Creates a WireGuard based overlay network with centralized access control for secure peer to peer connectivity.

NetBird is an open-source and self-hosted Web Application that creates a peer-to-peer private network. It combines a WireGuard-based overlay network with a centralized access control system to connect machines across different infrastructures without requiring manual port forwarding or complex firewall rules. The software is deployed as a server-side management component and a client agent installed on end devices, allowing for a configuration-free setup of secure tunnels.
Users can manage their network via a web-based admin interface or automate deployments using a public API. The system supports a wide range of platforms, including Linux, Windows, macOS, Android, iOS, and various network operating systems like OpenWRT, pfSense, and OPNsense. It is designed for both organizational remote access and home networking use cases, providing a way to link servers, containers, and desktop machines into a single encrypted mesh.
Technically, NetBird utilizes a Management Service to maintain network state and distribute peer IPs to all connected agents. Agents use ICE and STUN servers to discover connection candidates for direct peer-to-peer communication. In environments where NAT traversal fails, such as carrier-grade NAT, the system automatically falls back to a Relay Service to maintain the encrypted tunnel. The architecture allows for the integration of third-party identity providers to synchronize groups via JWT, and it includes a browser-based SSH and RDP client for remote management. For those seeking deeper integration, a Caddy plugin exists to proxy traffic through NetBird networks.
NetBird is a Zero Trust Network Access solution that simplifies the creation of secure mesh networks for users who require centralized control over decentralized connectivity.
A cross platform GUI client for managing rule based network tunnels and proxy configurations via Tauri.
Creates private WireGuard networks to connect devices across clouds, VPCs, and on-premises networks without modifying firewall rules.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.