Zero-Trust Network Based on WireGuard

Networks Without Borders Connections Made Secure by Zero Trust

VirtuaMesh is an enterprise-grade virtual mesh network platform that connects global devices as if they were on the same LAN.
End-to-end encryption · Intelligent routing · Low-latency P2P direct connections.

99.9%
Control Plane Availability
<200ms
API P95 Response
>100Mbps
P2P Direct Throughput
ChaCha20·AES
End-to-End Encryption
WireGuard Encryption Self-Hosted Deployment Zero-Trust Architecture RBAC Role Permissions
End-to-End Encryption
WireGuard Protocol
Full Mesh Interconnect
P2P Direct
Cross-Region Networking
Global Device Interconnect
Beijing Office 203.0.113.0/24 Shanghai Data Center 198.51.100.0/24 Remote Mobile Office CGNAT · VPN Tunnel Access WireGuard Encrypted Tunnel ChaCha20-Poly1305 · 51820/UDP · 1-RTT Handshake Curve25519 · BLAKE2s Virtual LAN · 100.64.0.0/16 MagicDNS Firewall 100.64.0.20 Core Switch 100.64.0.30 Router 100.64.0.1 IoT Gateway 100.64.50.1 Application Server 100.64.0.10 Database 100.64.0.40 IoT VLAN · 100.64.50.0/24 Physical Link (L2) VPN Tunnel (WireGuard Mesh) Data Sync (App↔DB)

Smart Virtual Mesh Networking

Self-organizing P2P mesh network — nodes automatically discover optimal paths, encrypted data flows at light speed

Drag to rotate globe · Scroll to zoom
Loading 3D globe…

Multi-Network × Cross-Region
ACL + DERP

🟢 VM Mesh Interconnect: 6 cross-region VM nodes (Beijing/Frankfurt/Singapore/New York/Johannesburg/Sydney) are coordinated by the VirtuaMesh control plane. A proprietary mesh protocol builds a full mesh with 15 WireGuard tunnels interconnecting every pair. Each node hosts several terminals (shown in the "icon strip" below the main label), and packets continuously slide along arcs within the tunnels (white dots + colored halos).

  • Multi-Network Interconnect / Isolation

    Each network (100.64.x.0/24, RFC 6598 shared address space) is an independent subnet that can be bridged or isolated on demand; cross-network traffic flows through the central control plane

  • ACL Access Control

    By default only adjacent networks are allowed to interconnect; diagonal links are denied by ACL (green/red lines + 🚫), packets stop at the wall on contact

  • DERP Relay Fallback

    When P2P traversal fails, it automatically falls back to DERP relay servers (HTTP/2 TLS) to guarantee cross-network reachability

  • Cross-Region Networking

    Beijing/Frankfurt/Singapore/New York/Johannesburg/Sydney…global nodes can all join the same network, with intelligent region-aware routing

Control Plane
ACL Allowed
ACL Denied
Encrypted Packet

Core Capabilities

From end-to-end encryption to intelligent routing, VirtuaMesh provides a complete solution for modern distributed networks

End-to-End Encryption

ChaCha20-Poly1305 encryption based on the WireGuard protocol — all traffic is end-to-end encrypted, and the control plane cannot decrypt user data

NAT Traversal

Automatically traverses NAT and firewalls to establish P2P direct connections, with DERP relay as a backup to keep connections always available

Cross-Region Networking

Supports multi-region deployment and cross-region optimization, self-hosted DERP relay servers to reduce latency, and intelligent routing to select the optimal path

Zero-Trust Access

Identity-based access control, RBAC role permission management, fine-grained traffic rule control, and full security audit trail

Cross-Platform Clients

Supports Windows, macOS, and Linux across all platforms, with both CLI and GUI, supporting both userspace and kernel WireGuard modes

Observability

Real-time traffic monitoring, network topology visualization, system health checks, and alert rule configuration for full visibility into network operations

MagicDNS

Automatically assigns DNS names to each node, enabling direct access by device name, with support for custom A/AAAA/CNAME records and reverse resolution

