ZeroTier

ZeroTier

Virtual Ethernet network that links remote PCs, servers and phones peer to peer, so RDP, VNC and SSH work as on one LAN. Shareware (conditionally free): ZeroTier Central has a free Personal plan for one network and up to 10 devices; larger plans are paid.

Facebook
Twitter
LinkedIn
Reddit
Telegram
WhatsApp
Shareware (conditionally free)Latest version: 1.16.2Actively developed

ZeroTier is a software-defined virtual network for admins, MSP technicians and home-lab users who want remote machines to behave as if they were plugged into the same switch. The ZeroTier download is free and the ZeroTier One client core is open source under the Mozilla Public License 2.0, while the hosted ZeroTier Central service is shareware (conditionally free): a Personal plan with one network and up to 10 devices costs nothing, larger plans are paid.

Each device runs the ZeroTier One agent, joins a network by its 16-character network ID and, once an admin authorises it, gets a managed IP on a virtual Ethernet interface. From there you use the tools you already know: Remote Desktop, VNC, SSH, SMB shares or a web console, all over an encrypted peer-to-peer link that works through most NAT routers without port forwarding.

ZeroTier at a glance

ItemDetails
Latest versionZeroTier One 1.16.2 (28 May 2026) for Windows, macOS, Linux and Docker; mobile apps 1.16.0
LicenceShareware (conditionally free): free Personal plan on ZeroTier Central; paid plans for more devices and networks. Client core under MPL-2.0, some components licensed separately
PlatformsWindows, macOS 10.13+, Linux (DEB/RPM), iOS, Android, Docker; community ports for FreeBSD and OpenWrt
DeveloperZeroTier, Inc.
Official websitezerotier.com
Best forFlat virtual LANs for remote support, labs, game servers and devices that need layer-2 behaviour

What it does

  • Creates virtual Ethernet networks identified by a 16-digit hex network ID; members get managed IPv4 and IPv6 addresses.
  • Connects peers directly with UDP hole punching and relays traffic only when a direct path is impossible.
  • Requires admin authorisation for each new member in private networks, so knowing the network ID is not enough to get in.
  • Pushes managed routes, letting one Linux box route traffic between the virtual network and a physical LAN.
  • Supports layer-2 bridging through a Linux bridge, so devices that cannot run ZeroTier can still join.
  • Runs as a service on desktops and servers and as a VPN profile on iOS and Android.
  • Offers a command-line tool, zerotier-cli, for scripted joins, status checks and diagnostics.

How IT teams use it

Join a support laptop and a remote PC to one network

  1. Sign in to ZeroTier Central and click Create A Network; note the network ID.
  2. Install ZeroTier One on both machines and join:
    zerotier-cli join <network-id>

    On Windows and macOS you can also use Join New Network in the tray menu.

  3. In Central open Members and tick Auth for each device; give them readable names.
  4. Check status with zerotier-cli listnetworks (it should say OK), then connect over RDP or VNC to the managed IP.

Route a whole office LAN through one Linux box

  1. In Central, under Settings → Managed Routes, add the office subnet via the ZeroTier IP of the Linux box.
  2. Enable forwarding: sudo sysctl -w net.ipv4.ip_forward=1 (and make it permanent in /etc/sysctl.conf).
  3. Add NAT and forwarding rules, where $PHY_IFACE is the LAN interface and $ZT_IFACE the ZeroTier one:
    sudo iptables -t nat -A POSTROUTING -o $PHY_IFACE -j MASQUERADE
    sudo iptables -A FORWARD -i $PHY_IFACE -o $ZT_IFACE -m state --state RELATED,ESTABLISHED -j ACCEPT
    sudo iptables -A FORWARD -i $ZT_IFACE -o $PHY_IFACE -j ACCEPT
  4. Save the rules (for example with iptables-persistent) so they survive a reboot.

Diagnose a slow connection

  1. Run zerotier-cli peers and look for peers marked as relayed.
  2. Allow outbound UDP (at least source port 9993 with return traffic) on the firewall at both ends.
  3. Re-check; a direct path usually brings latency down to the plain internet round-trip.

Install and first run

Windows: run the MSI installer and approve the network driver when Windows asks; without it the virtual adapter is not created. Windows 7 and Server 2012 need the legacy 1.6.6 build.

macOS: install the PKG (macOS 10.13 or newer) and allow the system extension if prompted.

Linux:

curl -s https://install.zerotier.com | sudo bash
sudo zerotier-cli info

Packages exist for Debian, Ubuntu, RHEL, CentOS and Fedora; official Docker images are available for containers and NAS devices, where native packages are deprecated.

iOS and Android: install the app from the store, add the network ID and accept the VPN prompt.

Network notes: ZeroTier listens on UDP 9993 plus a random secondary port. No inbound rule is strictly required, but strict or symmetric NAT on some enterprise firewalls forces traffic onto relays.

Limitations

  • The free Personal plan covers one network, one admin and up to 10 devices; bigger fleets need a paid plan.
  • Self-hosted and air-gapped controllers are listed only for the Enterprise tier of the hosted product.
  • iOS and Android VPN APIs do not allow multicast or broadcast, so LAN discovery does not work from phones.
  • Some enterprise firewalls (Palo Alto, SonicWall, pfSense are named in the docs) can push connections onto slower relays.
  • Like any VPN it gives network access only; you still need an RDP, VNC or SSH client for the screen or shell.

ZeroTier vs alternatives

Tailscale is layer 3 on top of WireGuard, with identity-based sign-in and SSH built in; ZeroTier is layer 2, which helps with bridging and protocols that expect a shared Ethernet segment. WireGuard alone is free and fully self-managed but needs reachable endpoints and manual key handling. OpenVPN fits a central gateway model with certificates you control.

FAQ

What is ZeroTier One?

ZeroTier One is the agent you install on each device. It creates the virtual network interface and connects to other members of the networks it joins.

Is ZeroTier free?

The client is free to download, and ZeroTier Central has a free Personal plan for one network with up to 10 devices. Larger plans are paid, so the service is shareware (conditionally free).

What is ZeroTier Central?

Central is the web console where you create networks, authorise members, set managed routes and IP ranges.

ZeroTier vs Tailscale: which is better?

Choose ZeroTier when you need layer-2 features such as bridging or a flat Ethernet-like segment. Choose Tailscale when you want sign-in through an identity provider, per-user access rules and built-in SSH.

How do I install ZeroTier on Linux?

Run the official install script with curl -s https://install.zerotier.com | sudo bash, then join with sudo zerotier-cli join <network-id> and authorise the member in Central.

Which port does ZeroTier use?

UDP 9993 by default, plus a randomised secondary UDP port. Outbound UDP is what matters for direct connections.

Last checked against official sources: 8 October 2026 (developer website: zerotier.com). Versions and licence terms change — confirm on the developer's site before deploying in production.

Other programs

Submit your application