# ZeroTier > Next-Generation Connectivity and Cybersecurity ## Pages - [Quantum Signals](https://www.zerotier.com/quantum/signals/): Quantum Signals ZeroTier’s definitive resource hub for the latest quantum-safe networking insights, news, and webinars tracking quantum readiness, quantum security,... - [Insights](https://www.zerotier.com/insights/): Networking and Cybersecurity Insights There’s a lot to keep up with. We can help. All Blog News Webinars Videos Podcasts... - [Videos, Webinars, and Podcasts](https://www.zerotier.com/videos-webinars-and-podcasts/): Videos, Webinars, and Podcasts Dive into on-demand webinars and expert-led videos designed to help you get the most out of... - [ZeroTier Quantum](https://www.zerotier.com/quantum/): The Network You’d Build If You Could Start Over ZeroTier creates secure, programmable network overlays that connect devices, infrastructure, and... - [ZeroTier One](https://www.zerotier.com/one/): The Network You’d Build If You Could Start Over ZeroTier creates secure, programmable network overlays that connect devices, infrastructure, and... - [Support](https://www.zerotier.com/support/): Support How Can We Help? ZeroTier provides several ways to help you connect, troubleshoot, and get the most out of... - [Newsletter Sign-up](https://www.zerotier.com/newsletter/): Sign up for our newsletter Don’t miss an update. Sign up to receive occasional networking content and news. By providing... - [Developers](https://www.zerotier.com/enterprise/developers/): Developers Connect all of your apps, services, and devices without worrying about physical connectivity, firewalls, or VPNs. Start Free Connect... - [Home](https://www.zerotier.com/): ZeroTier delivers a software-defined network overlay that connects devices, clouds, and networks anywhere in the world while improving security and... - [Glossary](https://www.zerotier.com/glossary/): The Complete Glossary of Networking, Cybersecurity, and Cyberwarfare Terms Networking can sound confusing. We’ve got you covered. All Cybersecurity Cyberwarfare... - [Industries](https://www.zerotier.com/industries/): Enterprise Connectivity and Cybersecurity Don’t let complex network challenges slow you down. Connect With Us Centralize your operations, reduce security... - [Connect With Us](https://www.zerotier.com/connect-with-us/): Connect With Us Ready to Transform Your Network? We’re excited you’re considering ZeroTier for tackling your biggest networking connectivity and... - [Automotive and Transport](https://www.zerotier.com/enterprise/auto-and-transport/): Auto and Transport Instantly connect vehicles, fleets, teams, and factories. Our secure networking brings mobile, cloud, and on-prem systems together... - [Defense](https://www.zerotier.com/enterprise/defense/): Defense Spin up secure, private, and battlefield-ready networks in minutes, without buying any new hardware. ZeroTier works anywhere, adapts fast,... - [Education](https://www.zerotier.com/enterprise/education/): Education ZeroTier helps educational institutions make the grade. Extend your Campus Area Network (CAN) to connect every device and resource... - [Enterprise IT](https://www.zerotier.com/enterprise/enterprise-it/): Enterprise IT Next-generation software-defined networking built for global enterprises. Manage your network resources like they’re on the same local network,... - [Finance and Banking](https://www.zerotier.com/enterprise/finance-and-banking/): Finance and Banking In finance, every connection is high-stakes. Establish secure, reliable connectivity in minutes across branches, remote offices, and... - [Government](https://www.zerotier.com/enterprise/government/): Government Government networks demand security and resilience you can trust. ZeroTier’s encrypted, peer-to-peer connections keep sensitive data safe while simplifying... - [Healthcare and Pharma](https://www.zerotier.com/enterprise/healthcare-and-pharma/): Healthcare and Pharma Keep your networks healthy. ZeroTier secures patient and research data with encrypted connections you can rely on.... - [Hospitality and Gaming](https://www.zerotier.com/enterprise/hospitality-and-gaming/): Hospitality and Gaming Deliver five-star network performance every time. ZeroTier’s end-to-end encryption, unique device IDs, and peer-to-peer connections offer casinos,... - [IoT and Edge Computing](https://www.zerotier.com/enterprise/iot-and-edge-computing/): IoT and Edge Computing Manage your network resources like they’re on the same local network, no matter where they are... - [Manufacturing](https://www.zerotier.com/enterprise/manufacturing/): Manufacturing Keep your network running like a well-oiled machine: ZeroTier’s easy set up, instant failover, and centralized device management make... - [MSPs and Telcos](https://www.zerotier.com/enterprise/msps-and-telcos/): MSPs and Telcos Keep your clients and devices connected, even when internet conditions get rough. ZeroTier helps keep MSP and... - [Contact](https://www.zerotier.com/contact-us/): Contact us Let’s talk about the future of networking We’re always interested in new ideas and challenging the status quo.... - [ToS](https://www.zerotier.com/tos/): Terms of Service August 2024 Welcome to the website and online services of ZeroTier, Inc. (“we”, “our” or “us”). This... - [Data Processing Addendum](https://www.zerotier.com/dpa/): ZeroTier Data Processing Addendum October 2025 This Data Processing Addendum (“DPA“) supplements and forms part of the agreement (the “Agreement“)... - [Customer Stories](https://www.zerotier.com/customer-stories/): Networking and Cybersecurity Stories Learn how ZeroTier makes networking simple for small- and large-scale deployments across a variety of industries.... - [Platform](https://www.zerotier.com/platform/): The Network You’d Build If You Could Start Over ZeroTier creates secure, programmable network overlays that connect devices, infrastructure, and... - [Privacy Policy](https://www.zerotier.com/privacy-policy/): Privacy Policy of zerotier. com Welcome to the privacy policy of zerotier. com. This policy will help you understand what... - [Blog](https://www.zerotier.com/blog/) - [About](https://www.zerotier.com/about/): About ZeroTier ZeroTier started with a simple idea: networking shouldn’t be hard. We cut through the chaos of legacy systems... - [Pricing](https://www.zerotier.com/pricing/): Infinitely Scalable From home use to enterprise-scale, whether you have 10 devices or 10,000, we have pricing to fit your... - [Download](https://www.zerotier.com/download/): Downloads Version 1. 16. 0–1. 16. 2 View the changelog Windows Apple Android Linux Docker FreeBSD OpenWRT NAS GitHub Microsoft... - [Media Kit](https://www.zerotier.com/media-kit/): Media Kit ZeroTier has been making headlines for re-defining secure networking. Everything you need to tell that story starts here.... - [Partnerships](https://www.zerotier.com/partnerships/): Revolutionize Connectivity Whether you’re reselling, integrating, or powering your operation with our secure network overlay, ZeroTier can help. Partnerships Why... ## Posts - [What's the real cost of outdated remote access tools in a distributed workforce?](https://www.zerotier.com/blog/whats-the-real-cost-of-outdated-remote-access-tools-in-a-distributed-workforce/): Legacy remote access tools silently drain budgets through security gaps, IT overhead, and compliance failures — here's the real cost. - [Is your agency's network architecture ready for the threats already in motion?](https://www.zerotier.com/blog/is-your-agencys-network-architecture-ready-for-the-threats-already-in-motion/): Flat networks, legacy VPNs, and unpatched systems leave agencies dangerously exposed — here's what modern secure architecture actually requires. - [Why are government IT teams moving away from hardware-dependent networking?](https://www.zerotier.com/blog/why-are-government-it-teams-moving-away-from-hardware-dependent-networking/): Legacy hardware is costing government IT teams more than money — discover why software-defined networking is now mission-critical. - [How do encrypted overlay networks compare to traditional VPNs for classified environments?](https://www.zerotier.com/blog/how-do-encrypted-overlay-networks-compare-to-traditional-vpns-for-classified-environments/): VPNs are failing classified environments — encrypted overlay networks offer zero-trust, post-quantum security that legacy infrastructure simply can't match. - [What does 'assume breach' mean for how you design your network today?](https://www.zerotier.com/blog/what-does-assume-breach-mean-for-how-you-design-your-network-today/): Assume breach flips network security on its head — here's what that means for segmentation, access control, and blast radius. - [Why is harvest-now-decrypt-later a procurement decision, not just a security