Fine-Grained Policies

Fine-grained access control policies based on ACL, RBAC, time windows, and geolocation — flexibly matching enterprise organizational structures and security requirements

MagicDNS: Connect Everything by Name

Say goodbye to the era of memorizing IP addresses — MagicDNS gives every device in the network a readable domain name

Terminal
$ ping monitoring
PING monitoring (100.64.16.3): 56 bytes
64 bytes: icmp_seq=0 ttl=64 time=2.1 ms
$ ssh user@db-server
Welcome to Ubuntu 22.04 LTS
$ curl http://grafana:3000
<!DOCTYPE html><!-- Grafana Dashboard -->
$ virtuamesh dns resolve api.internal
api.internal.virtuamesh.com → 100.64.16.8

Automatic Domain Registration

DNS records are automatically registered when a node joins the network, with device name changes synced in real time — access by name with zero configuration

Reverse DNS Resolution

Supports IP → hostname reverse resolution, making log auditing, troubleshooting, and device identification easier

Custom DNS Records

Supports adding A, AAAA, CNAME, and other custom records to map dedicated domains for internal services

Search / Cache / Statistics

Supports domain search, DNS cache acceleration, and query statistics for easier operations observation and performance optimization

How It Works

Set up secure networking in three steps — no complex configuration or specialized knowledge required

1

Deploy the Control Plane

One-click deployment of the server using Docker Compose, including the API server, database, and DERP relay — done in minutes

2

Register Device Nodes

Install the client on each device and register it with the control plane — automatically obtains virtual IP and WireGuard keys and establishes encrypted tunnels

3

Secure Interconnection

Devices automatically establish P2P encrypted connections and access each other by node name via MagicDNS — as if on the same LAN

3 Commands, Connect with an Invite Code

No need to configure firewalls, routing tables, or public IPs — init to initialize, register to join the network, up to connect

virtuamesh — bash — 100×30
Networking Flow Visualization Waiting to start

Left: CLI terminal simulator — initregisterup three-step onboarding  |  Right: Networking flow animation — Registration → Key Exchange → P2P Direct / DERP Relay Fallback

Choose the Right Plan

From individual developers to enterprise groups, flexible feature packages meet the needs of different scales

Free
Personal experience and feature evaluation
¥0 /forever
  • 3 nodes
  • 1 network
  • End-to-end encryption + NAT traversal
  • MagicDNS automatic domain names
  • Community technical support
Download Free
Lite
Individual developers and small studios
¥299 /year
  • 10 nodes
  • 2 networks
  • MFA multi-factor authentication
  • Device group management
  • Email technical support
Subscribe Now
Enterprise
Large enterprises and organizations
¥1,788 /year
  • 200 nodes
  • 20 networks
  • Advanced ACL (identity + protocol)
  • SSO single sign-on (OIDC)
  • 5 exit nodes
  • 180-day audit logs
  • 99.95% SLA
  • 8h ticket response + dedicated account manager
Contact Sales
Flagship
Groups, government, and financial enterprises
¥6,888 /year
  • Unlimited nodes
  • Unlimited networks
  • Enterprise ACL (unlimited rules)
  • Private deployment
  • Unlimited exit nodes
  • Traffic monitoring + alerts + reports
  • 180-day audit + offsite backup
  • 4h ticket response + dedicated account manager
Contact Sales

Annual or monthly billing · 17% discount on annual plans · 7-day no-questions-asked refund

View full feature comparison →

Use Cases

From individual developers to enterprise teams, VirtuaMesh adapts to a variety of network connectivity needs

Remote Work

Securely access corporate intranet resources without a traditional VPN client — zero-trust architecture protects the perimeter

Multi-Cloud Interconnect

Bridge multi-cloud environments such as Alibaba Cloud, Tencent Cloud, and AWS to build a unified virtual network plane

IoT Device Management

Securely connect distributed IoT devices for remote monitoring and management — no public IP or port mapping required

Privileged Access Management

Just-in-time access control under a zero-trust architecture, with full operation audit trails to meet compliance and security audit requirements

Get Started with VirtuaMesh

Set up a secure virtual mesh network in minutes — making device connections secure and simple