090 | ZeroTier and NetBird: When a Mesh Network Is Needed Here and Now
Published on August 22, 2025
When Zero-config VPN Means More Than Just Tailscale
Although Tailscale has become the benchmark for simplicity, it’s not the only player in the Zero-config VPN field. ZeroTier and NetBird offer similar functionality but with important architectural and ideological differences.
ZeroTier: A Virtual Ethernet Switch
ZeroTier is one of the first and most well-known services implementing the mesh network concept. It works on the principle of a virtual local network. Instead of relying on the WireGuard protocol, ZeroTier uses its own protocol and creates a virtual L2 switch (Layer 2) that unites all devices into a single local network. Each device gets an IP address from a virtual subnet and can “see” other devices as if they were connected to the same physical switch.
Pros:
- Reliability: The ZeroTier protocol works through any firewalls and NAT.
- Flexibility: Allows you to create separate networks for different tasks.
- Stability: A mature and time-tested project.
Cons:
- Performance: ZeroTier’s custom protocol is usually slower than WireGuard.
- Complexity: Setting up L2 networks may feel unusual for those accustomed to classic routing.
NetBird: Open-source and Full Control
NetBird is a relatively new but actively developing open-source project built on top of WireGuard. Its main advantage is the ability to self-host.
NetBird consists of two parts:
- Client: An application installed on the device (similar to Tailscale).
- Control Plane server: You can use the cloud version like Tailscale or deploy your own server on a VPS.
Pros:
- Full control: You own the data and infrastructure. Critical for those who don’t trust third-party services.
- WireGuard: Uses the proven, fast WireGuard protocol.
- Clear architecture: Working with NetBird helps you better understand how WireGuard-based mesh networks function.
Cons:
- Setup complexity: Deploying your own control server requires some knowledge.
- Less mature: Compared to ZeroTier and Tailscale, it’s a younger project.
Comparison: The Choice Depends on the Task
Service | Base Protocol | Core Value | Use Case |
---|---|---|---|
Tailscale | WireGuard | Simplicity. Works “out of the box.” | For those who value time and don’t want to deal with configurations. Ideal for everyday users. |
ZeroTier | Custom | Virtual L2 network. Flexibility. | For IoT devices, complex networks where a transparent local network is needed. |
NetBird | WireGuard | Self-hosting. Full control. | For companies and tech enthusiasts who want to own their infrastructure. |
Conclusion
The choice between Tailscale, ZeroTier, and NetBird depends on your priorities. If you need maximum simplicity — choose Tailscale. If you want flexibility and L2 networks — ZeroTier. If full control and an open-source solution matter most — NetBird.
In the next and final article of this series, we’ll show you how to create your own Tailscale alternative using Headscale and set up “pure” WireGuard to gain complete control over your network.
Related Posts
094 | OpenVPN + Keycloak: Modern Authentication
August 27, 2025
093 | OpenVPN Setup: Explaining the Basics
August 26, 2025
092 | OpenVPN: One Protocol – Different Clients
August 25, 2025
091 | DIY Mesh VPN: Headscale and Self-Managed WireGuard
August 23, 2025