For an open source virtual private network solution, the strongest matches are openvpn/openvpn (OpenVPN provides a robust, self-hostable server and multi-platform client), amnezia-vpn/amnezia-client (Amnezia Client is a cross-platform VPN client and server) and softethervpn/softethervpn (SoftEtherVPN is a robust, self-hostable multi-protocol VPN server and). easytier/easytier and slackhq/nebula round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
We curate open-source GitHub repositories matching “open source alternatives to nordvpn”. Results are ranked by relevance to your query — pick filters below to narrow, or refine with AI.
OpenVPN is a cross-platform networking solution that establishes secure virtual private network connections by wrapping data traffic within encrypted tunnels. It functions as a server-side application that authenticates remote endpoints and routes encrypted traffic to provide access to private network resources across untrusted public networks. The software utilizes standard cryptographic protocols to perform mutual authentication and key exchange over a dedicated control channel. It verifies the identity of remote systems through certificate-based authentication, ensuring that only trusted e
OpenVPN provides a robust, self-hostable server and multi-platform client solution with encrypted tunneling, though it lacks built-in mesh networking and native kill switches out of the box.
Amnezia Client is a cross-platform VPN client application and server orchestrator designed to manage secure tunnels and automate the deployment of containerized VPN services on remote self-hosted servers. It functions as a multi-protocol VPN manager that supports various tunneling standards to ensure connectivity across restrictive network environments. The project distinguishes itself through network traffic obfuscation, which disguises VPN traffic as common web protocols or DNS requests to bypass deep packet inspection and censorship. It further enables the automation of remote server admin
Amnezia Client is a cross-platform VPN client and server orchestrator that automates self-hosted server deployment and supports encrypted tunneling with split tunneling features, though it relies on underlying protocols rather than providing a native mesh network.
SoftEtherVPN is a multi-protocol virtual private network server that provides secure remote access and site-to-site connectivity. It functions as a virtual network gateway, enabling encrypted communication across public internet connections while supporting both Layer 2 Ethernet bridging and Layer 3 IP routing to manage traffic between connected devices. The platform is designed to maintain connectivity in restrictive network environments by bypassing firewalls and NAT devices through techniques such as HTTPS, ICMP, and DNS-based tunneling. It eliminates the requirement for static public IP a
SoftEtherVPN is a robust, self-hostable multi-protocol VPN server and client solution with encrypted tunneling and firewall bypass capabilities, though it lacks native peer-to-peer mesh networking.
EasyTier is a decentralized peer-to-peer virtual private network and mesh networking tool. It functions as a layer 3 network overlay that establishes secure tunnels between devices without requiring a centralized server or coordinator. It also serves as a WireGuard-compatible VPN, capable of acting as a server for standard WireGuard clients. The project distinguishes itself through multipath latency-based routing and the use of KCP or QUIC proxies to mitigate packet loss and stabilize connections in high-loss environments. It provides a virtual networking manager featuring a web management co
EasyTier is a decentralized peer-to-peer virtual private network and mesh networking tool that provides encrypted tunneling and cross-platform clients, though it functions primarily as a serverless overlay rather than a traditional centralized VPN service.
Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer connections between distributed hosts. By utilizing a certificate-based identity authority, it enables the construction of private communication fabrics across disparate physical infrastructures, such as multiple cloud providers or on-premises data centers, without requiring central authentication servers. The project distinguishes itself through a zero-trust architecture that enforces granular, policy-driven firewall filtering based on certificate-derived group memberships. It facili
Nebula is a scalable, decentralized overlay networking tool providing encrypted peer-to-peer tunnels and cross-platform clients, though it is designed more as a mesh networking fabric than a traditional commercial VPN alternative.
Headscale is a self-hosted control plane for private mesh networking that enables the creation of secure, encrypted peer-to-peer networks. By acting as a centralized coordination server, it manages device authentication, cryptographic key exchange, and network topology, allowing distributed infrastructure to communicate without relying on third-party services. It implements a zero-trust security architecture, verifying device and user identity before granting access to internal resources. The project distinguishes itself by providing a fully independent, self-hosted alternative for managing n
Headscale provides a self-hosted control plane and server solution for encrypted peer-to-peer mesh networking using WireGuard, though it functions as a Tailscale control server rather than an all-in-one standalone client suite.
Oblivion is an encrypted tunneling service and internet privacy tool designed to route network traffic through private encrypted tunnels. It functions as a network privacy gateway that masks user identity and encrypts web traffic to prevent tracking and unauthorized surveillance. The project acts as a secure network proxy that combines end-to-end encryption with latency-optimized routing to increase data throughput and reduce network lag. This infrastructure allows for the masking of a device's public identity by relaying connections through a private network. The system provides capabilitie
Oblivion is an encrypted tunneling tool that provides privacy-focused network routing, though it serves more as a client/proxy solution rather than a complete self-hostable server and mesh networking suite.
