WZ-IT Logo
NetBird Logo

NetBird

NetBird is a modern, open-source VPN solution that provides secure, peer-to-peer connectivity without the complexity of traditional VPN setups. As a 100% self-hostable alternative to Tailscale, NetBird offers complete control over your network infrastructure.

All Expertises

Trusted by leading companies

  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • NextGym
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy
  • Negosh
  • ABCO Water
About the Technology

About NetBird

Technology Logo

NetBird is a modern, open-source VPN solution that provides secure, peer-to-peer connectivity without the complexity of traditional VPN setups. As a 100% self-hostable alternative to Tailscale, NetBird offers complete control over your network infrastructure.

With 16.8k+ GitHub stars and fully open-source architecture, NetBird enables zero-trust networking using WireGuard protocol. Unlike proprietary solutions, both the client and coordination server are completely open source.

Open Source
Self-Hosted
Enterprise Ready
GDPR compliant

WZ-IT & NetBird

We install, host and operate NetBird for your company - either on our secure, GDPR-compliant infrastructure in Germany or other locations, as well as on-premise in your own environment.

With 24/7 monitoring, enterprise support, backups and professional maintenance, we ensure maximum availability and reliable operation of your NetBird instance.

Features

Self-Hosted Features

Feature icon

Complete Infrastructure Control

Full ownership of all components including management server, relay servers, and client agents. No vendor lock-in or external dependencies.

Feature icon

100% Open Source

Both client and coordination server are fully open source, allowing complete customization, security audits, and community contributions.

Feature icon

Advanced Network Routes

Connect entire LANs, VPCs, and office networks without installing agents on every device. Support for high availability routing and traffic masquerading.

Feature icon

Granular Access Policies

Define precise access control rules between peer groups, networks, and resources with support for protocol-specific restrictions (TCP/UDP/ICMP).

Feature icon

DNS Routes & Wildcard Domains

Route traffic based on domain names with support for wildcard domains (*.company.internal) and dynamic DNS resolution every 60 seconds.

Feature icon

Service Users & API Access

Create non-interactive service accounts with API tokens for automation, infrastructure-as-code tools like Terraform, and third-party integrations.

Feature icon

Flexible Database Support

Choose between SQLite for simple deployments or PostgreSQL for enterprise-scale installations with activity events logging support.

Feature icon

Role-Based Access Control

Five user roles (Owner, Admin, Network Admin, Auditor, User) with granular permissions for team management and security compliance.

Feature icon

High Availability Routes

Multiple routing peers for the same network with automatic failover, load balancing, and metric-based priority selection for critical infrastructure.

You got questions? We are here to help!
Use Cases

Perfect for These Use Cases

Serverless Functions & FaaS

Connect AWS Lambda, Azure Functions, and other serverless environments to your private infrastructure without exposing services to the internet. Access databases, APIs, and internal resources securely.

And much more

The perfect solution for your individual requirements

Demo

NetBird in Action

NetBird Screenshot
Video Demo
Playing the video will transmit data to YouTube. Details in the YouTube privacy policy.

Experience NetBird in Action

See how simple and efficient NetBird works in practice. From installation to productive use.

Live DemoStep by StepBest Practices
Professional Installation Service

NetBird Installation & Einrichtung

Professional installation on your infrastructure – on-premise, cloud or hybrid

On-Premise

In your data center

  • Installation on bare-metal, VM or Docker
  • Optimal performance configuration
  • Integration with existing Active Directory/LDAP
  • SSL certificate & reverse proxy
  • Backup strategy & monitoring
  • Security hardening following best practices
  • Documentation & training

Cloud Installation

AWS, Azure, Hetzner & more

  • Installation on AWS, Azure, GCP, Hetzner
  • Terraform/IaC setup (optional)
  • Kubernetes or Docker Compose
  • Auto-scaling configuration
  • Load balancer & CDN integration
  • CloudWatch/monitoring setup
  • Cost optimization & best practices

Enterprise Setup

High-availability setup with comprehensive security and compliance features

  • High-availability cluster setup
  • VPN access (e.g. WireGuard, NetBird, Tailscale)
  • SSO integration (e.g. Keycloak, Authentik, Azure AD)
  • Multi-factor authentication (MFA)
  • Audit logging & compliance
  • Disaster recovery plan
  • Custom security policies
  • Dedicated contact person

Security & Secure Access

Secure access and access control for your installation

VPN Access

WireGuard, NetBird or Tailscale

SSO Integration

Keycloak, Authentik, Azure AD

Multi-Factor Auth

TOTP, WebAuthn, YubiKey

Firewall & Hardening

Fail2Ban, Rate Limiting, IP Whitelisting

Secure Access via VPN

We set up secure VPN access to your installation – ideal for remote work and external employees.

