For network access tools, the strongest matches are firezone/firezone (Firezone is a self-hostable zero-trust access platform that leverages), ngoduykhanh/wireguard-ui (This tool provides a web-based management interface for WireGuard) and zerotier/zerotierone (ZeroTier is a peer-to-peer software-defined networking engine that provides). gravitl/netmaker and openziti/ziti round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Find the best open-source network access control tools. We compare top GitHub repositories by activity and features to help you pick the right one.
Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to internal network resources. It functions as a virtual private network that synchronizes authentication and user groups via OpenID Connect providers. The system implements a group-based access control engine to enforce least privilege by restricting network resources to specific user groups. It utilizes holepunching and relay protocols for NAT traversal to establish encrypted tunnels through firewalls without requiring inbound ports. The platform includes a control plane for managing
Firezone is a self-hostable zero-trust access platform that leverages WireGuard for secure connectivity and includes robust features like identity-based access control, MFA support, and cross-platform clients.
wireguard-ui is a web-based management interface and configuration generator for WireGuard VPN servers. It provides an authenticated administrative dashboard that allows users to manage VPN tunnels and peer connections through a graphical interface instead of manually editing configuration files. The project automates the creation of cryptographic key pairs and produces connection files and QR codes for distributing network settings to clients. It includes tools for tracking client metadata, such as names and email addresses, to identify individual users associated with specific connection se
This tool provides a web-based management interface for WireGuard VPN servers, making it a practical utility for configuring and orchestrating secure remote access tunnels, though it functions as a management layer rather than a full zero-trust gateway.
ZeroTierOne is a software-defined networking engine that creates virtual local area networks by emulating Ethernet switches across distributed devices. It functions as a peer-to-peer platform, establishing encrypted tunnels directly between endpoints to bypass the need for centralized gateways or hub-and-spoke architectures. The system distinguishes itself through a decentralized approach to network discovery and identity management. By utilizing a distributed hash table and public key infrastructure, it authenticates devices and maps virtual addresses to physical endpoints without relying on
ZeroTier is a peer-to-peer software-defined networking engine that provides secure, encrypted remote access to private networks, functioning as a robust alternative to traditional VPNs for building virtual overlay networks.
Netmaker is a platform for automating and managing virtual mesh networks built on WireGuard. It functions as a centralized control plane that orchestrates encrypted, peer-to-peer tunnels across distributed infrastructure, including cloud environments, on-premise data centers, and containerized clusters. By automating the configuration of routing tables and access policies, the system enables secure, private connectivity between diverse devices and services without requiring manual network administration. The platform distinguishes itself through its focus on zero-trust network access and soft
Netmaker is a self-hostable platform that leverages WireGuard to create secure, zero-trust mesh networks, providing the exact remote access and tunneling capabilities required for distributed infrastructure.
Ziti is a zero-trust network overlay and identity-based mesh network. It provides a software-defined perimeter that replaces traditional IP-based routing and VPNs by mapping network services to cryptographically verified identities, effectively cloaking applications from the public internet. The project distinguishes itself through an outbound-only connection model that eliminates open listening ports and a Zero Trust SDK that allows developers to embed encryption and identity-based access control directly into application source code. It also provides transparent tunneling proxies to extend
Ziti is a comprehensive zero-trust network overlay that provides secure, identity-based remote access and tunneling capabilities, effectively serving as a modern alternative to traditional VPNs.
Pritunl is an enterprise VPN gateway and server manager used to deploy and configure OpenVPN and WireGuard servers through a centralized web interface. It functions as a VPN access control system and an SSH certificate authority, issuing short-lived signed certificates to manage secure shell access and network entry without manual public key distribution. The platform acts as an SSO integrated VPN controller, synchronizing user access and organization mapping with third-party identity providers via OAuth, OIDC, and SAML. It supports high-availability deployments by using database-backed clust
Pritunl is a robust, self-hostable VPN gateway that supports WireGuard and integrates with identity providers for secure access control, though it functions primarily as a managed VPN server rather than a zero-trust tunnel.
NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce
NetBird is a self-hostable, zero-trust networking platform that uses the WireGuard protocol to create secure, encrypted peer-to-peer tunnels with identity-based access control and cross-platform support.
Teleport is a zero-trust access platform designed to provide secure, identity-based connectivity to servers, databases, and Kubernetes clusters. It functions as a centralized gateway that replaces static credentials with short-lived, identity-bound cryptographic certificates, effectively eliminating the need for traditional VPNs and long-term secret exposure. The platform distinguishes itself by orchestrating access through a unified control plane that maps external identity provider claims to granular, role-based infrastructure permissions. It enforces security through mutual TLS gateways an
Teleport is a comprehensive zero-trust access platform that provides secure, identity-based connectivity to private infrastructure, effectively serving as a modern, self-hostable alternative to traditional VPNs with robust support for MFA and granular access control.
Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n
Pangolin is a self-hostable zero-trust network access platform that uses WireGuard for secure tunneling and integrates reverse proxy capabilities with identity-aware authentication to protect private services.
Wirehole is a containerized network stack that integrates a WireGuard VPN server with recursive DNS resolution and sinkhole-based advertisement filtering. It bundles these interdependent services into a single managed environment using a compose-based deployment. The system enables network-wide ad blocking and tracker filtering by intercepting DNS queries via a sinkhole. It implements recursive DNS resolution to resolve domain names independently of external upstream providers and provides a web-based interface for managing VPN client peers and keys. Additional capabilities include split-tun
Wirehole is a self-hostable VPN solution that uses the WireGuard protocol to provide secure remote access to private networks, though it focuses more on network-wide DNS filtering than on zero-trust access controls.
Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted mesh network. By utilizing a high-performance, user-space implementation of the WireGuard protocol, it establishes secure peer-to-peer tunnels across diverse network topologies without requiring complex firewall configuration. The platform operates on a centralized control plane that manages global network state, authentication, and policy distribution, ensuring that connectivity is governed by identity rather than traditional IP-based rules. What distinguishes Tailscale is it
Tailscale is a zero-trust networking overlay that uses the WireGuard protocol to create secure, encrypted mesh networks, providing a comprehensive solution for remote access that includes multi-factor authentication and cross-platform support.
Algo is a cloud VPN deployment tool and WireGuard orchestrator designed to automate the provisioning and configuration of personal VPN servers across multiple cloud infrastructure providers. It functions as a multi-cloud infrastructure provisioner and a VPN client configuration generator, creating the necessary tunnels and connection profiles for secure device connectivity. The project distinguishes itself by integrating a network ad-blocking DNS server directly into the deployment, filtering advertisements and malicious domains for all connected clients. It further simplifies the onboarding
Algo is a self-hostable VPN orchestrator that automates the deployment of WireGuard and IPsec servers, providing a secure way to access private networks despite lacking native zero-trust or reverse proxy features.
Rathole is a reverse proxy tunneling tool designed to expose local services behind firewalls and network address translation to the public internet. It functions as a secure tunneling infrastructure that enables remote access to private network resources without requiring manual router port forwarding configurations. The system utilizes a client-server architecture where a public-facing gateway coordinates with a private-network agent. It distinguishes itself by multiplexing multiple logical service connections through a single persistent TCP stream, which reduces the overhead of maintaining
Rathole is a self-hostable reverse proxy and tunneling tool that enables secure remote access to private services, fitting the category well despite lacking native WireGuard protocol support.
zrok is a zero trust networking service that provides a secure overlay mesh to expose local services and files through firewalls and NAT without the need for manual port forwarding. It functions as a zero trust network manager, orchestrating identities, policies, and routers to establish secure connectivity between applications and users. The project distinguishes itself through the use of identity-based routing and hardened HTTP frontends that integrate with external identity providers. These capabilities allow for the creation of identity-aware proxies and secure reverse proxies that authen
This tool provides a zero-trust overlay network for exposing local services and files through secure tunnels, fitting the category of remote access and network tunneling software.
OpenVPN is a cross-platform networking solution that establishes secure virtual private network connections by wrapping data traffic within encrypted tunnels. It functions as a server-side application that authenticates remote endpoints and routes encrypted traffic to provide access to private network resources across untrusted public networks. The software utilizes standard cryptographic protocols to perform mutual authentication and key exchange over a dedicated control channel. It verifies the identity of remote systems through certificate-based authentication, ensuring that only trusted e
OpenVPN is a foundational, self-hostable VPN solution that provides secure remote access to private networks, though it relies on its own established protocol rather than the WireGuard protocol requested.
Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,
Octelium is a zero-trust network access platform that provides secure, identity-aware tunneling for private resources, aligning well with the core requirements for remote access and secure service exposure.
This project is a high-performance reverse proxy designed to expose local services to the internet. It provides a comprehensive suite of tools for managing network traffic, including support for TCP and UDP stream multiplexing, connection pooling, and load balancing across proxy instances. The system facilitates secure communication through TLS encryption, data compression, and multiple authentication methods such as OpenID Connect, shared tokens, and basic password protection. The software offers granular control over HTTP traffic, enabling users to route requests based on subdomains or URL
This is a high-performance reverse proxy and tunneling tool that enables secure remote access to local services, though it lacks native WireGuard protocol support and a formal zero-trust architecture.
