Alternatives to innernet

Private network manager built on WireGuard with peer invitations. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as innernet.

  • headscale

    A self-hosted, open-source implementation of the Tailscale control server, so your mesh VPN does not depend on a company.

    headscale is a self-hosted Tailscale control server that works with the standard Tailscale clients on every platform, but targets a single tailnet and has no graphical admin interface.

  • NetBird

    A WireGuard-based mesh network with single sign-on, multi-factor authentication and access policies, self-hostable or managed.

    NetBird offers a WireGuard mesh with SSO, MFA, group access policies and an admin web interface on more platforms, self-hostable under AGPL-3.0 or managed.

  • Netmaker

    Self-hosted platform for building and managing WireGuard mesh networks.

    Netmaker automates WireGuard keys, peers and access lists with an admin interface and private DNS across platforms, but some code is commercially licensed and paid tiers hold back features.

  • Tailscale

    Builds a private network between your own devices using WireGuard, without opening ports or running a server.

    Tailscale builds a WireGuard mesh through NAT without running a server yourself, with clients for all major platforms, but its coordination server is hosted and requires an account.

  • nebula

    Connect devices through an encrypted overlay network.

    nebula is an MIT-licensed encrypted overlay network that runs on Windows, macOS, Linux and Android, but uses certificate management instead of invitation-based enrolment.

  • ZeroTier One

    Puts machines anywhere in the world on the same virtual Ethernet network, as if they were plugged into one switch.

    ZeroTier One puts machines on a virtual Ethernet network across all major platforms, but uses a hosted controller unless you run your own and some repository parts are not free software.

  • defguard

    A self-hosted WireGuard VPN platform with built-in identity management and multi-factor authentication per connection.

    defguard is a self-hosted WireGuard platform with per-connection MFA and LDAP and OIDC integration, aimed at organisations, with some features in enterprise plans.

  • tinc

    A VPN daemon that builds an encrypted mesh network between hosts over the internet.

    tinc builds a self-managed Linux mesh VPN with automatic full mesh routing, but uses its own daemon and hand-written config files instead of WireGuard invitations.

Also worth comparing

These listings name innernet as their own alternative, so the relationship runs both ways.

  • WireGuard

    A small, fast VPN protocol and set of official clients that connect two machines by exchanging public keys.

    Innernet builds on WireGuard with invitation-based enrolment and central access rules, removing manual key exchange, but is Linux focused and needs a coordination server.

Similar software

Related functionality, not a direct replacement.