicated tunnel interface. It supports both OpenVPN and WireGuard protocols, managing the connection lifecycle and routing logic as a sidecar cont
Gluetun routes Docker container traffic through VPN tunnels using OpenVPN and WireGuard, but it does not manage dynamic routing protocols (BGP, OSPF) or offer the policy-routing and redistribution features expected from a routing daemon.
This project provides a shell-based automation utility for deploying and managing OpenVPN servers on Linux hosts. It functions as an orchestration tool that handles the installation of networking software, the configuration of system-level routing rules, and the generation of cryptographic credentials required to establish secure, encrypted tunnels for remote network access. The tool distinguishes itself by automating the entire lifecycle of a private network gateway, including the management of peer identities and the distribution of standardized configuration profiles. It simplifies the set
This tool is a shell script for automating OpenVPN server installation, which handles VPN tunnel setup and basic routing, but it is not a routing daemon for implementing and managing dynamic routing protocols like BGP or OSPF.
OpenClash is a network traffic controller designed for embedded router hardware. It functions as a kernel-level traffic management solution that intercepts network packets to enforce user-defined routing policies and connectivity rules across home or office network environments. The project distinguishes itself through a comprehensive build and deployment pipeline tailored for diverse firmware architectures. It provides a cross-compilation environment that transforms source code into hardware-specific installation files, while also offering a package management system to handle the retrieval
OpenClash is a traffic controller for proxy-based routing on embedded routers, but it does not implement standard dynamic routing protocols like BGP or OSPF, making it a neighbouring tool rather than the routing daemon this search targets.
MetalLB is a Kubernetes load balancer implementation and IP address manager designed for bare metal clusters. It functions as a networking tool that provides external connectivity and traffic distribution by assigning external IPv4 and IPv6 addresses to services. The project differentiates itself by providing two distinct advertisement modes. It can operate as a BGP routing controller, using the Border Gateway Protocol to announce service IPs to external routers with support for bidirectional forwarding detection and VRF-aware routing. Alternatively, it can act as a Layer 2 network advertiser
MetalLB is a Kubernetes-specific load balancer that uses BGP to advertise service IPs, not a general-purpose routing daemon for managing protocols like OSPF or policy-based routing across multiple platforms.
Netch is a multi-protocol proxy client and network traffic interceptor designed to route internet traffic through VPN and proxy tunnels. It functions as a connection manager that tunnels outbound data to modify network paths and bypass network restrictions. The project supports a wide range of tunneling protocols, including Socks5, Shadowsocks, WireGuard, Trojan, VMess, and VLESS. It distinguishes itself by offering the ability to distribute established proxy connections to other devices on a local network and by providing UDP FullCone NAT support to maintain stable peer-to-peer connectivity
Netch is a proxy and VPN client that tunnels traffic through various protocols, not a routing daemon for managing BGP/OSPF or policy-based routing; it fits the network routing domain but lacks the core routing protocol features you need.
meta-rules-dat is a collection of binary-encoded network datasets used to identify and categorize traffic for routing on resource-constrained devices. It provides a structured domain categorization list and a geographic IP routing dataset to map network traffic to specific countries or service providers. The project utilizes trie-based lookup data and compact binary serialization to enable high-performance prefix matching and fast domain-to-category resolution. To minimize memory and storage overhead, it employs stripped-down GeoIP mapping that removes non-essential metadata. The datasets co
This repository provides binary-encoded datasets for traffic categorization and geographic IP routing, which can be consumed by routing software, but it is not itself a routing daemon or tool for implementing and managing dynamic routing protocols like BGP or OSPF.
Gluetun is a Docker VPN client gateway that routes network traffic from other containers through secure WireGuard or OpenVPN tunnels. It serves as a network gateway to mask origin IP addresses and provides a firewall kill switch that blocks all outbound traffic unless it is destined for the active VPN server. The project supports multiple commercial VPN providers and can maintain several simultaneous connections using custom configuration files. It includes an integrated proxy server stack hosting SOCKS5, HTTP, and Shadowsocks servers to tunnel TCP and UDP traffic. Security is managed throug
Gluetun is a VPN client gateway for routing container traffic through tunnels, but it does not implement dynamic routing protocols like BGP or OSPF, so it falls outside the core intent of a routing daemon.
This project provides a set of curated configuration rules and domain lists for the Shadowrocket app. It consists of network traffic routing rules, ad-blocking domain lists, DNS configuration profiles, and proxy bypass lists used to filter and direct network traffic. The rules establish policy-based routing logic to determine whether specific traffic is proxied, connected directly, or rejected. This includes specialized lists for proxy bypass management and the blocking of known advertising and tracking domains at the network level. The project covers a broad range of traffic management capa
This project provides curated configuration rules and domain lists for the Shadowrocket proxy app, not a routing daemon that implements dynamic routing protocols like BGP or OSPF — it is a rule collection, not the network-routing software you are looking for.
This project is a curated collection of deployment files and configurations for hosting a wide variety of open-source services on a home server. It primarily utilizes Docker and Docker Compose to automate the orchestration, lifecycle management, and deployment of containerized applications. The repository provides a comprehensive suite for self-hosted infrastructure, covering network management tools, media streaming, and home automation. It includes specialized configurations for securing internal services via reverse proxies, WireGuard VPN tunnels, and automated SSL/TLS certificate manageme
This repository is a curated collection of Docker deployment configurations for self-hosted services, not a standalone routing daemon. While it includes network‑management tools and VPN setups, it does not implement dynamic routing protocols (BGP, OSPF) or provide a CLI for routing policy management.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| projectcalico/calico | 7.3K | Go | Apache-2.0 | |
| cloudflare/boringtun | 7.1K | Rust | BSD-3-Clause | |
| softethervpn/softethervpn | 13K | C | apache-2.0 | |
| qdm12/gluetun | 13.1K | Go | mit | |
| angristan/openvpn-install | 15.6K | Shell | mit | |
| vernesong/openclash | 24.4K | HTML | mit | |
| metallb/metallb | 8.2K | Go | Apache-2.0 | |
| netchx/netch | 17.6K | C# | GPL-3.0 | |
| metacubex/meta-rules-dat | 3.8K | Shell | gpl-3.0 | |
| passteque/gluetun | 14.6K | Go | MIT |