Skip to main content

ZTXGate vs NetBird

ZTXGate and NetBird overlap in several areas that make this comparison particularly useful: both use WireGuard-based connectivity, both can be operated outside a mandatory vendor-hosted control plane, and both can fit environments that require self-hosting.

The products are not architecturally identical, however. NetBird is fundamentally a coordinated WireGuard peer-networking platform with cloud-hosted and self-hosted options. ZTXGate is a ZTNA gateway/proxy platform built around resource policy, managed WireGuard access, clientless HTTP/HTTPS access, and customer- or MSP-operated deployment.

At a Glance

AreaZTXGateNetBird
Primary architectureZTNA gateway/proxy with resource policyWireGuard peer networking with centralized management/policy
Hosted optionOptional CoreZT-operated ZTXHub provides lifecycle functions, not core access controlNetBird Cloud provides hosted management/control services
Self-hostingCustomer- or MSP-operated ZTXGateSupported self-hosted NetBird edition
Air-gapped suitabilitySupported standalone deploymentNetBird explicitly lists air-gapped networks as a self-host use case
Managed connectivityWireGuard-based access through ZTXGateDirect peer-to-peer where possible, with relay fallback
Browser accessLicensed HTTP/HTTPS clientless proxyBrowser Client currently documents SSH and RDP using a WASM NetBird peer
IdentityOIDC + SCIM; integrated ZTXBAS optionBuilt-in local users in current self-hosted edition, plus optional external IdPs; enterprise features vary by edition/license
ResilienceBackup/restore DR; no conventional HA clusteringCloud includes managed HA; self-hosted HA/relay design is customer responsibility
Open sourceNoYes, with commercial offerings/features around the platform

Self-hosting and WireGuard are therefore shared territory. A useful comparison needs to go deeper than those labels.

Different Core Architectures

NetBird coordinates WireGuard peers so machines can establish secure connectivity, directly where possible and through relays when necessary. Its management layer distributes network and access-control information to those peers.

ZTXGate uses WireGuard as the secure transport for managed access, but the central product abstraction is the ZTXGate enforcement environment and its resource policy. The same product can also enforce HTTP/HTTPS access through a licensed clientless proxy path.

A simplified distinction is:

NetBird:
peer identity + WireGuard network + centralized policy

ZTXGate:
identity/device policy + gateway/proxy enforcement + authorized resource

Neither model is inherently better. They optimize for different access patterns.

Self-Hosting

NetBird currently offers both cloud-hosted and self-hosted deployment models. Its documentation says the self-hosted edition can run on your own servers and, since recent versions, can use built-in local user management without requiring an external IdP.

Self-hosted NetBird also means operating the components required for management, signaling, relay, identity, backup, and availability according to the selected architecture.

ZTXGate is designed to be deployed in infrastructure operated by the customer or an MSP. Core access operation can remain independent of a CoreZT-hosted control plane.

This means self-hosting itself is not a unique ZTXGate differentiator. The meaningful comparison is what each self-hosted product asks the operator to run and what access model it provides.

Compare self-hosted and cloud ZTNA models

WireGuard Usage

Both products use WireGuard, but WireGuard serves the surrounding architecture differently.

NetBird uses WireGuard peer connectivity as the foundation of its private network. The management layer coordinates peers and access controls.

ZTXGate uses WireGuard as secure transport for managed access while ZTXGate policy determines which user/device may reach which resource.

In both cases, WireGuard is transport rather than the complete authorization system.

Learn more about WireGuard and ZTNA

Browser and Clientless Access

The two products currently document different browser-access models.

NetBird's Browser Client runs a NetBird peer as WebAssembly in the browser and currently documents direct browser access to SSH and RDP resources. It creates temporary peer/access state for the session.

ZTXGate's licensed clientless capability is focused on HTTP and HTTPS applications. The ZTXGate proxy terminates the incoming web connection, applies supported policy, and establishes the authorized outbound connection to the protected application.

These are not equivalent implementations:

  • NetBird Browser Client brings selected remote-access protocols into a browser-based peer model.
  • ZTXGate clientless access acts as an HTTP/HTTPS policy-enforcing proxy.

The right choice depends on which applications and protocols need clientless access.

Explore Clientless ZTNA

Identity

Current self-hosted NetBird documentation includes built-in local user management and optional OIDC-compatible identity providers. Commercial licensing applies to some enterprise capabilities such as SCIM in self-hosted deployments.

ZTXGate supports OIDC authentication and SCIM identity lifecycle integration. When licensed, ZTXBAS is tightly integrated into ZTXGate as a library and does not require a separate ZTXBAS service deployment.

Standalone ZTXBAS is also available free for developers integrating biometric authentication into their own applications; that is a different use case from the licensed ZTXGate integration.

Device and Posture

Both products incorporate device-related policy, but implementations and integrations differ.

ZTXGate supports posture integrations including Microsoft Intune, Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, and Jamf.

NetBird provides device/peer policy controls and documents posture capabilities and enterprise EDR integrations in its current editions.

For a real evaluation, compare the specific posture signal you need rather than simply checking whether a “device posture” feature exists.

Air-Gapped Operation

Both products can be relevant to disconnected environments.

NetBird's current documentation explicitly lists air-gapped networks among the scenarios for its self-hosted edition.

ZTXGate can also remain fully air-gapped in standalone mode. In that model, licensing and software updates are handled manually. When licensed, integrated ZTXBAS remains available inside the ZTXGate deployment for phishing-resistant biometric authentication, while external cloud services naturally require connectivity if selected.

This is therefore another area where ZTXGate should not claim uniqueness.

The practical comparison is the number of components, identity model, update process, operational burden, access architecture, and protocols required in the isolated environment.

Availability and Disaster Recovery

NetBird Cloud provides vendor-managed high availability. In a self-hosted NetBird deployment, the operator is responsible for the availability of management and relay components and can design more complex deployment patterns as required.

ZTXGate does not currently implement conventional HA clustering. Its admin portal supports periodic backups that can be restored into a fresh deployment for disaster recovery.

Organizations requiring automatic failover should evaluate this distinction carefully.

Which Architecture May Fit Better?

NetBird may fit well when:

  • you want an open-source WireGuard networking platform
  • direct peer connectivity is a central design goal
  • you want the choice between NetBird Cloud and a self-hosted edition
  • browser-based SSH/RDP is an important access pattern
  • your team is comfortable operating the components required for the chosen self-hosted topology

ZTXGate may fit well when:

  • you want a commercially supported ZTNA gateway/proxy deployment operated by your organization or MSP
  • policy-centric access through a dedicated enforcement environment matches your architecture
  • clientless HTTP/HTTPS access is important
  • tightly integrated phishing-resistant ZTXBAS biometric authentication is useful
  • you want an optional vendor-operated lifecycle service without making that service mandatory for core access

These are architecture and operating-model considerations rather than an overall product ranking.

Official Sources Used

Competitor facts were verified against current NetBird first-party documentation:

Explore ZTXGate · Self-Hosted ZTNA · Start Free Trial