Netbird
WireGuard-based overlay network with centralized access control, connecting machines peer to peer without open ports or VPN gateways.
Open Source Alternative to:

NetBird pairs a configuration-free peer-to-peer private network with a central access control system in one platform. Machines join an encrypted WireGuard overlay and reach each other directly, which removes the familiar work of opening ports, writing firewall rules and standing up VPN gateways for every site.
Every machine runs an agent that manages WireGuard locally and connects to a Management Service holding network state, peer addresses and configuration updates. Agents use ICE to discover candidates for direct connections, with a relay as fallback when no peer-to-peer path can be established.
Around that core sits the management surface an organization actually needs.
- Access control: Groups and rules, device posture checks and periodic re-authentication.
- Identity: SSO and MFA support, identity provider integrations and group sync through JWT.
- Routing: Routes into external networks, domain-based DNS routes, exit nodes and private DNS zones.
- Automation: A public API, setup keys for bulk provisioning, a Terraform provider and an Ansible collection.
- Visibility: Activity logging and traffic events, plus browser-based SSH and RDP to peers.
Clients cover Linux, macOS, Windows, Android, iOS, FreeBSD and appliance platforms including pfSense, OPNsense, OpenWRT, Synology and Raspberry Pi. Self-hosting needs a Linux VM with one CPU and two gigabytes of memory, public reachability on TCP 80 and 443 and UDP 3478, a public domain pointing at it, and Docker with the Compose plugin.
Stars
28,960Forks
1,658Last commit
6 days agoRepository age
5 yearsVersion
0.78.1Repository
netbirdio/netbird
Auto-fetched from GitHub .
Open source alternatives similar to Netbird:
Stars
Forks
Last commit
Stars
Forks
Last commit
Stars
Forks
Last commit