one?](https://www.zerotier.com/blog/why-is-harvest-now-decrypt-later-a-procurement-decision-not-just-a-security-one/): Quantum decryption is coming by 2030—the contracts you sign today determine your exposure tomorrow. - [Why does a multi-cloud environment break perimeter-based security models?](https://www.zerotier.com/blog/why-does-a-multi-cloud-environment-break-perimeter-based-security-models/): Multi-cloud breaks perimeter security by design—discover why identity is now your only reliable boundary. - [The Quantum Weak Link: How to Choose Crypto-Agile Vendors](https://www.zerotier.com/blog/the-quantum-weak-link-how-to-choose-crypto-agile-vendors/): The TL;DR: Securing your own network is a great first step, but a titanium deadbolt won’t protect a cardboard door.... - [Are your legacy remote access tools creating compliance exposure you can't see?](https://www.zerotier.com/blog/are-your-legacy-remote-access-tools-creating-compliance-exposure-you-cant-see/): Legacy remote access tools hide compliance gaps that auditors will find — learn what's at risk before they do. - [Salt Typhoon and the Case for Post-Quantum Network Security in the Public Sector](https://www.zerotier.com/blog/salt-typhoon-and-the-case-for-post-quantum-network-security-in-the-public-sector/): Salt Typhoon exposed a fatal flaw in public sector networks — and quantum threats are making it worse. Act now. - [Defusing the Q-Bomb: How to Assemble Your Quantum-Ready Team](https://www.zerotier.com/blog/defusing-the-q-bomb-how-to-assemble-your-quantum-ready-team/): The TL;DR: A Cryptographic Center of Excellence (CCOE) helps enterprises prepare for post-quantum cryptography by finding cryptographic debt, setting migration... - [NIST FIPS 203 Explained for Defense and Government Network Architects](https://www.zerotier.com/blog/nist-fips-203-explained-for-defense-and-government-network-architects/): FIPS 203 is now federal law — defense architects must migrate to ML-KEM before the 2027 CNSA 2. 0 deadline... - [ZeroTier Unveils Next Release of ZeroTier Quantum, Approaching General Availability for the World’s Only End-to-End Quantum-Secure Networking Platform](https://www.zerotier.com/news/zerotier-unveils-next-release-of-zerotier-quantum-approaching-general-availability-for-the-worlds-only-end-to-end-quantum-secure-networking-platform/): SAN FRANCISCO, CALIFORNIA, JUNE 25, 2026 — ZeroTier, one of the world’s top software-defined networking companies, today announced the launch... - [CNSA 2.0 Compliance and What It Actually Requires of Government IT Teams](https://www.zerotier.com/blog/cnsa-2-0-compliance-and-what-it-actually-requires-of-government-it-teams/): CNSA 2. 0 compliance is mandatory by January 2027 — is your agency's encryption strategy ready in time? - [Harvest Now, Decrypt Later: The Silent Attack Already Targeting Defense Infrastructure](https://www.zerotier.com/blog/harvest-now-decrypt-later-the-silent-attack-already-targeting-defense-infrastructure/): Adversaries are harvesting encrypted defense data today to decrypt it tomorrow — your window to act is closing fast. - [Beyond the Threat: Building Your Quantum Defense](https://www.zerotier.com/blog/beyond-the-threat-building-your-quantum-defense/): The TL;DR: How do enterprises prepare for quantum computing security threats? Transitioning to a quantum-resistant architecture requires moving from panic... - [The Quantum Threat to Government Networks Is Not a Future Problem](https://www.zerotier.com/blog/the-quantum-threat-to-government-networks-is-not-a-future-problem/): Adversaries are harvesting encrypted government data today—quantum decryption is coming. Is your agency ready? - [Advanced Access: Custom Flow Rules Arrive in ZeroTier One](https://www.zerotier.com/blog/advanced-access-custom-flow-rules-arrive-in-zerotier-one/): ZeroTier networks give you policy control at the network layer without forcing everything through a brittle perimeter. You can define... - [Secure Connectivity for High-Stakes Forensics](https://www.zerotier.com/customer-story/secure-connectivity-for-high-stakes-forensics/): The Southwest Missouri Cyber Crimes Task Force needed to securely share evidence, connect field investigators, and accelerate mobile forensic investigations. - [Loss of Communications Security: When Encryption Fails, Everything Starts Talking](https://www.zerotier.com/blog/loss-of-communications-security-when-encryption-fails-everything-starts-talking/): Modern networks run on trust. Every HTTPS session, VPN tunnel, SSH login, certificate exchange, and software update depends on one... - [Harvest Now, Decrypt Later: The Breach Already Happened, You Just Haven’t Seen it Yet](https://www.zerotier.com/blog/harvest-now-decrypt-later-the-breach-already-happened-you-just-havent-seen-it-yet/): Many organizations think about quantum risk as a future problem. It isn’t. The data being targeted by quantum attacks is... - [A Cleaner Core: ZeroTier 1.16.2 Update Is Here](https://www.zerotier.com/blog/a-cleaner-core-zerotier-1-16-2-update-is-here/): Modern infrastructure doesn’t stay still. Devices move, users shift, networks grow, and the tools managing all of it need to... - [The Time Bomb: How Quantum Can Drive Legacy Zero-Day Exposure and Other Risks](https://www.zerotier.com/blog/the-time-bomb-how-quantum-can-drive-legacy-zero-day-exposure-and-other-risks/): Quantum computing is usually framed as a cryptography problem: broken encryption, obsolete algorithms, and a race toward post-quantum standards. That... - [3 Key Takeaways from Quantum Live!: What You Need to Know for the Post-Quantum Era](https://www.zerotier.com/blog/3-key-takeaways-from-quantum-live-what-you-need-to-know-for-the-post-quantum-era/): Post-quantum security is becoming an infrastructure and a compliance problem. Enterprises need a plan before “eventually” turns into “too late.... - [Inside Quantum Live!: Quantum Threats, PQC, and What Comes Next](https://www.zerotier.com/blog/inside-quantum-live-quantum-threats-pqc-and-what-comes-next/): On May 13, ZeroTier hosted Quantum Live! , a practical look at one of the biggest security shifts in decades:... - [Real-Time Automation Is Here: Webhooks Arrive in New ZeroTier Central](https://www.zerotier.com/blog/real-time-automation-is-here-webhooks-arrive-in-new-zerotier-central/): Modern networking infrastructure doesn’t wait around. Users join, permissions change, systems update, and teams need those changes to trigger the... - [Quantum Computing: From Qubits to Risk](https://www.zerotier.com/blog/quantum-computing-from-qubits-to-risk/): Quantum computing is moving from theory to real-world strategy. This shift in computational paradigms changes how teams think about cybersecurity,... - [Securing the New Space Race for the Post-Quantum Era](https://www.zerotier.com/blog/securing-the-new-space-race-for-the-post-quantum-era/): The nation that leads in space will lead the future. That starts not just with rockets and satellites, but also... - [Quantum Isn’t a Future Problem — It’s Already a Security Problem](https://www.zerotier.com/blog/quantum-isnt-a-future-problem-its-already-a-security-problem/): Today’s security models were designed for the threat environment we know, and, in many cases, they still work. But quantum... - [Secure Access for Automation: Introducing New Central API and Service Account Capabilities](https://www.zerotier.com/blog/secure-access-for-automation-introducing-new-central-api-and-service-accounts/): Automation is only as reliable as the access behind it. APIs make it possible to manage networks programmatically, but when... - [ZeroTier Named 'Cybersecurity Solution of the Year 2026' by The Cyber Security Review](https://www.zerotier.com/news/zerotier-named-cybersecurity-solution-of-the-year-2026-by-the-cyber-security-review/): SAN FRANCISCO, CALIFORNIA, APRIL 14, 2026 — ZeroTier, one of the world’s top software-defined networking companies, announced today it has... - [Defense Can’t Wait: The Post-Quantum Deadline Is Here](https://www.zerotier.com/blog/defense-cant-wait-the-post-quantum-deadline-is-here/): The U. S’s most sensitive computer networks are under daily attack today by adversarial hackers, and these networks’ data encryption... - [Quantum Live! Webinar Replay](https://www.zerotier.com/webinar/quantum-live/): Read the transcript Andrew Gault Welcome everyone to Quantum Live. We’re excited to walk you through the quantum threat and... - [Post-Quantum Cryptography Explained (Without the PhD)](https://www.zerotier.com/blog/post-quantum-cryptography-explained/): Quantum computing is forcing a shift in how we think about security. Quantum computing isn’t theoretical anymore. It’s forcing a... - [Security Is Moving into the Network & RSAC 2026 Just Proved it](https://www.zerotier.com/blog/security-is-moving-into-the-network-rsac-2026-just-proved-it/): RSAC 