ZTXGate vs NetBird
ZTXGate and NetBird overlap in several areas that make this comparison particularly useful: both use WireGuard-based connectivity, both can be operated outside a mandatory vendor-hosted control plane, and both can fit environments that require self-hosting.
The products are not architecturally identical, however. NetBird is fundamentally a coordinated WireGuard peer-networking platform with cloud-hosted and self-hosted options. ZTXGate is a ZTNA gateway/proxy platform built around resource policy, managed WireGuard access, clientless HTTP/HTTPS access, and customer- or MSP-operated deployment.
At a Glance
| Area | ZTXGate | NetBird |
|---|---|---|
| Primary architecture | ZTNA gateway/proxy with resource policy | WireGuard peer networking with centralized management/policy |
| Hosted option | Optional CoreZT-operated ZTXHub provides lifecycle functions, not core access control | NetBird Cloud provides hosted management/control services |
| Self-hosting | Customer- or MSP-operated ZTXGate | Supported self-hosted NetBird edition |
| Air-gapped suitability | Supported standalone deployment | NetBird explicitly lists air-gapped networks as a self-host use case |
| Managed connectivity | WireGuard-based access through ZTXGate | Direct peer-to-peer where possible, with relay fallback |
| Browser access | Licensed HTTP/HTTPS clientless proxy | Browser Client currently documents SSH and RDP using a WASM NetBird peer |
| Identity | OIDC + SCIM; integrated ZTXBAS option | Built-in local users in current self-hosted edition, plus optional external IdPs; enterprise features vary by edition/license |
| Resilience | Backup/restore DR; no conventional HA clustering | Cloud includes managed HA; self-hosted HA/relay design is customer responsibility |
| Open source | No | Yes, with commercial offerings/features around the platform |
Self-hosting and WireGuard are therefore shared territory. A useful comparison needs to go deeper than those labels.
Different Core Architectures
NetBird coordinates WireGuard peers so machines can establish secure connectivity, directly where possible and through relays when necessary. Its management layer distributes network and access-control information to those peers.
ZTXGate uses WireGuard as the secure transport for managed access, but the central product abstraction is the ZTXGate enforcement environment and its resource policy. The same product can also enforce HTTP/HTTPS access through a licensed clientless proxy path.
A simplified distinction is:
NetBird:
peer identity + WireGuard network + centralized policy
ZTXGate:
identity/device policy + gateway/proxy enforcement + authorized resource
Neither model is inherently better. They optimize for different access patterns.
Self-Hosting
NetBird currently offers both cloud-hosted and self-hosted deployment models. Its documentation says the self-hosted edition can run on your own servers and, since recent versions, can use built-in local user management without requiring an external IdP.
Self-hosted NetBird also means operating the components required for management, signaling, relay, identity, backup, and availability according to the selected architecture.
ZTXGate is designed to be deployed in infrastructure operated by the customer or an MSP. Core access operation can remain independent of a CoreZT-hosted control plane.
This means self-hosting itself is not a unique ZTXGate differentiator. The meaningful comparison is what each self-hosted product asks the operator to run and what access model it provides.
Compare self-hosted and cloud ZTNA models
WireGuard Usage
Both products use WireGuard, but WireGuard serves the surrounding architecture differently.
NetBird uses WireGuard peer connectivity as the foundation of its private network. The management layer coordinates peers and access controls.
ZTXGate uses WireGuard as secure transport for managed access while ZTXGate policy determines which user/device may reach which resource.
In both cases, WireGuard is transport rather than the complete authorization system.
Learn more about WireGuard and ZTNA
Browser and Clientless Access
The two products currently document different browser-access models.
NetBird's Browser Client runs a NetBird peer as WebAssembly in the browser and currently documents direct browser access to SSH and RDP resources. It creates temporary peer/access state for the session.
ZTXGate's licensed clientless capability is focused on HTTP and HTTPS applications. The ZTXGate proxy terminates the incoming web connection, applies supported policy, and establishes the authorized outbound connection to the protected application.
These are not equivalent implementations:
- NetBird Browser Client brings selected remote-access protocols into a browser-based peer model.
- ZTXGate clientless access acts as an HTTP/HTTPS policy-enforcing proxy.
The right choice depends on which applications and protocols need clientless access.
Identity
Current self-hosted NetBird documentation includes built-in local user management and optional OIDC-compatible identity providers. Commercial licensing applies to some enterprise capabilities such as SCIM in self-hosted deployments.
ZTXGate supports OIDC authentication and SCIM identity lifecycle integration. When licensed, ZTXBAS is tightly integrated into ZTXGate as a library and does not require a separate ZTXBAS service deployment.
Standalone ZTXBAS is also available free for developers integrating biometric authentication into their own applications; that is a different use case from the licensed ZTXGate integration.
Device and Posture
Both products incorporate device-related policy, but implementations and integrations differ.
ZTXGate supports posture integrations including Microsoft Intune, Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, and Jamf.
NetBird provides device/peer policy controls and documents posture capabilities and enterprise EDR integrations in its current editions.
For a real evaluation, compare the specific posture signal you need rather than simply checking whether a “device posture” feature exists.
Air-Gapped Operation
Both products can be relevant to disconnected environments.
NetBird's current documentation explicitly lists air-gapped networks among the scenarios for its self-hosted edition.
ZTXGate can also remain fully air-gapped in standalone mode. In that model, licensing and software updates are handled manually. When licensed, integrated ZTXBAS remains available inside the ZTXGate deployment for phishing-resistant biometric authentication, while external cloud services naturally require connectivity if selected.
This is therefore another area where ZTXGate should not claim uniqueness.
The practical comparison is the number of components, identity model, update process, operational burden, access architecture, and protocols required in the isolated environment.
Availability and Disaster Recovery
NetBird Cloud provides vendor-managed high availability. In a self-hosted NetBird deployment, the operator is responsible for the availability of management and relay components and can design more complex deployment patterns as required.
ZTXGate does not currently implement conventional HA clustering. Its admin portal supports periodic backups that can be restored into a fresh deployment for disaster recovery.
Organizations requiring automatic failover should evaluate this distinction carefully.
Which Architecture May Fit Better?
NetBird may fit well when:
- you want an open-source WireGuard networking platform
- direct peer connectivity is a central design goal
- you want the choice between NetBird Cloud and a self-hosted edition
- browser-based SSH/RDP is an important access pattern
- your team is comfortable operating the components required for the chosen self-hosted topology
ZTXGate may fit well when:
- you want a commercially supported ZTNA gateway/proxy deployment operated by your organization or MSP
- policy-centric access through a dedicated enforcement environment matches your architecture
- clientless HTTP/HTTPS access is important
- tightly integrated phishing-resistant ZTXBAS biometric authentication is useful
- you want an optional vendor-operated lifecycle service without making that service mandatory for core access
These are architecture and operating-model considerations rather than an overall product ranking.
Official Sources Used
Competitor facts were verified against current NetBird first-party documentation: