04.10.2026
Replacing Your VPN: From Classic VPN to Zero Trust and Mesh VPN
The classic corporate VPN comes from a time when staff, servers and applications sat in one shared network. A gateway at the network edge checks...
NetBird provides a self-hostable control plane for WireGuard-based connectivity. WZ-IT plans the migration, integrates identity, policies and routing and can take over operations. Vendor licence and WZ-IT service are shown separately.
Companies worldwide trust WZ-IT
The following are trademarks of their respective owners: Tailscale (Tailscale Inc.), Headscale (the Headscale project (Juan Font Alonso)). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services. NetBird is a trademark of NetBird GmbH. WZ-IT is an official NetBird Reseller Partner. Commercial Starter and Enterprise can be purchased through WZ-IT where required; vendor licensing and WZ-IT services are itemised separately.
Hardly any team leaves Tailscale because of the technology. The three reasons we hear again and again in conversations:
The Personal plan covers up to 6 users. Standard costs $8 and Premium $18 per occupied user seat per month (as of August 2026). At 50 user seats this results in $400 or $900 per month; additional tagged resources may be billed separately.
The data plane is based on WireGuard, while the Tailscale control plane is operated as a proprietary SaaS service. Organisations with self-hosting, data-sovereignty or specific compliance requirements therefore need to assess whether this operating model fits.
The coordination layer cannot be self-hosted, the fallback relays (DERP) are operated by Tailscale, and Funnel exposes services exclusively under *.ts.net - custom domains are not possible. If you want the entire platform on your own infrastructure, you need a different foundation.
Tailscale provides an established SaaS operating model. This page is intended for teams whose seat-based billing, data-sovereignty or self-hosting requirements no longer fit that model.
Current Tailscale Standard and Premium plans are billed per occupied user seat. The table shows list prices excluding optional additional resources:
| Users | Tailscale Standard ($8/user/month) | Tailscale Premium ($18/user/month) |
|---|---|---|
| 10 | $80 per month | $180 per month |
| 25 | $200 per month | $450 per month |
| 50 | $400 per month | $900 per month |
| 100 | $800 per month | $1,800 per month |
A WZ-IT proposal cannot be compared by user count alone: it includes target architecture, infrastructure, operating scope and service level. NetBird vendor terms apply separately when Commercial Starter or Enterprise is required.
Tailscale list prices as of 6 August 2026: Personal up to 6 users, Standard $8 and Premium $18 per user seat per month. Source: tailscale.com/pricing. Additional tagged resources may be billed separately. WZ-IT is an independent service provider; all trademarks belong to their respective owners.
The choice depends on self-hosting, client compatibility, functional scope and the desired operating responsibility.
An independent open-source platform with its own control plane, dashboard, group-based access policies, SSO integration and network routes. Community Edition and commercial NetBird editions differ in scope; as an official Reseller Partner, we can supply Commercial Starter or Enterprise directly where required.
View NetBird at WZ-ITA community-maintained open-source reimplementation of the Tailscale control server that is not affiliated with Tailscale Inc. Official Tailscale clients connect to your own server. The project describes its scope as a single tailnet for personal use or smaller organisations.
View Headscale at WZ-ITIf self-hosting, your own control plane or a different operating model are not required, Tailscale may remain the appropriate solution. A migration should follow concrete technical, contractual or organisational requirements.
Four steps, no big bang: your tailnet stays in production until the last device has moved over cleanly.
We capture ACLs, tags, subnet routers, exit nodes, MagicDNS names, users and devices. This provides the target design and a technical assessment of whether NetBird, Headscale or remaining with Tailscale is appropriate.
We build management, signal and relay on your infrastructure, connect your identity provider (SSO) and translate the Tailscale ACLs into group-based access policies with groups and network routes.
Both overlays run at the same time: Tailscale stays in production while the NetBird network is brought up with a separate address range and tested against the current state. No big bang, no time pressure.
Devices and user groups switch one by one in a planned order. Tailscale remains as a rollback layer for each wave - the tailnet is only decommissioned in an orderly fashion after sign-off.
Clearly defined migration
WZ-IT builds the new secure-access path, migrates a pilot group and documents testing, rollback and the wider rollout.
The concepts largely correspond - only the names differ. The most important mappings for your inventory:
| Tailscale | NetBird | Note |
|---|---|---|
| MagicDNS | NetBird DNS | Devices are reachable via names instead of IP addresses. |
| ACLs (HuJSON policy file) | Access Policies | Group-based rules in the dashboard instead of a policy file - the access logic carries over, the syntax does not. |
| Subnet Router | Network Routes | Make entire networks reachable behind a routing peer. |
| Exit Node | Exit Node | Same concept, same name: route internet traffic via a defined peer. |
| Tailscale SSH | Identity-based SSH | Availability and scope are assessed for the deployed NetBird version and edition. |
| Funnel | No 1:1 equivalent | You publish services via your own reverse proxy such as Pangolin instead - with your own domains instead of *.ts.net. More about Pangolin |
Documented mappings reviewed in August 2026. Each item is configured from scratch in the NetBird setup and tested during parallel operation.
The usual objection to any Tailscale alternative is: "Then we have to operate it ourselves." You do not - that is exactly our offering:
Setup, operations and support for your NetBird environment without automatic WZ-IT billing per user or device. The proposal is based on architecture, infrastructure, operating scope and service level; required vendor licences are shown separately.
Enquiry
Name the tailnet, users, devices, and reason for the change. We assess NetBird, Headscale, migration, and required licences.