2026 made one thing clear: networking and cybersecurity are no longer separate conversations. They’re becoming one operating model. Beneath... - [Quantum Is Coming: What Enterprise Network Teams Should Be Doing Right Now](https://www.zerotier.com/blog/quantum-is-coming-what-enterprise-network-teams-should-be-doing-right-now-2/): Quantum computing isn’t breaking your network tomorrow. But it is changing the clock. Post-quantum cryptography (PQC) refers to new encryption... - [RSAC 2026: ZeroTier Launches ZeroTier Quantum, the World's First End-to-End Quantum-Secure Networking Platform](https://www.zerotier.com/news/rsac-2026-zerotier-launches-zerotier-quantum-the-worlds-first-end-to-end-quantum-secure-networking-platform/): SAN FRANCISCO, CALIFORNIA, MARCH 23, 2026 — ZeroTier, a leading software-defined networking company, announced today the launch of ZeroTier Quantum,... - [ZeroTier Wins Cybersecurity Excellence Award for Best Software Industry Solution](https://www.zerotier.com/news/zerotier-wins-cybersecurity-excellence-award-for-best-software-industry-solution/): SAN FRANCISCO, CALIFORNIA, MARCH 18, 2026 — ZeroTier, one of the world’s top software-defined networking companies, announced today it was... - [Eyes on Target: A Swarm Networking Scenario](https://www.zerotier.com/blog/eyes-on-target-a-swarm-networking-scenario/): Imagine a swarm of UAS’s launching on a mission to surveil and test adversary air and EW defenses and strike... - [Contested Battlefields: Connectivity That Doesn’t Break](https://www.zerotier.com/blog/contested-battlefields-connectivity-that-doesnt-break/): In the chaos of a firefight, infantry units need more than ammunition, ISR, and fire support. They need ultra-robust and... - [Networking the Swarm: Secure Control for Autonomous Drones](https://www.zerotier.com/blog/networking-the-swarm-secure-control-for-autonomous-drones/): The Pentagon’s plan for U. S. drone dominance envisions masses of attritable UAVs performing every conceivable mission set in support... - [Quantum Isn’t the Threat, the Lead-Up Is](https://www.zerotier.com/blog/quantum-isnt-the-threat-the-lead-up-is/): When people talk about quantum threats, they usually jump straight to cryptography. Broken encryption. Shattered trust models. A clean before-and-after... - [Introducing Flow Rules: A Policy Engine Update in ZeroTier’s New Central](https://www.zerotier.com/blog/introducing-flow-rules-a-policy-engine-update-in-zerotiers-new-central/): Firewalls and policy engines exist for a simple reason: the internet doesn’t provide trust by default. It was designed to... - [Why Centralized Firewalls Can’t Keep Up With Modern Networks](https://www.zerotier.com/blog/why-centralized-firewalls-cant-keep-up-with-modern-networks/): Firewalls and policy engines exist for one simple reason: the internet doesn’t provide trust by default. It was designed to... - [Future Threats for 2026 & Beyond: When Access Becomes the Attack](https://www.zerotier.com/blog/future-threats-for-2026-beyond-when-access-becomes-the-attack/): The biggest security shift heading into 2026 isn’t a new exploit, a breakthrough vulnerability, or some yet-to-be-known attack technique. It’s... - [Mission-Critical Video Made Simple](https://www.zerotier.com/customer-story/mission-critical-video-made-simple/): Active Security needed to stream real-time video from OT sensors across cellular, satellite, and fiber networks to secure high-stakes events. - [Your Networking Checklist: 5 Ways to Get Your Network in Shape for 2026](https://www.zerotier.com/blog/your-networking-checklist-5-ways-to-get-your-network-in-shape-for-2026/): 2026 is here. And if your network still feels like a patchwork of VPNs, firewalls, cloud dashboards, and workarounds, you’re... - [The Top 10 Cyber Trends, Hacks (and Failures) that Defined 2025](https://www.zerotier.com/blog/the-top-10-cyber-trends-hacks-and-failures-that-defined-2025/): In 2025 the pace and sophistication of cyber hacks reached alarming levels. A sweeping cyber espionage campaign targeting Microsoft SharePoint... - [The Tactical Edge: How ZeroTier Supports UAVs and Drone Swarms](https://www.zerotier.com/blog/the-tactical-edge-how-zerotier-supports-uavs-and-drone-swarms/): UAVs have become a core part of modern defense and security operations. They support ISR missions, perimeter monitoring, supply delivery,... - [Ready for Takeoff: How ZeroTier Delivers