27.06.2026
Tailscale Pricing 2026: When Self-Hosting Headscale or NetBird Beats Seat Pricing
Two news items reshaped the market for modern mesh VPNs in 2026. Tailscale overhauled its pricing and now bills business plans per seat. And NetBird,...
WireGuard is an extremely simple, fast, modern, and self-hosted VPN that uses state-of-the-art cryptography.
The following are trademarks of their respective owners: WireGuard (Jason A. Donenfeld (WireGuard LLC)). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.

WireGuard is an extremely simple, fast, modern, and self-hosted VPN that uses state-of-the-art cryptography.
Thanks to direct integration into the Linux kernel and a compact codebase, WireGuard is faster than solutions like IPSec and OpenVPN. WireGuard is ideal for use as an isolated corporate network on servers, routers, desktops, and mobile devices.
We install, host and operate WireGuard for your company - either on our secure, GDPR-compliant infrastructure in Germany or other locations, as well as on-premise in your own environment.
With 24/7 monitoring, enterprise support, backups and professional maintenance, we ensure maximum availability and reliable operation of your WireGuard instance.
Configuration via simple key exchange, similar to SSH.
Uses state-of-the-art techniques like Curve25519 and ChaCha20.
Compact codebase for easy review and high security.
Thanks to kernel integration and optimized cryptographic primitives, impressive speeds.
Tight coupling of identity and IP assignment ensures the highest security.
Available for Linux, Windows, macOS, BSD, iOS, and Android.
WireGuard follows the model of SSH: both parties exchange public keys, and cryptokey routing maps each key to its allowed tunnel IPs. The project explicitly declares key distribution and pushed configurations "out of scope" - these tasks are left to other layers so the protocol stays lean instead of inheriting the complexity of IKE or OpenVPN.
For business use this means concretely: these building blocks are not included out of the box.
This is exactly the gap that management layers built on WireGuard close: NetBird adds user management, SSO, access policies and automatic key distribution as a standalone product. If you want to use the official Tailscale clients with a self-hosted control server, Headscale is the matching alternative.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
High-availability setup with comprehensive security and compliance features
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Keycloak, Authentik, Azure AD
TOTP, WebAuthn, YubiKey
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
Since March 2020, WireGuard has been part of the Linux kernel (from version 5.6) - with clients for Windows, macOS, BSD, iOS and Android. In the project's official benchmarks, WireGuard reached gigabit line rate without maxing out the CPU:
1.011 Mbit/s
Gigabit line rate, CPU not maxed - ping 0.403 ms
825-881 Mbit/s
Depending on cipher suite
258 Mbit/s
CPU fully maxed - ping 1.541 ms
In fairness: the WireGuard project itself points out that these benchmarks are old. The tendency still holds, however - WireGuard edges out IPsec, while OpenVPN remains far behind.
Open source enterprise-ready for productive workloads - we run your applications with highest security standards and enterprise support
Open source software for business-critical processes requires professional maintenance, continuous updates, and enterprise-grade support. With our WireGuard Enterprise Managed Hosting, you get the necessary infrastructure and support to reliably operate open source in production environments. Backups, SLAs, telephone support, and personal contact - so you can focus on your core business.
We also offer customized WireGuard Enterprise solutions for your specific requirements. Contact us for an individual quote.
Managed VPN at a fixed price - based on WireGuard & NetBird. Unlimited users & devices, hosted in Germany.
Yes. WireGuard has been part of the Linux kernel since March 2020 (from version 5.6) and is available for Windows, macOS, BSD, iOS and Android. It is also the technical foundation of modern overlay networks such as NetBird, Tailscale and Headscale - a clear signal of the protocol's maturity.
In the project's official benchmarks, WireGuard reached 1,011 Mbit/s (gigabit line rate without maxing out the CPU), while OpenVPN maxed out the CPU at 258 Mbit/s. Latency was also significantly lower at 0.403 ms versus OpenVPN's 1.541 ms. The benchmarks are old - the project points this out itself - but the tendency continues to hold in practice.
In the official benchmarks, WireGuard led with 1,011 Mbit/s ahead of IPsec (825-881 Mbit/s depending on cipher suite) - with simpler configuration and a much smaller codebase. The measurements are old, but the ranking has held.
WireGuard itself deliberately ships without user management, SSO or automatic key distribution - each peer is a manually maintained key pair with a fixed tunnel IP. From a handful of devices onwards, a management layer such as NetBird or Headscale pays off, managing users, access policies and keys centrally.
No - deliberately so. The project explicitly declares key distribution and pushed configurations "out of scope" and follows the SSH model: both parties exchange public keys. SSO, key rotation and dynamic IP assignment are handled by management layers such as NetBird or Headscale built on top of WireGuard.
Yes. We analyse existing setups, harden the configuration, add monitoring and alerting, and support migration to a management layer such as NetBird or Headscale where needed - on-premise, in your cloud or operated GDPR-compliant from Germany.
Good choice - we'll help you get started or with operations.
As a Managed Service customer at WZ-IT, you have access to our exclusive portal: Monitor your infrastructure in real-time, schedule maintenance, request quotes, and get direct support - all in one central location.

In-depth knowledge from our remote access knowledge base.
27.06.2026
Two news items reshaped the market for modern mesh VPNs in 2026. Tailscale overhauled its pricing and now bills business plans per seat. And NetBird,...
24.06.2026
Anyone who services machines and plants remotely knows the little boxes in the control cabinet: Ewon Cosy from HMS Networks, plus the Talk2M cloud that...
23.06.2026
On 26 February 2026, the US agency CISA issued a Binding Operational Directive ordering an actively exploited FortiOS zero-day to be patched or disabled within...
13.05.2026
On 12 May 2026 the OPNsense team shipped version 26.1.8 with patches for two critical remote code execution flaws. CVE-2026-44194 (CVSS 9.1, GitHub advisory GHSA-f59w-m967-9rf6)...
11.05.2026
A Cisco ASA vulnerability from September 2025 is still being actively exploited in May 2026. Seven months after the patch, CrowdSec counts 292 source IPs...
These solutions are often used together with WireGuard
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
