Alternatives to nebula
Connect devices through an encrypted overlay network. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
nebula
Connect devices through an encrypted overlay network.
Replacements
Listings that take over the same core job as nebula.
ZeroTier One
Puts machines anywhere in the world on the same virtual Ethernet network, as if they were plugged into one switch.
ZeroTier One joins machines into a virtual Ethernet network with NAT traversal and iOS support, but uses a hosted controller unless you run your own.
Tailscale
Builds a private network between your own devices using WireGuard, without opening ports or running a server.
Tailscale builds a WireGuard mesh with sign-in through an identity provider instead of certificates, and central access rules, but its coordination server is a hosted service.
NetBird
A WireGuard-based mesh network with single sign-on, multi-factor authentication and access policies, self-hostable or managed.
NetBird provides a WireGuard mesh with SSO, MFA, group access policies and an admin web interface, self-hostable under AGPL-3.0 instead of MIT.
headscale
A self-hosted, open-source implementation of the Tailscale control server, so your mesh VPN does not depend on a company.
headscale lets you self-host a Tailscale-compatible control server used with standard Tailscale clients, but targets a single tailnet and you must keep it running.
Netmaker
Self-hosted platform for building and managing WireGuard mesh networks.
Netmaker automates WireGuard key exchange, peers and access lists with an admin interface and private DNS, but some code is commercially licensed and paid tiers hold back features.
innernet
Private network manager built on WireGuard with peer invitations.
innernet manages a WireGuard private network with invitation-based enrolment and central access rules, but it is focused on Linux and the command line.
tinc
A VPN daemon that builds an encrypted mesh network between hosts over the internet.
tinc builds a self-managed encrypted mesh with automatic routing and NAT traversal, configured by hand, but focuses on Linux and its 1.1 branch remains prerelease.
EasyTier
A decentralized mesh VPN written in Rust that links devices into one private network, with WireGuard support.
EasyTier is a Rust mesh VPN that needs no central server and adds WireGuard support and a graphical interface, though much documentation is in Chinese.
Also worth comparing
These listings name nebula as their own alternative, so the relationship runs both ways.
Husarnet
A peer-to-peer VPN that connects laptops, servers and microcontrollers directly, with built-in support for ROS.
nebula is an MIT-licensed encrypted overlay network for desktop, server and mobile, but requires you to manage certificates and network configuration.
LogMeIn Hamachi
A hosted VPN service that creates LAN-like virtual networks between remote computers.
Nebula is a free, MIT-licensed encrypted overlay network for desktop and Android that you run yourself, requiring certificate management instead of a hosted web console.
n2n
A lightweight peer-to-peer layer-2 VPN for linking machines into a virtual network.
Nebula is an MIT-licensed encrypted overlay network with Windows, macOS and Android support, using certificate management instead of a supernode.
Netclient
Connect a machine to a Netmaker-managed network.
Nebula connects devices to its own certificate-based encrypted overlay network under MIT, with no Netmaker server, but you handle certificates and network configuration yourself.
WireGuard
A small, fast VPN protocol and set of official clients that connect two machines by exchanging public keys.
Nebula builds an encrypted overlay network between many devices using certificates rather than exchanged keys, and has no iOS client listed.
Yggdrasil
An experimental, end-to-end encrypted IPv6 mesh network run as a lightweight userspace software router.
nebula builds an encrypted overlay network across desktop, server and mobile platforms under the MIT license, but it requires certificate management and network configuration rather than self-healing routing.
Similar software
Related functionality, not a direct replacement.