  • Zero-Trust Network Access (ZTNA)
  • Encrypted connections
  • Easy client setup for all devices
  • Centralized access management
Supported VPN Solutions:
WireGuard
NetBird
Tailscale
Headscale
OpenVPN
Cloudflare Tunnel

What's Included in the Service

Full-service installation with no hidden costs

✓ Complete installation & configuration
✓ SSL certificate & reverse proxy setup
✓ Backup strategy & disaster recovery
✓ Performance optimization & tuning
✓ Security hardening following OWASP
✓ Monitoring & logging setup
✓ Documentation & best practices
✓ Administrator training (remote)
✓ 30 days email support included
✓ Dedicated contact person
✓ Optional integration: LDAP/AD, SSO, MFA
✓ Update strategy & patch management setup

NetBird on Your Own Infrastructure

Want to self-host NetBird and keep full control over your VPN infrastructure? We help you with installation and configuration – on your servers.

Bring Your Own Infrastructure

We install and configure NetBird on your existing infrastructure – Hetzner, AWS, Azure, or on-premise.

To Our Installation Service
RECOMMENDED

Managed VPN Flatrate

Don't want to self-host? Our VPN Flatrate: Fully Managed NetBird at a fixed price – unlimited users, hosted in Germany.

View VPN Flatrate

Want to self-host NetBird?

We help with installation, configuration, and operations.

1/2 – Interest50%

Response within 24h – no spam, no sales pressure.

Manage Your Stack in the Customer Portal

As a Managed Service customer at WZ-IT, you have access to our exclusive portal: Monitor your infrastructure in real-time, schedule maintenance, request quotes, and get direct support – all in one central location.

  • Real-time infrastructure status
  • Reschedule maintenance windows yourself
  • View complete access logs
  • Direct support without detours
Explore Portal
WZ-IT Customer Portal Dashboard

Topics

General Information

NetBird is an open-source platform for zero-trust networks. It enables secure connections between devices, servers, and cloud resources – without a classic VPN gateway. Connections run peer-to-peer and are established automatically when devices come online.

NetBird uses a modern zero-trust model: Each connection is individually authenticated, access is only granted when needed, and there is no central gateway infrastructure that becomes a bottleneck. The result is faster, more secure, and easier-to-scale networks.

Yes, NetBird uses WireGuard as the protocol for encryption. WireGuard is fast, modern, and is considered the most secure VPN protocol currently available. NetBird builds on it and adds management, authentication, and zero-trust features.

Self-Hosting & Installation

Yes, NetBird is fully open source and can be completely self-hosted. This includes the management server, relay servers, and authentication. This way you maintain full control over your network infrastructure.

Initial setup is possible in just a few minutes: create an account, install the client, done. Self-hosting requires a bit more effort, but WZ-IT offers pre-configured installations and a VPN Flatrate based on NetBird.

Yes, NetBird provides a web dashboard for management. Here you can view and control peers, access policies, and network configurations. The interface is intuitive and does not require deep networking knowledge.

NetBird vs. Alternatives

Both are based on WireGuard and enable peer-to-peer connections. The main difference: NetBird is fully open source and can be completely self-hosted. Tailscale offers a cloud variant, but the control plane is proprietary. If you want full control, NetBird is the better choice.

Headscale is an open-source implementation of the Tailscale control server. It enables self-hosting of Tailscale clients. NetBird, on the other hand, is an independent project with its own architecture, its own client, and a more comprehensive feature set for zero-trust networks.

NetBird is ideal when you need complete control over your infrastructure, want to implement advanced access policies, or value an independent open-source project. Tailscale is better suited for quick cloud setups, while Headscale bridges the gap for Tailscale users with self-hosting requirements.

Enterprise & Security

Absolutely. NetBird supports SSO, role-based access control, audit logs, and can be integrated into existing IT security concepts. For companies with high compliance requirements, the self-hosting option is particularly attractive.

Yes, NetBird supports Single Sign-On (SSO) via common identity providers like Okta, Azure AD, Google Workspace, or Keycloak. This also enables multi-factor authentication (MFA) if the IdP supports it.

Since NetBird is open source, the entire code can be viewed and audited. This is particularly important for companies seeking security certifications or needing to meet compliance requirements. Additionally, activities are logged in the dashboard.

Technical Details

NetBird uses modern techniques like STUN, TURN, and ICE for NAT traversal. This means: Even devices behind firewalls or NAT routers can establish direct peer-to-peer connections – without port forwarding or complicated firewall rules.

Yes, NetBird supports site-to-site connections. You can connect entire networks with each other – ideal for location networking, connecting cloud resources, or hybrid infrastructures.

NetBird is still a relatively young project – this means not all features are as mature as with established enterprise VPNs. The community is also smaller than Tailscale. If you need production-ready stability, you should rely on an experienced partner like WZ-IT.

Industry-leading companies rely on us

  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • NextGym
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy
  • Negosh

What do our customers say?

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea – we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

E-Mail
[email protected]

Trusted by leading companies

  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • NextGym
  • Maho Management
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy
  • Negosh
  • ABCO Water
Timo Wevelsiep & Robin Zins - CEOs of WZ-IT

Timo Wevelsiep & Robin Zins

CEOs of WZ-IT

1/3 – Topic Selection33%

What is your inquiry about?

Select one or more areas where we can support you.