7,380 open-source and SaaS tools, with GitHub stats refreshed every day.

8 alternatives ranked by real activity

Open-source Cato Networks alternatives

A curated, ranked list of the 8 best open-source alternatives to Cato Networks.

The best open-source alternative to Cato Networks is NetBird. If that doesn't suit you, other good options are Pangolin, Firezone, OPNsense and OpenZiti.

Cato Networks alternatives are mainly networking & VPN tools, but some are also security tools. 7 of them shipped code in the last 30 days, 8 can be self-hosted, and 4 use a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

NetBird

NetBird builds a secure WireGuard-based overlay network for devices and users, with SSO, MFA and granular access controls.

GitHub stars
30k
Last commit
today
Latest release
v0.80.0
Self-hosted
Yes
Hosted version
Available
netbird.ioNetBird homepage screenshot

NetBird joins a configuration-free peer-to-peer private network with a central access control system on one platform. It creates a WireGuard-based overlay that connects machines over encrypted tunnels automatically, which avoids opening ports, writing complex firewall rules or running VPN gateways. It is written in Go and can be used for an organization or a home network. The repository metadata lists the license as Other.

Connectivity features include kernel WireGuard, peer-to-peer connections with relay fallback, routes to external networks, exit nodes, and private DNS with custom zones. For management and security there is an admin web UI, automatic peer discovery, SSO and MFA, identity provider integrations, groups and rules for access control, activity logging, traffic events and device posture checks. A public API, setup keys, a Terraform provider and a self-hosting quickstart script support automation. Clients cover Linux, macOS, Windows, Android and Android TV, and an agent network beta targets AI agents.

Key features

  • WireGuard-based peer-to-peer overlay network
  • Relay fallback when direct connections fail
  • SSO, MFA and identity provider integrations
  • Access control through groups and rules
  • Private DNS, exit nodes and network routes
  • Public API and Terraform provider

Pricing: The cloud Free plan covers up to 5 users. Team costs €6 and Business €12 per user per month, with a free trial; Enterprise is custom, and NetBird can also be self-hosted.

Read more about NetBirdWebsite GitHub

Pangolin

An open-source SASE platform on WireGuard combining zero-trust VPN and proxy access, privileged access control and an AI gateway that understands identity.

GitHub stars
23k
Last commit
yesterday
Latest release
1.24.0
Self-hosted
Yes
Hosted version
Available
pangolin.netPangolin homepage screenshot

Pangolin is an open-source secure access service edge platform built on WireGuard. It aims to connect and protect users wherever they are by combining networking and security in one system: a zero-trust VPN, a zero-trust reverse proxy, privileged access control and a gateway for AI workloads that is aware of user identity, with one identity and policy model underneath.

The project compares its idea to commercial platforms such as Cloudflare One, Zscaler and Prisma, but argues that it is open, self-hostable and light enough to be easy to deploy. Legacy SASE products, it says, are heavy, closed and cloud-locked. Topics include reverse proxy, single sign-on, OIDC, SSH, tunneling, NAT traversal and remote access. Because the source is open to inspection, you can verify how traffic and access decisions are handled.

You can use Pangolin Cloud at app.pangolin.net or run it yourself. The repository's license is listed as 'Other' on GitHub, because it mixes open-source and enterprise components, so check the terms. It suits homelab users, small companies and IT teams that want zero-trust remote access without a large vendor contract.

Key features

  • Zero-trust VPN built on WireGuard
  • Zero-trust reverse proxy
  • Privileged access management
  • Identity-aware AI gateway
  • Single identity and policy model
  • Cloud or self-hosted deployment

Pricing: Basic is free for up to 5 users. Team costs $4 and Business $9 per user per month with a 10-day free trial; Enterprise is custom. Pangolin can run in the cloud or self-hosted.

Read more about PangolinWebsite GitHub

Firezone

Firezone is a zero trust access platform based on WireGuard, released as open source, that replaces traditional VPNs with policy-based access to apps and networks.

GitHub stars
9.1k
Last commit
today
Latest release
android-client-1.5.15
Licence
Apache-2.0
Hosted version
Available
firezone.devFirezone homepage screenshot

Firezone is a zero trust access platform that uses WireGuard and is published as open source. It is positioned as a replacement for a traditional VPN, connecting users to internal apps, services and networks through access policies rather than broad network-level rules.

Administrators define policies for resources and can restrict access by conditions such as device location and time of day, with every authorized connection visible by user, resource or policy. Users and groups sync from an identity provider, which simplifies onboarding and offboarding. Lightweight Gateways run as Linux binaries wherever access is needed, and using two or more Gateways gives automatic load balancing and failover. Hole-punching keeps protected resources hidden from the public internet.

Client apps are available for macOS, Windows, Linux, Android, ChromeOS and iOS. The codebase is licensed under Apache-2.0 and written largely in Elixir, with Rust used for networking components. The vendor offers a hosted admin portal, a free way to get started and a separate pricing page.

Key features

  • WireGuard-based VPN replacement
  • Access policies per resource and group
  • Identity provider directory sync
  • Conditional access by location and time
  • Gateways with load balancing and failover
  • Clients for desktop and mobile platforms

Pricing: Free Starter plan for up to 6 users. Team costs $5 per user per month, or $4.16 billed annually; Enterprise is quoted via sales. Source code can be self-hosted without vendor support.

Read more about FirezoneWebsite GitHub

OPNsense

An open-source firewall and routing platform; this repository holds its web GUI, API and system backend, licensed under BSD-2-Clause.

GitHub stars
4.7k
Last commit
today
Licence
BSD-2-Clause
Self-hosted
Yes
opnsense.orgOPNsense homepage screenshot

OPNsense is an open-source firewall project, and this repository contains its web GUI, API and systems backend. Its topics point to a broad feature set that includes a firewall, intrusion prevention, proxy, VPN, traffic shaping, a captive portal and routing, built on a BSD base.

The project invites developers to contribute and has designed its build process so that anyone can build and write code. Build tools are freely available in a separate tools repository, an architecture overview is on docs.opnsense.org, and the repository offers Makefile targets such as make package for assembling a package from the current state of the code. The team aims to evolve toward a new codebase gradually rather than in one big switch.

OPNsense is written mostly in PHP and is committed to staying available under the 2-clause BSD license, with every contribution required to carry the same terms. Contributions can be as simple as testing functionality, filing bug reports or sending pull requests.

Key features

  • Web GUI for firewall management
  • API and system backend
  • Intrusion prevention and proxy
  • VPN and traffic shaping
  • Captive portal and routing
  • BSD-based platform

Pricing: Free and open source under the BSD-2-Clause licence.

Read more about OPNsenseWebsite GitHub

OpenZiti

OpenZiti's core project, an open-source zero-trust networking platform that authenticates every connection with cryptographic identity and keeps services hidden.

GitHub stars
4.4k
Last commit
today
Latest release
v2.0.6
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available

Ziti is the parent project of OpenZiti, an open-source zero-trust networking platform that makes network services invisible to unauthorized users. Every connection, whether from a person, service, device or workload, is authenticated with a cryptographic identity, authorized by policy and encrypted end to end.

It works with existing applications through lightweight tunnelers that need no code changes, and with new applications through embedded SDKs for the strongest zero-trust model. The README lists use cases such as replacing VPNs with per-service authorization, hiding APIs and services so they have no listening ports, and giving IoT devices and other non-human workloads their own identities.

OpenZiti was created and sponsored by NetFoundry and is licensed under Apache-2.0. The code is written in Go, the README describes three deployment models, and a managed solution is available for teams that prefer not to operate it themselves.

Key features

  • Zero-trust overlay networking
  • Cryptographic identity for every connection
  • End-to-end encryption
  • Tunnelers for apps without code changes
  • Embedded SDKs for new applications
  • Policy-based authorization per service
  • Dark services with no listening ports
Read more about OpenZitiWebsite GitHub

Octelium

Octelium is a self-hosted zero trust access platform that can act as a VPN, ZTNA system, API and AI gateway, tunnel service or PaaS on Kubernetes.

GitHub stars
4.1k
Last commit
today
Latest release
v0.43.0
Licence
AGPL-3.0
Self-hosted
Yes
octelium.comOctelium homepage screenshot

Octelium is a self-hosted, open-source platform that unifies zero trust secure access under one system. It is flexible enough to act as a zero-config remote access VPN, a Zero Trust Network Access and BeyondCorp-style platform, an alternative to ngrok and Cloudflare Tunnel, an API gateway, an AI and LLM gateway, and an infrastructure for building MCP gateways and AI agent access.