Historical monolithic WireGuard repository, split into wireguard-tools, wireguard-linux, and wireguard-linux-compat.
WireGuard provides the foundational cryptographic tunnel protocol for self-hostable server and multi-platform client setups, serving as the core engine behind many modern private VPN solutions.
NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce
NetBird is a zero-trust mesh VPN platform built on WireGuard that provides encrypted tunneling and multi-platform client support, functioning as a self-hostable alternative to traditional VPN services.
PiVPN is an automated VPN deployer and server manager designed to establish secure gateways for remote network access. It provides a command-line tool for the installation and configuration of WireGuard and OpenVPN servers on Linux systems, with specific optimizations for single-board computers like the Raspberry Pi. The project distinguishes itself through a wrapper-based management interface that abstracts complex server commands into simplified operations. This includes automated handling of firewall rules, port forwarding, and package installation, as well as the ability to export client
PiVPN is a self-hostable VPN server installer and management utility that sets up WireGuard or OpenVPN tunnels, fitting the server side of the search though it relies on external clients.
This project is a containerized IPsec VPN server designed to provide secure remote network access. It functions as an IKEv2 VPN gateway, utilizing the StrongSwan daemon to manage security associations and establish encrypted tunnels between remote clients and a private network. The server acts as a certificate-based VPN manager, handling the generation and distribution of digital certificates and pre-shared keys to authenticate remote users. It includes tools for IKEv2 client management to automate the creation of configuration profiles and security keys for connecting devices. The system co
This project is a containerized IPsec VPN server that provides encrypted tunneling and self-hosted server deployment, though it lacks the peer-to-peer mesh networking and built-in client features requested by the visitor.
Algo is a cloud VPN deployment tool and WireGuard orchestrator designed to automate the provisioning and configuration of personal VPN servers across multiple cloud infrastructure providers. It functions as a multi-cloud infrastructure provisioner and a VPN client configuration generator, creating the necessary tunnels and connection profiles for secure device connectivity. The project distinguishes itself by integrating a network ad-blocking DNS server directly into the deployment, filtering advertisements and malicious domains for all connected clients. It further simplifies the onboarding
Algo automates the secure deployment and configuration of self-hosted VPN servers and client profiles using WireGuard, though it functions as a provisioning tool rather than an ongoing mesh network manager.
Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted mesh network. By utilizing a high-performance, user-space implementation of the WireGuard protocol, it establishes secure peer-to-peer tunnels across diverse network topologies without requiring complex firewall configuration. The platform operates on a centralized control plane that manages global network state, authentication, and policy distribution, ensuring that connectivity is governed by identity rather than traditional IP-based rules. What distinguishes Tailscale is it
Tailscale provides a secure, WireGuard-based encrypted tunneling and peer-to-peer mesh networking solution that serves as an alternative to traditional commercial VPNs, though its centralized control plane relies on managed infrastructure rather than a purely self-hostable server.
Brook is a cross-platform proxy server designed to secure network traffic and manage multi-user access. It functions as a proxy manager that facilitates connectivity across diverse hardware architectures, including desktop, mobile, and router environments. The system distinguishes itself through integrated identity and administrative controls, utilizing email-based token authentication to verify users and enforce granular, role-based access policies. It also provides a white-label build pipeline that allows for the customization of client application branding, enabling the replacement of defa
Brook is a cross-platform proxy and VPN solution that offers encrypted tunneling and multi-platform client support, though it operates primarily as a proxy-based tool rather than a full peer-to-peer mesh network.
This project is an automated command-line tool designed to install and configure a secure network gateway on a host machine. By utilizing established open-source security protocols, it establishes a private tunnel endpoint that encrypts internet traffic and facilitates remote access connectivity for authorized users. The tool functions as an infrastructure lifecycle manager, streamlining the deployment of private network services through shell-script-based orchestration. It distinguishes itself by integrating directly with the Linux kernel to manage packet filtering rules and providing creden
This project provides scripts to quickly self-host an IPsec VPN server with encrypted tunneling, though it acts as a deployment tool rather than offering a complete multi-platform client suite or mesh networking.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| openvpn/openvpn | 13.3K | C | other | |
| amnezia-vpn/amnezia-client | 10.1K | C++ | gpl-3.0 | |
| softethervpn/softethervpn | 13K | C | apache-2.0 | |
| easytier/easytier | 12K | Rust | LGPL-3.0 | |
| slackhq/nebula | 17.4K | Go | MIT | |
| juanfont/headscale | 40.1K | Go | BSD-3-Clause | |
| bepass-org/oblivion | 4.7K | Java | — | |
| wireguard/wireguard | 2.3K | C | GPL-2.0 | |
| netbirdio/netbird | 26.2K | Go | NOASSERTION | |
| pivpn/pivpn | 8K | Shell | MIT |