Self-hosted network security ratings
Network-wide blocking, VPN and security tools to run at home or on a server.
10 self-hosted network security are rated against 4 public criteria, and 10 have enough evidence for a letter grade. Of the 3 with a known jurisdiction, 2 are based in a Five Eyes country, and 3 in the wider Fourteen Eyes.
Open-source self-hosted network security only · Criteria for this category · Suggest an addition · Markdown
| Name | Grade | Score | Data | Jurisdiction | Open source | No trackers or telemetry | No ads or data sales | Independent audit |
|---|---|---|---|---|---|---|---|---|
VPN protocol and implementation built on modern cryptography such as Curve25519 and ChaCha20-Poly1305, included in the Linux kernel and available as apps for other platforms. |
Grade A | 90 | 100% | – | Yes | Yes | Yes | Partial |
Self-hosted DNS proxy and ad blocker for local networks, with per-client blocklists, conditional forwarding, caching and support for encrypted upstream DNS such as DoH and DoT. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Web content filtering proxy for Linux and BSD that blocks sites by phrase, URL, file type and MIME type, running as an explicit or transparent proxy or an ICAP server. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Linux-based firewall distribution for routers and gateways, with a web interface, intrusion prevention, VPN support and add-on packages. |
Grade B | 80 | 100% | Germany Fourteen Eyes | Yes | Yes | Yes | No |
Self-hosted DNS sinkhole that blocks ads, trackers and malware domains for every device on a network, with a web interface for query logs and blocklist management. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Set of shell scripts that install and manage a WireGuard or OpenVPN server on a Raspberry Pi or Debian-based server. The maintainers announced the end of the project and it is maintained only on a best-effort basis. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Self-hosted authoritative and recursive DNS server with a web console, network-wide ad and tracker blocking, and support for DNS-over-TLS, DNS-over-HTTPS and DNS-over-QUIC. |
Grade B | 80 | 100% | – | Yes | Yes | Yes | No |
Open-source VPN daemon that uses TLS for key exchange and runs over UDP or TCP, widely used for self-hosted site-to-site and remote-access VPNs. |
Grade C | 60 | 100% | United States Five Eyes | Yes | No | Yes | Partial |
Open-source network security monitor that passively analyzes traffic and writes detailed logs of connections and protocols, used for intrusion detection, incident response and threat hunting. |
Grade D | 50 | 100% | – | Yes | No | Yes | No |
FreeBSD-based firewall and router distribution from Netgate with a web interface, VPN and package system, available as the open-source Community Edition and the closed pfSense Plus. |
Grade F | 35 | 100% | United States Five Eyes | Partial | No | Yes | No |
Questions
What is the most private option among self-hosted network security?
No pick has been made yet. The table above is sorted by score, based on public evidence.
How are self-hosted network security rated?
Each entry answers 4 questions: open source, no trackers or telemetry, no ads or data sales and independent audit. Answers need links to evidence. See the full criteria.
Does jurisdiction matter?
Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.