SoftEtherVPN is a multi-protocol virtual private network server that provides secure remote access and site-to-site connectivity. It functions as a virtual network gateway, enabling encrypted communication across public internet connections while supporting both Layer 2 Ethernet bridging and Layer 3 IP routing to manage traffic between connected devices. The platform is designed to maintain connectivity in restrictive network environments by bypassing firewalls and NAT devices through techniques such as HTTPS, ICMP, and DNS-based tunneling. It eliminates the requirement for static public IP a
SoftEtherVPN is a comprehensive, self-hostable multi-protocol VPN server that provides secure remote access and NAT traversal, though it lacks a native zero-trust architecture compared to modern identity-aware proxy alternatives.
Boundary is an identity-aware access proxy and privileged access management tool. It brokers secure network connections to infrastructure targets by mapping verified user identities to granular permissions, providing a gateway to servers and databases without the need for static credentials or VPNs. The system distinguishes itself through just-in-time connectivity and automated credential injection, delivering short-lived secrets to users during session initialization. It implements a composable security model using allow-only role-based access control and hierarchical resource scoping to iso
Boundary is a zero-trust access proxy that provides secure, identity-aware connectivity to private infrastructure without requiring a traditional VPN, making it a strong fit for remote access needs despite not natively using the WireGuard protocol.
WireGuard Manager is a system orchestration tool designed to automate the deployment, configuration, and lifecycle management of virtual private network infrastructure. It functions by translating high-level user intent into precise, declarative system configurations, managing kernel-level network interfaces, and enforcing firewall-based traffic control to ensure secure, isolated network routing. The project distinguishes itself by providing a centralized web-based management interface that abstracts the complexity of manual configuration files. It includes comprehensive administrative tools
This tool simplifies the deployment and management of WireGuard VPNs, providing a self-hostable solution for secure remote network access that directly addresses the core requirement for WireGuard-based connectivity.
Chisel is a network tunneling tool that facilitates secure communication by encapsulating TCP and UDP traffic within HTTP requests. It functions as a connection multiplexer, consolidating multiple logical network streams into a single persistent connection to improve throughput and reduce overhead. By leveraging standard web protocols, the system enables firewall traversal and provides a mechanism for remote port forwarding and proxying. The project distinguishes itself through its focus on resilient connectivity and granular access control. It maintains persistent network sessions across uns
Chisel is a lightweight, self-hostable tunneling tool that provides secure, encrypted remote access and port forwarding over HTTP, though it lacks native WireGuard protocol support and built-in zero-trust identity management.
gost is a multi-protocol proxy tunnel and secure tunneling server designed to route network traffic through encrypted connections. It functions as a traffic obfuscation gateway and a transparent proxy server capable of intercepting TCP and UDP traffic at the IP level. The project also includes a virtual network interface manager for creating TUN and TAP devices to intercept operating system packets. The system distinguishes itself through a chain-based request routing model, allowing traffic to pass through an ordered sequence of proxy nodes. It provides extensive transport-layer encapsulatio
This is a versatile multi-protocol tunneling and proxy server that enables secure remote traffic routing, though it lacks built-in zero-trust identity management and multi-factor authentication features.
This project provides a shell-based automation utility for deploying and managing OpenVPN servers on Linux hosts. It functions as an orchestration tool that handles the installation of networking software, the configuration of system-level routing rules, and the generation of cryptographic credentials required to establish secure, encrypted tunnels for remote network access. The tool distinguishes itself by automating the entire lifecycle of a private network gateway, including the management of peer identities and the distribution of standardized configuration profiles. It simplifies the set
This tool automates the deployment and management of OpenVPN servers, providing a functional solution for secure remote access, though it relies on the OpenVPN protocol rather than WireGuard and lacks native zero-trust or multi-factor authentication features.
| Repository | Stele | Limbaj | Licență | Ultimul push |
|---|---|---|---|---|
| firezone/firezone | 8.7K | Elixir | Apache-2.0 | |
| ngoduykhanh/wireguard-ui | 5.1K | Go | MIT | |
| zerotier/zerotierone | 16.5K | C++ | other | |
| gravitl/netmaker | 11.6K | Go | NOASSERTION | |
| openziti/ziti | 3.9K | Go | apache-2.0 | |
| pritunl/pritunl | 5K | Python | NOASSERTION | |
| netbirdio/netbird | 26.2K | Go | NOASSERTION | |
| gravitational/teleport | 19.9K | Go | agpl-3.0 | |
| fosrl/pangolin | 21.3K | TypeScript | NOASSERTION | |
| iamstoxe/wirehole | 5K | — | — |