FireZone
WireGuard based remote access with least privilege policies, for organizations replacing a legacy VPN with per-resource control.
Open Source Alternative to:

Firezone manages remote access for an organization of any size, replacing the flat network a traditional VPN hands out. Group based policies gate access to individual applications, to entire subnets and to everything in between, so one compromised laptop does not expose the rest.
It is built on WireGuard, with a Rust data plane that needs only a few megabytes of memory and an Elixir admin portal and control plane. Tunnels are established on the fly through hole punching, and traffic runs peer to peer and end to end encrypted rather than through Firezone's own infrastructure.
The product is organized around a small set of components.
- Gateways: deploy into your infrastructure, and two or more give automatic load balancing and failover.
- Relays: run STUN and TURN so peers can find each other behind NAT.
- Clients: cover macOS, iOS, Android, ChromeOS, Windows and Linux, in graphical and headless form.
- Identity: authenticates through email, Google Workspace, Okta, Entra ID or OIDC, with automatic user and group sync.
- Policy templates: ship MDM profiles for Windows and macOS fleet management.
Firezone is not a mesh network builder, a full router or firewall, or an IPSec server. The code is open under Apache 2.0 with the Elixir portal under the Elastic License 2.0, and the maintainers state that production self-hosting is not supported today because internal APIs move quickly, so running it yourself suits educational and hobby use while the managed cloud covers production.
Stars
9,052Forks
451Last commit
5 days agoRepository age
6 yearsLicense
Apache-2.0Version
macos-client-1.5.19Repository
firezone/firezone
Auto-fetched from GitHub .
Open source alternatives similar to FireZone:
Stars
Forks
Last commit
Stars
Forks
Last commit
Stars
Forks
Last commit