Repository topics list attribute-based access control, policy as code, WireGuard, QUIC, SSO, multi-factor authentication, OpenTelemetry and SSH access. The README includes use cases, a feature overview, a guide to try it in a Codespace, CLI installation and instructions to install your first cluster. It is written in Go and runs on Kubernetes. It is compared to ngrok, Cloudflare Tunnel and Apigee for different roles.

Octelium is licensed under AGPL-3.0 and you operate the cluster yourself. It suits platform and security teams, homelab users and developers who want to replace several access, tunnel and gateway tools with one self-hosted system.

Key features

  • Zero-config remote access VPN
  • ZTNA and BeyondCorp-style access
  • API, AI and MCP gateway capabilities
  • Tunnel service as ngrok alternative
  • Attribute-based policy as code
  • Runs on Kubernetes clusters

Pricing: Free and open source under AGPL-3.0.

Read more about OcteliumWebsite GitHub

Defguard

Self-hosted secure remote access platform combining WireGuard VPN, identity management, multi-factor authentication, and network access control.

GitHub stars
2.9k
Last commit
today
Latest release
v2.1.0
Self-hosted
Yes
defguard.netDefguard homepage screenshot

Defguard is a self-hosted platform that brings WireGuard VPN, identity and access management, multi-factor authentication, and network access control into one product. It is built in Rust with a security-first design and targets organizations that otherwise juggle separate tools for identity, VPN access, and permissions. The core is open source under the AGPL, while some Enterprise components are open-code.

The VPN side supports multiple locations with per-location access control, MFA per connection, self-service device setup, and kernel and userspace WireGuard. The identity side includes an internal OIDC provider for single sign-on, external OIDC with Google, Microsoft, or custom providers, LDAP and Active Directory sync, remote enrollment, and user self-service. MFA options include TOTP, WebAuthn and FIDO2, and email tokens.

Everything runs in your own environment with no external dependencies or data leaving your infrastructure, and the project publishes SBOMs, penetration test reports, and architecture decision records. It suits IT and security teams that want zero-trust remote access and identity management they control, as an alternative to products such as Keycloak and Pritunl.

Key features

  • WireGuard VPN with per-connection MFA
  • Internal OIDC provider for single sign-on
  • LDAP and Active Directory sync
  • TOTP, WebAuthn, and email-token MFA
  • Per-location access control
  • Self-service device setup
  • Published SBOMs and security reports

Pricing: The Open Source edition is free to self-host. Business is free up to 10 users and 1 location, with larger setups priced through a calculator; Enterprise is custom.

Read more about DefguardWebsite GitHub

pfSense

Free firewall and router distribution based on FreeBSD, managed through a web interface and extendable with packages.

GitHub stars
5.7k
Last commit
6 mo ago
Licence
Apache-2.0
Self-hosted
Yes
pfsense.orgpfSense homepage screenshot

pfSense is a network firewall distribution built on the FreeBSD operating system. It uses a custom kernel and bundles third-party free software to cover routing and security tasks. The project began in 2004 as a fork of the m0n0wall project and has since diverged significantly.

All components are configured through a web interface, so the project says no UNIX knowledge or command-line work is needed and rule sets never have to be edited by hand. A package system adds functionality, and the project states that with packages it can match or exceed the functionality of common commercial firewalls, without artificial limits. It lists products from Check Point, Cisco, Juniper, Sonicwall, Netgear and Watchguard among those it has replaced.

pfSense is copyright Rubicon Communications (Netgate) and published under an open source license, listed as Apache-2.0 on GitHub. Netgate sells bundled hardware appliances and commercial support, which is the main way the team funds development. Administrators used to commercial firewalls may find the interface familiar, though others face a learning curve.

Key features

  • FreeBSD-based firewall and router distribution
  • Web interface for all configuration tasks
  • Package system for extra functionality
  • No command-line work required for setup
  • Hardware appliances and commercial support available

Pricing: Free open-source software; Netgate sells bundled hardware appliances and commercial support.

Read more about pfSenseWebsite GitHub

Cato Networks alternatives: questions

What is the best open-source alternative to Cato Networks?
NetBird is the top-ranked open-source alternative to Cato Networks on Enlisted: NetBird builds a secure WireGuard-based overlay network for devices and users, with SSO, MFA and granular access controls. Other strong options are Pangolin, Firezone, OPNsense and OpenZiti.
Are these Cato Networks alternatives free?
All 8 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 4 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Cato Networks alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 7 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all