3 ms·
OpenZiti has some similarities to Wireguard/Tailscale... lets give s description of the former as thats then opensource vs opensource. Wireguard is built to be
by PLG88 4y ago
OpenZiti has some similarities to Wireguard/Tailscale... lets give s description of the former as thats then opensource vs opensource.
Wireguard is built to be a better VPN and really cares about "connecting machines" and not so much about connecting "services". OpenZiti cares about connecting "services" with zero trust networking concepts, including least privilege, micro-segmentation, and attribute-based access (though you can also set up a whole CIDR if you want). OpenZiti also uses the embedded identity to build outbound only connections into a mesh (think Cloudflare tunnels), so we can close all inbound ports. This can all be surmised as WG being 'default-open' whereas ZT is 'default-closed'.
Wireguard uses UDP and hole punching to build P2P connections, while OpenZiti uses TCP and a mesh overlay (with the outbound only at source and destination). This is how Tailscale implements Wireguard to ensure it works easily in all situations. It also allows you to control the internet routing and provide higher redundancy, resiliency and control for routing traffic according to policy (e.g., low latency or geo-restrictions).
Due to OpenZiti's uses of identity in the endpoints and fabric for routing, you also get a private DNS and unique naming (e.g., send from IoT endpoint service to IoT server rather than from 192.xxx.xxx.xx to 100.xxx.xxx.xx). This also means we do not need to use floating or static IPs, easily handle overlapping, no need for port forwarding.
Finally, where it really differentiates is that with OpenZiti you canstart with "network-based zero trust" (installing a router in private IP space) and progress to "host-based zero trust" (using an agent/tunneller), it also have a suite of SDKs to embed in apps themselves for "application-based zero trust". This allows it to run clientless, in serverless, in confidential computing and more.
P.S., Wireguard get a lot of well-deserved love! OpenZiti uses the Windows TUN (WinTun) that the Wireguard project made as (at least) part of our Windows tunneler. Thanks, Wireguard!