// Engineering Log

ZeroTier and NetBird: alternatives to Tailscale — what they are and how they differ

Published on 2026-09-22

// Fast route

This article belongs to the topic Networking and routing.

ZeroTier and NetBird are services for creating a private network between your devices over the Internet, main alternatives to Tailscale. All three solve the same problem: computers, servers and phones see each other by internal addresses without port forwarding and manual tunnel setup. They differ by network design, licenses, and whether you can host the control server yourself.

What is ZeroTier

ZeroTier is one of the oldest services of this type. Unlike Tailscale and NetBird, it does not use WireGuard, but works on its own protocol and builds a layer-2 virtual network (L2) — analogous to an Ethernet switch stretched over the Internet.

According to ZeroTier documentation, the system consists of two layers:

  • VL1 — peer-to-peer transport: devices discover each other and establish encrypted connections, using relays when necessary;
  • VL2 — Ethernet virtualization, similar to VXLAN: isolated networks, broadcast and multicast traffic, rules and access certificates.

The network is managed by a controller: it grants devices permission to join and provides configuration. Usually the cloud controller my.zerotier.com is used, but the documentation explicitly allows a self-hosted controller — at the cost of working with JSON configuration or third-party interfaces.

The main practical feature of ZeroTier is the layer-2 network. Devices are in the same broadcast domain, so discovery protocols that need a “real” local network work: some games, industrial and IoT devices, legacy systems. Tailscale and NetBird do not provide this — they operate at layer 3 (IP).

License. The main ZeroTierOne code is distributed under the Mozilla Public License, but the repository includes a nonfree/ directory — its sources are readable but distributed under a non-free license. Therefore “ZeroTier is a fully open project” is not entirely correct.

What is NetBird

NetBird is an open mesh VPN platform based on WireGuard, closest to Tailscale in architecture, but with the ability to fully deploy it yourself. According to the project documentation, NetBird consists of four parts:

  • Management — coordination server with a web panel: stores network state and public keys, authenticates users, distributes changes;
  • Signal — helps devices agree on a direct connection; no traffic goes through it or is stored;
  • Relay — relay for cases when a direct connection is impossible; traffic through it remains encrypted;
  • client on devices — creates keys and WireGuard tunnels (on Linux it can use the kernel WireGuard).

Connections are established using ICE and STUN — the same NAT traversal techniques used in WebRTC.

License. Most of the repository is BSD-3-Clause, while the server components management/, signal/ and relay/ are under AGPLv3. This is not an obstacle for self-hosting, but if you modify the server and provide it as a service to others, AGPLv3 requires you to open your changes.

Self-hosted server. For quick deployment there is an official script:

bash
export NETBIRD_DOMAIN=netbird.example.ru
curl -fsSL https://github.com/netbirdio/netbird/releases/latest/download/getting-started.sh | bash

For production deployment you will need a server with a domain name and open ports for the web panel, Signal and Relay, as well as an account provider — built-in or external, for example Keycloak.

Comparison as of September 2026

TailscaleZeroTierNetBird
ProtocolWireGuardproprietaryWireGuard
Network layerL3 (IP)L2 (Ethernet)L3 (IP)
Licenseclient core — BSD-3 (graphical clients on macOS, iOS, Windows are closed-source), coordination server — closed serviceMPL + nonfree nonfree/ partBSD-3 (client) and AGPLv3 (server)
Free cloud tierPersonal: up to 6 users, unlimited devicesPersonal: 10 devices, 1 network, non-commercial use onlyFree: up to 5 users and 100 machines
Paid plansStandard $8, Premium $18 per user per monthEssential $18 and Scale $179 per monthTeam €6, Business €12 per user per month
Own management serverno (there is unofficial Headscale)yes, own controlleryes, built-in

Prices are taken from the pricing pages on tailscale.com, zerotier.com and netbird.io. Note ZeroTier’s limitation: the free Personal tier allows only personal non-commercial use; a company needs a paid plan.

How they differ in practice

Tailscale — the fastest to start and the most reliable NAT traversal, but the coordination server is cloud-only.

ZeroTier — the only one of the three with a layer-2 network. Chosen when broadcast protocols or a transparent “single LAN” are needed. The trade-off is a proprietary protocol instead of WireGuard and commercial restrictions on the free tier.

NetBird — an open alternative to Tailscale with a full self-hostable server and web panel. The best option if the management server must run in your infrastructure — for example, in a Russian data center for data residency requirements.

How to choose

  • Need something quick, for a few devices, without your own server — Tailscale or cloud NetBird.
  • Company, data and management must be on-premises — NetBird on your own server or Headscale.
  • Need an L2 network: device discovery, broadcast traffic — ZeroTier.
  • Need maximum control and the minimum number of components — manual WireGuard configuration.

For Russian companies there are two common limitations of cloud plans: foreign services cannot be paid with a Russian card — Visa and Mastercard suspended operations in Russia in 2022 — and management servers are located abroad. Free tiers and self-hosted servers are not affected by the first limitation.

Common mistakes

  • Using free ZeroTier in a commercial project — violation of the Personal tier terms.
  • Mixing network layers. Expecting broadcast protocols to work over Tailscale or NetBird, which is only possible with ZeroTier.
  • Self-hosted server without redundancy and backups. The management server becomes a critical element of the network: without it you cannot add a new device or change rules.
  • Default access rules. In all three systems you should immediately restrict which devices and users can see which resources.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Reviews

Related reviews

ladohinpy

MikroTik hAP router setup. I'll set up a MikroTik Wi‑Fi router for you.

2025-07-21 · ★ 5/5

An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed what we'd been racking our brains over for days! I'm sure this won't be the last time we rely on his boundless professionalism.

An excellent specialist, a savvy expert, and a wonderful person. In an hour he fixed for us what we had been scratching our heads over for days! I'm sure this won't be the first time we make use of his boundless …

Ravenor

MikroTik hAP router setup. I'll configure a MikroTik Wi-Fi router for you.

2025-05-28 · ★ 5/5

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply