awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
zerotier avatar

zerotier/ZeroTierOne

0
View on GitHub↗
16,459 stars·1,910 forks·C++·other·42 viewszerotier.com↗

ZeroTierOne

ZeroTierOne is a software-defined networking engine that creates virtual local area networks by emulating Ethernet switches across distributed devices. It functions as a peer-to-peer platform, establishing encrypted tunnels directly between endpoints to bypass the need for centralized gateways or hub-and-spoke architectures.

The system distinguishes itself through a decentralized approach to network discovery and identity management. By utilizing a distributed hash table and public key infrastructure, it authenticates devices and maps virtual addresses to physical endpoints without relying on centralized certificate authorities. Security is enforced at the individual device level, allowing for granular access control policies that remain consistent regardless of the physical network location.

The platform provides a user-space network stack that enables consistent behavior across diverse operating systems and hardware. It supports integration into applications for embedded networking, allows for deployment via containerization, and provides compatibility with mobile hardware. The software includes cryptographic standards designed to maintain security in sensitive environments.

Features

  • Peer-to-Peer Networking - Establishes secure, encrypted peer-to-peer tunnels between remote endpoints without requiring centralized gateway hardware.
  • Zero Trust Access - Enforces security rules and access controls directly at each device to remove the need for centralized network chokepoints.
  • Software-Defined Networking Services - Provides a software-defined networking engine that creates virtual Ethernet-like switches across distributed devices.
  • Virtual Local Area Networks - Connects distributed devices into a single peer-to-peer network that functions like a shared physical Ethernet switch.
  • Zero Trust Networking - Enforces granular access policies and cryptographic authentication directly at the device level for secure network communication.
  • Virtual Network Interfaces - Implements virtual network interfaces to enable seamless connectivity across diverse operating systems and hardware.
  • Virtual Private Networks - Establishes secure virtual private network connections for mobile hardware to allow remote devices to communicate as if locally attached.
  • Identity Management - Authenticates devices using public key infrastructure to verify peer identity without relying on centralized certificate authorities.
  • Userspace Network Stacks - Implements packet processing and protocol handling within the application layer for consistent network behavior across platforms.
  • Zero Trust Architectures - Enforces granular security policies directly on local devices to maintain consistent protection regardless of network location.
  • Overlay Networks - Layer 2 overlay network for decentralized device connectivity.
  • Virtualization Networking - Creates software-defined layer two network interfaces that allow remote devices to communicate as if connected to a local switch.
  • Network Access Control - Applies security rules and access controls directly at each device to remove the need for centralized network chokepoints.
  • Distributed Hash Tables - Locates network peers using a decentralized global lookup system to map virtual addresses to physical endpoints.
  • Network Policy Enforcement - Applies granular security rules and access control lists directly on local devices to ensure consistent protection.
  • Mobile Network Clients - Establishes secure virtual private network connections for mobile hardware to enable remote access to local networks.
  • Embedded Network Stacks - Integrates virtual network stacks directly into applications to grant exclusive access to private network interfaces.
  • Data Encryption - Protects network data using cryptographic standards designed to withstand future computing threats.

Star history

Star history chart for zerotier/zerotieroneStar history chart for zerotier/zerotierone

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does zerotier/zerotierone do?

ZeroTierOne is a software-defined networking engine that creates virtual local area networks by emulating Ethernet switches across distributed devices. It functions as a peer-to-peer platform, establishing encrypted tunnels directly between endpoints to bypass the need for centralized gateways or hub-and-spoke architectures.

What are the main features of zerotier/zerotierone?

The main features of zerotier/zerotierone are: Peer-to-Peer Networking, Zero Trust Access, Software-Defined Networking Services, Virtual Local Area Networks, Zero Trust Networking, Virtual Network Interfaces, Virtual Private Networks, Identity Management.

Which projects share features with zerotier/zerotierone?

Projects with overlapping indexed features include: netbirdio/netbird — NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the… slackhq/nebula — Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer… firezone/firezone — Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to… openziti/ziti — Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that… fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… shieldfy/api-security-checklist — This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a…

Projects sharing features with ZeroTierOne

These projects share indexed features with ZeroTierOne. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • netbirdio/netbirdnetbirdio avatar

    netbirdio/netbird

    26,188View on GitHub↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    Gogolangmeshmesh-networks
    View on GitHub↗26,188
  • slackhq/nebulaslackhq avatar

    slackhq/nebula

    17,405View on GitHub↗

    Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer connections between distributed hosts. By utilizing a certificate-based identity authority, it enables the construction of private communication fabrics across disparate physical infrastructures, such as multiple cloud providers or on-premises data centers, without requiring central authentication servers. The project distinguishes itself through a zero-trust architecture that enforces granular, policy-driven firewall filtering based on certificate-derived group memberships. It facili

    Go
    View on GitHub↗17,405
  • firezone/firezonefirezone avatar

    firezone/firezone

    8,701View on GitHub↗

    Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to internal network resources. It functions as a virtual private network that synchronizes authentication and user groups via OpenID Connect providers. The system implements a group-based access control engine to enforce least privilege by restricting network resources to specific user groups. It utilizes holepunching and relay protocols for NAT traversal to establish encrypted tunnels through firewalls without requiring inbound ports. The platform includes a control plane for managing

    Elixirclouddevsecopselixir
    View on GitHub↗8,701
  • openziti/zitiopenziti avatar

    openziti/ziti

    3,883View on GitHub↗

    Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet. The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend

    Goappsecgolangmesh
    View on GitHub↗3,883
Compare all 30 related projects→