Alternatives to ZeroTier One

Puts machines anywhere in the world on the same virtual Ethernet network, as if they were plugged into one switch. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as ZeroTier One.

  • Tailscale

    Builds a private network between your own devices using WireGuard, without opening ports or running a server.

    Tailscale builds a WireGuard mesh at the IP level rather than virtual Ethernet, with a free plan for up to 6 users and a hosted coordination server.

  • NetBird

    A WireGuard-based mesh network with single sign-on, multi-factor authentication and access policies, self-hostable or managed.

    NetBird is a WireGuard mesh with SSO, MFA and access policies that can be fully self-hosted under the AGPL, with no Ethernet-level broadcast support.

  • nebula

    Connect devices through an encrypted overlay network.

    Nebula is an MIT-licensed encrypted overlay with no hosted controller, but requires certificate management and has no iOS client listed.

  • Netmaker

    Self-hosted platform for building and managing WireGuard mesh networks.

    Netmaker is a self-hosted WireGuard mesh platform with an admin interface and private DNS, with some management features in commercially licensed paid tiers.

  • headscale

    A self-hosted, open-source implementation of the Tailscale control server, so your mesh VPN does not depend on a company.

    Headscale is a self-hosted Tailscale control server that works with standard Tailscale clients, giving a WireGuard mesh without any hosted account.

  • innernet

    Private network manager built on WireGuard with peer invitations.

    Innernet is an MIT-licensed WireGuard network manager with peer invitations and central access rules, but it is Linux focused and self-run.

  • LogMeIn Hamachi

    A hosted VPN service that creates LAN-like virtual networks between remote computers.

    LogMeIn Hamachi also creates LAN-like virtual networks with web management, but it is proprietary, depends on LogMeIn's hosted service, keeps key features paid and has no mobile apps.

  • EasyTier

    A decentralized mesh VPN written in Rust that links devices into one private network, with WireGuard support.

    EasyTier forms a decentralized mesh with no central server, written in Rust with WireGuard support, but it needs more setup and much of its documentation is in Chinese.

Also worth comparing

These listings name ZeroTier One as their own alternative, so the relationship runs both ways.

  • Firezone

    WireGuard-based zero trust access with self-hosted gateways.

    ZeroTier One joins machines into a virtual Ethernet network with end-to-end encryption, working at the network level rather than per resource, with a hosted controller by default.

  • Husarnet

    A peer-to-peer VPN that connects laptops, servers and microcontrollers directly, with built-in support for ROS.

    ZeroTier One joins devices into one Ethernet-level network with NAT traversal on many platforms, but relayed connections are slow and it lacks ROS tooling.

  • n2n

    A lightweight peer-to-peer layer-2 VPN for linking machines into a virtual network.

    ZeroTier One also offers Ethernet-level networking across sites, adds Windows, macOS and mobile clients, and uses a hosted controller unless you run your own.

  • Netclient

    Connect a machine to a Netmaker-managed network.

    ZeroTier One joins machines to an Ethernet-level virtual network managed by its hosted or self-run controller, rather than a WireGuard network run by Netmaker.

  • Radmin VPN

    A free Windows program that joins remote computers into one virtual local network.

    FreeProprietaryWindows

    ZeroTier One creates a virtual Ethernet network across Windows, macOS, Linux, Android and iOS, is open source, and requires a hosted controller account unless self-run.

  • tinc

    A VPN daemon that builds an encrypted mesh network between hosts over the internet.

    ZeroTier One creates a virtual Ethernet mesh with NAT traversal and clients for desktop and mobile, using a hosted controller unless you run your own.

  • Twingate

    An identity-based network access service meant to replace a traditional VPN for teams.

    FreemiumProprietaryWeb

    ZeroTier One joins machines into one virtual Ethernet network rather than granting per-resource access, and its controller can be self-run.

  • Yggdrasil

    An experimental, end-to-end encrypted IPv6 mesh network run as a lightweight userspace software router.

    ZeroTier One gives a flat Ethernet-level network with NAT traversal on major platforms instead of an experimental IPv6 mesh, but it uses a hosted controller account unless you run your own.

Similar software

Related functionality, not a direct replacement.