In-depth knowledge from our remote access knowledge base.
Answers to the most important questions
Community Edition can be self-hosted without a vendor licence; infrastructure, updates, monitoring and support still create operating effort. Commercial Starter adds high availability, SCIM and device approval for up to 50 users and 500 devices. For larger or individual requirements we assess Enterprise. WZ-IT supports selection and procurement and shows the vendor licence separately from the managed service.
Not necessarily. For up to 6 users without self-hosting requirements, the Tailscale Personal plan may be sufficient. A migration should primarily be assessed when seat-based billing, data-sovereignty or compliance requirements, or the need for a self-operated control plane conflict with the existing SaaS model.
Conceptually yes, via copy and paste no. Tailscale ACLs are a HuJSON policy file, while NetBird works with group-based access policies in the dashboard or via the API. The access logic - who may access what - can be mapped completely, but the translation is manual work. It is a fixed part of our migration package and is tested against the current state during parallel operation.
Headscale is a suitable option if you want to retain official Tailscale clients. The community-maintained project is not affiliated with Tailscale Inc. and deliberately describes its scope as a single tailnet for personal use or smaller organisations. If an independent platform with its own dashboard and a different policy model is required, we assess NetBird as an alternative.
Both have a direct equivalent: MagicDNS corresponds to NetBird DNS (devices remain reachable via names), exit nodes are also called exit nodes in NetBird, and subnet routers become network routes. The concepts move with you - they are, however, configured from scratch in the NetBird setup, which we handle as part of the migration.
That depends on the number of devices, the complexity of your ACLs and the number of subnet routers and exit nodes - a serious number only exists after the inventory, and that is exactly when we give you one. Thanks to running both overlays in parallel there is no time pressure though: every device switches individually, and Tailscale remains fully functional until the last cutover.
Yes. Both are WireGuard-based overlays with their own network interfaces. We configure the NetBird address range so it does not collide with your existing tailnet - then both networks run simultaneously during the migration, and the switch happens device by device instead of as a big-bang cutover.
On your infrastructure. Management, signal and relay services run on your servers - in your own data center or with a European provider of your choice. With Tailscale, by contrast, the coordination layer runs as SaaS operated by a US provider. It is exactly this layer - device identities, key distribution, policies - that you bring back under your own sovereignty with NetBird.
WZ-IT does not automatically bill the managed service per user or device. The proposal is based on architecture, infrastructure, operating scope and service level. Required NetBird vendor licences are shown separately; details are available on our VPN flatrate page.
No. WZ-IT has no business relationship with Tailscale Inc. or the Headscale project. WZ-IT is, however, an official NetBird Reseller Partner and can supply Commercial Starter and Enterprise. Our technical assessment still covers NetBird, Tailscale and Headscale; we only recommend migration where there is a clear technical or operational reason.
04.10.2026
The classic corporate VPN comes from a time when staff, servers and applications sat in one shared network. A gateway at the network edge checks...
24.08.2026
Mesh VPNs are usually compared in pairs: NetBird against Tailscale, Tailscale against ZeroTier, and so on. Such head-to-heads answer a specific question well, but they...
28.07.2026
NetBird has opened up its self-hosting licensing: instead of "price on request" there is now a figure on the pricing page. The Commercial Starter costs...
27.06.2026
Two news items reshaped the market for modern mesh VPNs in 2026. Tailscale overhauled its pricing and now bills business plans per seat. And NetBird,...
24.06.2026
Anyone who services machines and plants remotely knows the little boxes in the control cabinet: Ewon Cosy from HMS Networks, plus the Talk2M cloud that...
23.06.2026
On 26 February 2026, the US agency CISA issued a Binding Operational Directive ordering an actively exploited FortiOS zero-day to be patched or disabled within...
14.06.2026
NetBird is our preferred tool for secure, WireGuard-based network access following zero-trust principles: lean, open source and without classic VPN gateways. Recent releases brought several...
13.05.2026
On 12 May 2026 the OPNsense team shipped version 26.1.8 with patches for two critical remote code execution flaws. CVE-2026-44194 (CVSS 9.1, GitHub advisory GHSA-f59w-m967-9rf6)...
11.05.2026
A Cisco ASA vulnerability from September 2025 is still being actively exploited in May 2026. Seven months after the patch, CrowdSec counts 292 source IPs...
17.02.2026
<!-- wz-cta:netbird:top --> <!-- /wz-cta:netbird:top --> NetBird has released the Reverse Proxy – a feature that fundamentally changes self-hosted setups: Internal services can now be...
07.12.2025
NetBird and Twingate are both modern Zero-Trust Network Access (ZTNA) solutions aiming to replace traditional VPNs. But while Twingate relies on a proprietary cloud solution...
02.12.2025
NetBird and Enclave are both modern alternatives to traditional VPNs – but they follow different approaches. NetBird focuses on open source and complete self-hosting, while...
01.12.2025
<!-- wz-cta:netbird:top --> <!-- /wz-cta:netbird:top --> NetBird and Tailscale are both modern mesh VPNs based on WireGuard – but they follow fundamentally different philosophies. Tailscale...
30.11.2025
Traditional VPNs with central gateways are reaching their limits in modern IT environments. Mesh VPNs like NetBird and ZeroTier offer a contemporary approach: direct peer-to-peer...
These solutions are often used together with NetBird
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
“WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.”

Steve Kirchner
Managing Director, nextGYM GmbH

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.