Firezone: Zero-Trust Remote Access Built on WireGuard
Firezone provides remote access to private networks and services using WireGuard, with access decided by identity and policy rather than “anyone on the VPN can reach everything”. It is aimed at teams replacing a traditional VPN with zero-trust access.
Self-hosting caveat: Firezone’s code is public and its licences permit self-hosting, but the project states that production self-hosting of the control plane is not officially supported. The published clients are built for the managed service, and self-hosted setups need clients built from matching source revisions. For a fully self-hosted equivalent, see the alternatives below.
Architecture
| Component | Role |
|---|---|
| Control plane | Admin portal: users, groups, resources, and policies |
| Gateways | Run inside your networks and terminate WireGuard tunnels to resources |
| Relays | Help clients connect when direct paths are blocked |
| Clients | Windows, macOS, Linux, iOS, and Android |
Gateways can be self-hosted inside your network even when using the managed control plane, so traffic to your resources goes through infrastructure you run.
Features
- Per-resource access policies based on users and groups from your identity provider
- Device verification
- Audit logs of who accessed what
- Split tunnelling: only traffic for protected resources goes through Firezone
- Fast, modern WireGuard tunnels
Licensing
Mixed: the Elixir control-plane code uses the Elastic License 2.0 (source-available), and the rest uses Apache 2.0.
Fully self-hosted alternatives
- NetBird: WireGuard mesh with access policies, and a self-hostable control plane
- Headscale: self-hosted Tailscale control server; see our Headscale guide
- Pangolin: tunnelled access to self-hosted services
- wg-easy: a simple WireGuard server with a web UI
Our WireGuard vs OpenVPN vs Tailscale comparison covers the wider landscape.