// Engineering Log
ZeroTier and NetBird: alternatives to Tailscale — what they are and how they differ
Published on 2026-09-22
// Fast route
This article belongs to the topic Networking and routing.
ZeroTier and NetBird are services for creating a private network between your devices over the Internet, main alternatives to Tailscale. All three solve the same problem: computers, servers and phones see each other by internal addresses without port forwarding and manual tunnel setup. They differ by network design, licenses, and whether you can host the control server yourself.
What is ZeroTier
ZeroTier is one of the oldest services of this type. Unlike Tailscale and NetBird, it does not use WireGuard, but works on its own protocol and builds a layer-2 virtual network (L2) — analogous to an Ethernet switch stretched over the Internet.
According to ZeroTier documentation, the system consists of two layers:
- VL1 — peer-to-peer transport: devices discover each other and establish encrypted connections, using relays when necessary;
- VL2 — Ethernet virtualization, similar to VXLAN: isolated networks, broadcast and multicast traffic, rules and access certificates.
The network is managed by a controller: it grants devices permission to join and provides configuration. Usually the cloud controller my.zerotier.com is used, but the documentation explicitly allows a self-hosted controller — at the cost of working with JSON configuration or third-party interfaces.
The main practical feature of ZeroTier is the layer-2 network. Devices are in the same broadcast domain, so discovery protocols that need a “real” local network work: some games, industrial and IoT devices, legacy systems. Tailscale and NetBird do not provide this — they operate at layer 3 (IP).
License. The main ZeroTierOne code is distributed under the Mozilla Public License, but the repository includes a nonfree/ directory — its sources are readable but distributed under a non-free license. Therefore “ZeroTier is a fully open project” is not entirely correct.
What is NetBird
NetBird is an open mesh VPN platform based on WireGuard, closest to Tailscale in architecture, but with the ability to fully deploy it yourself. According to the project documentation, NetBird consists of four parts:
- Management — coordination server with a web panel: stores network state and public keys, authenticates users, distributes changes;
- Signal — helps devices agree on a direct connection; no traffic goes through it or is stored;
- Relay — relay for cases when a direct connection is impossible; traffic through it remains encrypted;
- client on devices — creates keys and WireGuard tunnels (on Linux it can use the kernel WireGuard).
Connections are established using ICE and STUN — the same NAT traversal techniques used in WebRTC.
License. Most of the repository is BSD-3-Clause, while the server components management/, signal/ and relay/ are under AGPLv3. This is not an obstacle for self-hosting, but if you modify the server and provide it as a service to others, AGPLv3 requires you to open your changes.
Self-hosted server. For quick deployment there is an official script:
export NETBIRD_DOMAIN=netbird.example.ru
curl -fsSL https://github.com/netbirdio/netbird/releases/latest/download/getting-started.sh | bashFor production deployment you will need a server with a domain name and open ports for the web panel, Signal and Relay, as well as an account provider — built-in or external, for example Keycloak.
Comparison as of September 2026
| Tailscale | ZeroTier | NetBird | |
|---|---|---|---|
| Protocol | WireGuard | proprietary | WireGuard |
| Network layer | L3 (IP) | L2 (Ethernet) | L3 (IP) |
| License | client core — BSD-3 (graphical clients on macOS, iOS, Windows are closed-source), coordination server — closed service | MPL + nonfree nonfree/ part | BSD-3 (client) and AGPLv3 (server) |
| Free cloud tier | Personal: up to 6 users, unlimited devices | Personal: 10 devices, 1 network, non-commercial use only | Free: up to 5 users and 100 machines |
| Paid plans | Standard $8, Premium $18 per user per month | Essential $18 and Scale $179 per month | Team €6, Business €12 per user per month |
| Own management server | no (there is unofficial Headscale) | yes, own controller | yes, built-in |
Prices are taken from the pricing pages on tailscale.com, zerotier.com and netbird.io. Note ZeroTier’s limitation: the free Personal tier allows only personal non-commercial use; a company needs a paid plan.
How they differ in practice
Tailscale — the fastest to start and the most reliable NAT traversal, but the coordination server is cloud-only.
ZeroTier — the only one of the three with a layer-2 network. Chosen when broadcast protocols or a transparent “single LAN” are needed. The trade-off is a proprietary protocol instead of WireGuard and commercial restrictions on the free tier.
NetBird — an open alternative to Tailscale with a full self-hostable server and web panel. The best option if the management server must run in your infrastructure — for example, in a Russian data center for data residency requirements.
How to choose
- Need something quick, for a few devices, without your own server — Tailscale or cloud NetBird.
- Company, data and management must be on-premises — NetBird on your own server or Headscale.
- Need an L2 network: device discovery, broadcast traffic — ZeroTier.
- Need maximum control and the minimum number of components — manual WireGuard configuration.
For Russian companies there are two common limitations of cloud plans: foreign services cannot be paid with a Russian card — Visa and Mastercard suspended operations in Russia in 2022 — and management servers are located abroad. Free tiers and self-hosted servers are not affected by the first limitation.
Common mistakes
- Using free ZeroTier in a commercial project — violation of the Personal tier terms.
- Mixing network layers. Expecting broadcast protocols to work over Tailscale or NetBird, which is only possible with ZeroTier.
- Self-hosted server without redundancy and backups. The management server becomes a critical element of the network: without it you cannot add a new device or change rules.
- Default access rules. In all three systems you should immediately restrict which devices and users can see which resources.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Networking and routing
MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.
Typical tasks behind this topic
- Set up VPN and secure access to office or cloud
- Fix routing, DNS, or unstable connectivity
- Configure MikroTik, firewall, and external links
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Reviews
Related reviews
Huge thanks to Mikhail for the work — I'm very pleased with the result. Special thanks for his recommendations during setup: from my rather muddled brief (I know little about servers), Mikhail, through clarifying questions and suggestions, formed a clear understanding of what the final build would accomplish and how best to organize everything. I recommend him!
Many thanks to Mikhail for the work, I am very pleased with the result. I especially thank him for the recommendations during the setup process — from my rather muddled brief (and I know little about servers) Mikhail, …
MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.
2025-07-21 · ★ 5/5
An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed what we'd been racking our brains over for days! I'm sure this won't be the last time we rely on his boundless professionalism.
An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed for us what we had been scratching our heads over for days! I'm sure this won't be the first time we make use of his boundless …
MikroTik hAP router setup. I'll configure a MikroTik Wi-Fi router for you.
2025-05-28 · ★ 5/5
A professional approach to the job!
Professional approach to the job!
MikroTik hAP router setup. I'll set up a MikroTik Wi-Fi router for you.
2025-03-31 · ★ 5/5
Knows their stuff, gets things done. Everything was prompt and to the point; I was satisfied with the collaboration.
Knows, can, does. Everything was prompt and to the point; I was satisfied with the collaboration.
MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.
2025-03-14 · ★ 5/5
Thanks! We set up the router according to my technical specification, with a full explanation of what we're doing.
Thank you! The router was configured according to my technical specification, with a full explanation of what we are doing
MikroTik hAP router setup. I'll configure a MikroTik Wi‑Fi router for you.
2025-03-09 · ★ 5/5
Everything's great! Thanks! I recommend it.
Everything's great! Thank you! I recommend it
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related