Firezone: Zero-Trust Remote Access Built on WireGuard

Firezone: Zero-Trust Remote Access Built on WireGuard

Firezone provides remote access to private networks and services using WireGuard, with access decided by identity and policy rather than “anyone on the VPN can reach everything”. It is aimed at teams replacing a traditional VPN with zero-trust access.

Self-hosting caveat: Firezone’s code is public and its licences permit self-hosting, but the project states that production self-hosting of the control plane is not officially supported. The published clients are built for the managed service, and self-hosted setups need clients built from matching source revisions. For a fully self-hosted equivalent, see the alternatives below.

Architecture

ComponentRole
Control planeAdmin portal: users, groups, resources, and policies
GatewaysRun inside your networks and terminate WireGuard tunnels to resources
RelaysHelp clients connect when direct paths are blocked
ClientsWindows, macOS, Linux, iOS, and Android

Gateways can be self-hosted inside your network even when using the managed control plane, so traffic to your resources goes through infrastructure you run.

Features

  • Per-resource access policies based on users and groups from your identity provider
  • Device verification
  • Audit logs of who accessed what
  • Split tunnelling: only traffic for protected resources goes through Firezone
  • Fast, modern WireGuard tunnels

Licensing

Mixed: the Elixir control-plane code uses the Elastic License 2.0 (source-available), and the rest uses Apache 2.0.

Fully self-hosted alternatives

  • NetBird: WireGuard mesh with access policies, and a self-hostable control plane
  • Headscale: self-hosted Tailscale control server; see our Headscale guide
  • Pangolin: tunnelled access to self-hosted services
  • wg-easy: a simple WireGuard server with a web UI

Our WireGuard vs OpenVPN vs Tailscale comparison covers the wider landscape.