Privacy Ratings

Open-source self-hosted network security

9 self-hosted network security whose code is public under an OSI-approved license, rated for privacy with evidence. Picks first, then by score.

  1. WireGuard Grade A

    VPN protocol and implementation built on modern cryptography such as Curve25519 and ChaCha20-Poly1305, included in the Linux kernel and available as apps for other platforms.

    GPL-2.0 for the kernel module and tools; the other implementations and apps use MIT or Apache-2.0. Source code

  2. Blocky Grade B

    Self-hosted DNS proxy and ad blocker for local networks, with per-client blocklists, conditional forwarding, caching and support for encrypted upstream DNS such as DoH and DoT.

    Apache-2.0. Source code

  3. E2Guardian Grade B

    Web content filtering proxy for Linux and BSD that blocks sites by phrase, URL, file type and MIME type, running as an explicit or transparent proxy or an ICAP server.

    GPL-2.0 and LGPL-2.1. Source code

  4. IPFire Grade B

    Linux-based firewall distribution for routers and gateways, with a web interface, intrusion prevention, VPN support and add-on packages.

    GPL-3.0. Source code

  5. Pi-hole Grade B

    Self-hosted DNS sinkhole that blocks ads, trackers and malware domains for every device on a network, with a web interface for query logs and blocklist management.

    AGPL-3.0 and EUPL-1.2. Source code

  6. PiVPN Grade B

    Set of shell scripts that install and manage a WireGuard or OpenVPN server on a Raspberry Pi or Debian-based server. The maintainers announced the end of the project and it is maintained only on a best-effort basis.

    MIT. Source code

  7. Technitium DNS Server Grade B

    Self-hosted authoritative and recursive DNS server with a web console, network-wide ad and tracker blocking, and support for DNS-over-TLS, DNS-over-HTTPS and DNS-over-QUIC.

    GPL-3.0. Source code

  8. OpenVPN Grade C

    Open-source VPN daemon that uses TLS for key exchange and runs over UDP or TCP, widely used for self-hosted site-to-site and remote-access VPNs.

    GPL-2.0. Source code

  9. Zeek Grade D

    Open-source network security monitor that passively analyzes traffic and writes detailed logs of connections and protocols, used for intrusion detection, incident response and threat hunting.

    BSD-3-Clause. Source code

Compare all 10 self-hosted network security, open source or not.