{"id":13638678,"url":"https://github.com/HarvsG/WireGuardMeshes","last_synced_at":"2025-04-19T18:30:50.787Z","repository":{"id":37658016,"uuid":"434181676","full_name":"HarvsG/WireGuardMeshes","owner":"HarvsG","description":"A text repo to feature-track WireGuard mesh software","archived":false,"fork":false,"pushed_at":"2024-12-15T14:09:01.000Z","size":93,"stargazers_count":539,"open_issues_count":7,"forks_count":31,"subscribers_count":22,"default_branch":"main","last_synced_at":"2024-12-15T15:20:11.537Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/HarvsG.png","metadata":{"files":{"readme":"readme.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-12-02T10:47:39.000Z","updated_at":"2024-12-15T14:09:06.000Z","dependencies_parsed_at":"2024-01-13T16:25:02.263Z","dependency_job_id":"9c2020e4-2f78-4dcc-ba5a-8ff127abd5b0","html_url":"https://github.com/HarvsG/WireGuardMeshes","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarvsG%2FWireGuardMeshes","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarvsG%2FWireGuardMeshes/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarvsG%2FWireGuardMeshes/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/HarvsG%2FWireGuardMeshes/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/HarvsG","download_url":"https://codeload.github.com/HarvsG/WireGuardMeshes/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":249764720,"owners_count":21322289,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:00:51.538Z","updated_at":"2025-04-19T18:30:50.780Z","avatar_url":"https://github.com/HarvsG.png","language":null,"funding_links":[],"categories":["Others","Projects","others"],"sub_categories":["Mesh Network"],"readme":"# Compare WireGuard Mesh Tools\n[WireGuard](https://wireguard.com/) is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography and supports mesh networking. However, by default it requires manual configuration. Adding a new client to the network would require the admin to update O(n\u003csup\u003e2\u003c/sup\u003e) client configurations each time. [wg-dynamic](https://git.zx2c4.com/wg-dynamic/about/docs/idea.md) was a proposed native WireGuard tool that would help with autoconfiguration, unfortunately development of this has gone stale. So here are a list of alternatives.\n\n## Table\n| Feature\\Software | Open source | Free | Full Mesh | Auto conf | Devices | Supports Users | Allows full tunnel | Subnet Access | NAT traversal | Linux | Windows | MacOS | Android | iOS | OpenWRT | Custom DNS |\n|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|\n| [Vanilla WireGuard](https://www.wireguard.com/repositories/) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :x: | Unlimited | :x: | :white_check_mark: | :white_check_mark: | :x: | :eight_pointed_black_star: | :eight_pointed_black_star: | :eight_pointed_black_star: | :eight_pointed_black_star: | :eight_pointed_black_star: | :eight_pointed_black_star: | :white_check_mark: |\n| [Tailscale](https://github.com/tailscale/tailscale) | :white_check_mark:[:exclamation:\u003csup\u003e0\u003csup\u003e](#tsexplain1) | :x::free: | :white_check_mark: | :white_check_mark: | Unlimited :one::zero::zero: | :white_check_mark: :three: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :globe_with_meridians: | :globe_with_meridians::lock_with_ink_pen: | :globe_with_meridians::lock_with_ink_pen: | :globe_with_meridians: | :globe_with_meridians::lock_with_ink_pen: | :white_check_mark: | :white_check_mark: [:exclamation:\u003csup\u003e3\u003csup\u003e](#tsexplain2) |\n| [Headscale](https://github.com/juanfont/headscale) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | Unlimited | :x: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :globe_with_meridians: | :globe_with_meridians: | :globe_with_meridians: | :globe_with_meridians:[:exclamation:\u003csup\u003e2\u003csup\u003e](#hsexplain1) | :globe_with_meridians::lock_with_ink_pen:[:exclamation:\u003csup\u003e2\u003csup\u003e](#hsexplain1) | :white_check_mark: | :white_check_mark: |\n| [Netmaker](https://github.com/gravitl/netmaker) | :white_check_mark:[:exclamation:\u003csup\u003e1\u003csup\u003e](#nmexplain1) | :white_check_mark: | :white_check_mark: | :white_check_mark: | Unlimited | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :globe_with_meridians: | :globe_with_meridians: | :globe_with_meridians: | :eight_pointed_black_star::snowflake: | :eight_pointed_black_star::snowflake: | :white_check_mark: | :white_check_mark: |\n| [WGSD](https://github.com/jwhited/wgsd) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :x: | Unlimited | :x: | :white_check_mark: | :x: | :white_check_mark: | :white_check_mark: | :x: | :x: | :x: | :x: | :white_check_mark: | :x: |\n| [Innernet](https://github.com/tonarino/innernet ) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :x: | Unlimited | :white_check_mark: | :white_check_mark: | :x: | :white_check_mark: | :white_check_mark: | :x: | :white_check_mark: | :x: | :x: | :x: |  |\n| [Wesher](https://github.com/costela/wesher) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | Unlimited | :x: |  |  |  | :white_check_mark: | :x: | :x: | :x: | :x: | :x: | :x: |\n| [NetBird](https://github.com/netbirdio/netbird) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | Unlimited :one::zero::zero: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :globe_with_meridians: | :globe_with_meridians: | :white_check_mark: | :white_check_mark: |\n| [wgmesh](https://github.com/aschmidt75/wgmesh) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | Unlimited | :x: | :white_check_mark: | :x: | :x: | :globe_with_meridians: | :x: | :x: | :x: | :x: | :x: | :x: |\n| [wiresmith](https://github.com/svenstaro/wiresmith) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | Unlimited | :x: | :x: | :x: | :x: | :globe_with_meridians: | :x: | :x: | :x: | :x: | :x: | :x: |\n| [webmesh](https://github.com/webmeshproj/webmesh) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | Unlimited | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :globe_with_meridians: | :globe_with_meridians: | :globe_with_meridians: | :soon: | :soon: | :soon: | :white_check_mark: |\n| [NordVPN Meshnet](https://github.com/NordSecurity/libtelio) | :white_check_mark: [:exclamation:\u003csup\u003e4\u003csup\u003e](#nvmexplain1) | :white_check_mark: | :white_check_mark: | :white_check_mark: | :one::zero: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :white_check_mark: | :globe_with_meridians: | :globe_with_meridians: :lock_with_ink_pen: | :globe_with_meridians: :lock_with_ink_pen: | :globe_with_meridians: :lock_with_ink_pen: | :globe_with_meridians: :lock_with_ink_pen: | :soon: | :white_check_mark: |\n  \n \u003csup\u003e0\u003c/sup\u003e\u003ca name=\"tsexplain1\"\u003eTailscale's client code is open source. Tailscale's control server code is entirely closed source (It's a SaaS product).\u003c/a\u003e  \n  \n \u003csup\u003e1\u003c/sup\u003e\u003ca name=\"nmexplain1\"\u003eNetmaker uses the SSPL license, which is not an \"official\" open source license occording to the OSI.\u003c/a\u003e  \n  \n \u003csup\u003e2\u003c/sup\u003e\u003ca name=\"hsexplain1\"\u003eHeadscale uses the tailscale mobile clients. \u003ca href=\"https://github.com/juanfont/headscale/blob/main/docs/android-client.md\"\u003eAndriod instructions\u003c/a\u003e\u003c/a\u003e. \u003ca href=\"https://github.com/juanfont/headscale/blob/main/docs/iOS-client.md\"\u003eiOS\u003c/a\u003e\u003c/a\u003e\n  \n \u003csup\u003e3\u003c/sup\u003e\u003ca name=\"tsexplain2\"\u003eWhen routing all traffic through an exit node tailscale ignores custom DNS. \u003ca href=\"https://github.com/tailscale/tailscale/issues/8237\"\u003eIssue\u003c/a\u003e\u003c/a\u003e\n\n \u003csup\u003e4\u003c/sup\u003e\u003ca name=\"nvmexplain1\"\u003eOpen source parts: `libtelio` - multiplatform meshnet library, `nordvpn-linux` - vpn client app for linux with integrated meshnet feature, `libdrop` - multiplatform file-sharing-over-meshnet library.\u003c/a\u003e\n\n \u003csup\u003e5\u003c/sup\u003e\u003ca name=\"nvmexplain2\"\u003e10 peers per account. Can connect to up to 50 devices from other accounts.\u003c/a\u003e\n \n## Legend\n- :free: Has free tier\n- :three: Limited amount on free tier (e.g 3)\n- :lock_with_ink_pen: This software version is closed source\n- :credit_card: Paid version only\n- :globe_with_meridians: Client can join as member of the full mesh\n- :eight_pointed_black_star: Client can join as a 'spoke' off a node/gateway on the mesh\n- :snowflake: Client can join the network but updates to the network are not automatically propgated to the client\n- :soon: Developer claims the feature is coming soon\n- [:exclamation:\u003csup\u003e0\u003csup\u003e](https://github.com/HarvsG/WireGuardMeshes/blob/main/readme.md#legend) Significant exception to the feature (should link to explanation)\n\n## Disclaimers\n- [WireGuard](https://wireguard.com/) is a registered trademark of Jason A. Donenfeld.\n- I do not independently verify each of the features and generally rely on the honesty of contributors please open an issue if you find any mistakes.\n\n## Changes\nPlease help update this table by using [issues](https://github.com/HarvsG/WireGuardMeshes/issues) or [pull requests](https://github.com/HarvsG/WireGuardMeshes/pulls). You may find https://www.tablesgenerator.com/markdown_tables helpful (File -\u003e paste table data)\n\n## Columns\n| Column | Description |\n|---|---|\n| Feature\\Software | The name and hyperlink to the project's main repository or website. |\n| Open source | Is the project open source. |\n| Free | Is the project entirely free to download, install and use. |\n| Full Mesh | Does the project allow every peer to communicate with every other peer directly. Relying on `AllowedIPs` to route traffic via a central peer in a hub and spoke model does not count. |\n| Auto conf | When a new peer is added to the mesh, are all other peers update automatically. Usually a requirement to be featured in this repo |\n| Devices | How many devices can the mesh support. |\n| Supports Users | Does the project allow users to be configured, usually for user access control. |\n| Allows full tunnel | Is the project capable of tunnelling all external traffic over at least one of the peers. |\n| Subnet Access | Can a device 'expose' the devices on its subnet to peers, usually using wiregaurd's `AllowedIPs`. This could allow you to access resources on your home network if your router was connected to the mesh, for example. |\n| NAT traversal | Can two peers that are each behind a separate NAT communicate with one another. This usually requires some other non-NATed central peer to update each NATed peer with the other's IP and port. Sometimes called NAT hole-punching |\n| Linux | Can the project be set up on a Linux machine e.g Ubuntu |\n| Windows | Can the project be installed on a Windows machine. |\n| MacOS | Can the project be installed on a MacOS machine. |\n| Android | Is there an Android App and can it connect to every other peer. |\n| iOS | Is there an iOS App and can it connect to every other peer. |\n| OpenWRT | Can the project be installed on an OpenWRT router. Useful if you want everything on your network to be able to access the devices on the mesh |\n| Custom DNS | Can the DNS provider used by all peers be configured centrally. |\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FHarvsG%2FWireGuardMeshes","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FHarvsG%2FWireGuardMeshes","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FHarvsG%2FWireGuardMeshes/lists"}