Alternatives to Netmaker

Self-hosted platform for building and managing WireGuard mesh networks. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as Netmaker.

  • NetBird

    A WireGuard-based mesh network with single sign-on, multi-factor authentication and access policies, self-hostable or managed.

    NetBird provides a self-hostable WireGuard mesh with SSO, MFA and group policies under AGPL-3.0, though self-hosting the full stack including identity is real work.

  • headscale

    A self-hosted, open-source implementation of the Tailscale control server, so your mesh VPN does not depend on a company.

    headscale self-hosts a Tailscale control server for use with standard Tailscale clients, fully under BSD-3-Clause, but targets a single tailnet and lacks a graphical admin interface.

  • Tailscale

    Builds a private network between your own devices using WireGuard, without opening ports or running a server.

    Tailscale builds a WireGuard mesh with central access rules and MagicDNS without running a server, but its coordination server is hosted and requires an identity provider account.

  • ZeroTier One

    Puts machines anywhere in the world on the same virtual Ethernet network, as if they were plugged into one switch.

    ZeroTier One joins machines into a virtual Ethernet network rather than a WireGuard mesh, with a hosted controller unless you run your own.

  • nebula

    Connect devices through an encrypted overlay network.

    nebula is an MIT-licensed encrypted overlay network with no paid tiers listed, but it requires certificate management and network configuration and has no admin interface mentioned.

  • innernet

    Private network manager built on WireGuard with peer invitations.

    innernet is an MIT-licensed WireGuard network manager with invitation-based enrolment and central access rules, but it is Linux and command-line focused.

  • Firezone

    WireGuard-based zero trust access with self-hosted gateways.

    Firezone provides WireGuard zero trust access with identity-driven per-resource policies and self-hosted gateways, but its control plane is hosted by the vendor.

  • defguard

    A self-hosted WireGuard VPN platform with built-in identity management and multi-factor authentication per connection.

    defguard is a self-hosted WireGuard platform focused on identity, with per-connection MFA, LDAP, Active Directory and OIDC integration and central firewall management.

Also worth comparing

These listings name Netmaker as their own alternative, so the relationship runs both ways.

  • Twingate

    An identity-based network access service meant to replace a traditional VPN for teams.

    FreemiumProprietaryWeb

    Netmaker is a self-hosted WireGuard mesh platform with access control lists and private DNS, with some features held back for paid tiers.

  • WireGuard Portal

    A self-hosted web portal for managing WireGuard server interfaces and user peer configurations.

    Netmaker automates WireGuard key exchange and access control lists across mesh networks with private DNS, though its pro code is commercially licensed and tiers hold back features.

Similar software

Related functionality, not a direct replacement.