# Open-source self-hosted network security

9 open-source self-hosted network security rated against public privacy criteria.

1. [WireGuard](https://privacyratings.com/self-hosted-network-security/wireguard/): A (90/100). VPN protocol and implementation built on modern cryptography such as Curve25519 and ChaCha20-Poly1305, included in the Linux kernel and available as apps for other platforms.
2. [Blocky](https://privacyratings.com/self-hosted-network-security/blocky/): B (80/100). Self-hosted DNS proxy and ad blocker for local networks, with per-client blocklists, conditional forwarding, caching and support for encrypted upstream DNS such as DoH and DoT.
3. [E2Guardian](https://privacyratings.com/self-hosted-network-security/e2guardian/): B (80/100). Web content filtering proxy for Linux and BSD that blocks sites by phrase, URL, file type and MIME type, running as an explicit or transparent proxy or an ICAP server.
4. [IPFire](https://privacyratings.com/self-hosted-network-security/ipfire/): B (80/100). Linux-based firewall distribution for routers and gateways, with a web interface, intrusion prevention, VPN support and add-on packages.
5. [Pi-hole](https://privacyratings.com/self-hosted-network-security/pi-hole/): B (80/100). Self-hosted DNS sinkhole that blocks ads, trackers and malware domains for every device on a network, with a web interface for query logs and blocklist management.
6. [PiVPN](https://privacyratings.com/self-hosted-network-security/pivpn/): B (80/100). Set of shell scripts that install and manage a WireGuard or OpenVPN server on a Raspberry Pi or Debian-based server. The maintainers announced the end of the project and it is maintained only on a best-effort basis.
7. [Technitium DNS Server](https://privacyratings.com/self-hosted-network-security/technitium/): B (80/100). Self-hosted authoritative and recursive DNS server with a web console, network-wide ad and tracker blocking, and support for DNS-over-TLS, DNS-over-HTTPS and DNS-over-QUIC.
8. [OpenVPN](https://privacyratings.com/self-hosted-network-security/openvpn/): C (60/100). Open-source VPN daemon that uses TLS for key exchange and runs over UDP or TCP, widely used for self-hosted site-to-site and remote-access VPNs.
9. [Zeek](https://privacyratings.com/self-hosted-network-security/zeek/): D (50/100). Open-source network security monitor that passively analyzes traffic and writes detailed logs of connections and protocols, used for intrusion detection, incident response and threat hunting.

Source: https://privacyratings.com/open-source/self-hosted-network-security/
