Mesh VPNs and Private Networking
Mesh VPNs connect devices directly or through encrypted relays to create private networks across home, office, and cloud environments. They can simplify access to remote machines and services without exposing them publicly, while handling changing addresses, restrictive firewalls, and network address translation. Identity-based access controls can also make it easier to manage who may reach particular devices or resources.
Open source tools in this area include VPN clients and daemons, coordination servers, command-line utilities, and network diagnostics for connectivity and NAT behavior. When choosing a tool, consider its security model, protocol support, maturity, license, maintenance activity, deployment requirements, and integration with existing identity and infrastructure systems. These tools are useful to administrators, developers, and self-hosters who need secure remote access or private connectivity across distributed devices.
3 repositories · updated May 13, 2026

Stunner: Quickly Detect Your NAT Type with Multi-Server STUN
Stunner is an efficient Go CLI tool designed to accurately detect your Network Address Translation (NAT) type. By sending STUN Binding Requests to multiple servers, it classifies your NAT as Full Cone, Symmetric, or Restricted, providing crucial insights into your network environment. This helps users understand network behavior and assess the feasibility of techniques like hole punching.

Tailscale: Secure and Easy WireGuard-based VPN with 2FA and SSO
Tailscale offers a simple and secure way to build private networks using WireGuard, integrating 2FA and SSO for enhanced access control. This open-source repository contains the core `tailscaled` daemon and `tailscale` CLI tool, enabling cross-platform secure connectivity. It simplifies network configuration, making secure remote access and device communication effortless.

Awesome Tunneling: A Curated List of Self-Hostable Tunneling Solutions
This comprehensive list, `awesome-tunneling`, compiles ngrok, Cloudflare Tunnel, Tailscale, and ZeroTier alternatives, focusing on self-hosting options. It serves as a valuable resource for developers and self-hosters aiming to expose local webservers via public domain names with automatic HTTPS, even behind restrictive networks.