Device-Level Reliability for Drone Fleets](https://www.zerotier.com/blog/ready-for-takeoff-how-zerotier-delivers-device-level-reliability-for-drone-fleets/): This is the second installment of a multi-part blog series exploring how drones can stay connected, secure, and mission-ready with... - [Inside ZeroTier: Building a Network that Works](https://www.zerotier.com/blog/inside-zerotier-building-a-network-that-works/): The internet began as a simple, open network where every device could reach every other directly. Researchers and engineers built... - [Active Security Partners with ZeroTier to Deliver Secure Networking Solutions for Defense, Enterprise Clients](https://www.zerotier.com/news/active-security-partners-with-zerotier-to-deliver-secure-networking-solutions-for-defense-enterprise-clients/): SAN FRANCISCO — NOVEMBER 13, 2025 – Active Security, a defense contracting firm specializing in the design, implementation, and sustainment... - [Meet the New ZeroTier Central: A Smarter, Cleaner Way to Manage Networks](https://www.zerotier.com/blog/meet-the-new-zerotier-central-a-smarter-cleaner-way-to-manage-networks/): During our recent webinar, ZeroTier One Update for Enterprise, we highlighted some exciting work underway to enhance the ZeroTier platform.... - [Zerotier Launches New Central Release, Unveils Redesigned UI/UX to Empower Users with Faster, More Intuitive Network Control](https://www.zerotier.com/news/zerotier-launches-new-central-release-unveils-redesigned-ui-ux-to-empower-users-with-faster-more-intuitive-network-control/): SAN FRANCISCO — NOVEMBER 04, 2025 — ZeroTier, one of the world’s leading software-defined networking and cybersecurity companies, has announced... - [The New Airspace Is Connected: Why Secure Networking Matters for Every Drone](https://www.zerotier.com/blog/the-new-airspace-is-connected-why-secure-networking-matters-for-every-drone/): This is the first installment of a multi-part blog series exploring how drones can stay connected, secure, and mission-ready with... - [A First Look at ZeroTier’s New Central Updates](https://www.zerotier.com/blog/a-first-look-at-zerotiers-new-central-updates/): During our last webinar, ZeroTier One Update for Enterprise, we highlighted some new projects and ongoing efforts to enhance the... - [Forbes Highlights the ‘Hidden Tax’ Companies Pay to Hackers Featuring ZeroTier](https://www.zerotier.com/news/forbes-highlights-the-hidden-tax-companies-pay-to-hackers-featuring-zerotier/): In an Oct. 15 article on Forbes. com, contributor Jaime Catmull explored the “hidden tax” companies pay due to cyberattacks,... - [4 Ways Software-Defined Networks Keep Casinos Running Smoothly & Securely](https://www.zerotier.com/blog/4-ways-software-defined-networks-keep-casinos-running-smoothly-securely/): Casinos and gaming operations never stop, and neither should your network. From gaming floors packed with connected machines to remote... - [A (Parking) Lot of Options](https://www.zerotier.com/customer-story/a-parking-lot-of-options/): Metropolis needed a way to remotely manage a massive number of devices within parking facilities, all while securely transmitting and... - [Building a Remote Solution](https://www.zerotier.com/customer-story/building-a-remote-solution/): Forest Rock, a UK-based IoT solutions provider specializing in smart buildings, needed real-time, secure visibility into sensors monitoring energy usage... - [How Forest Rock Keeps Buildings Cool (Even in the Hottest Months) with ZeroTier](https://www.zerotier.com/blog/how-forest-rock-keeps-buildings-cool-even-in-the-hottest-months-with-zerotier/): Picture this: It’s the middle of August. The sun’s out, temps are pushing 90 degrees, and the office AC is... - [Vacation-Proof Your IoT with Memory-Safe Code](https://www.zerotier.com/blog/vacation-proof-your-iot-with-memory-safe-code/): Imagine you’re lounging on a beach somewhere, margarita in hand, disconnected from Slack notifications when your phone buzzes: “Urgent: Production... - [ReBAC: Keep the Right People On the Job While You’re OOO](https://www.zerotier.com/blog/rebac-keep-the-right-people-on-the-job-while-youre-ooo/): It’s summer. You should be thinking about sunscreen and spritzers, not who accidentally got admin rights to your entire network.... - [Minimal Effort, Maximum Chill: Earn Recurring Revenue with ZeroTier’s Partner Program](https://www.zerotier.com/blog/minimal-effort-maximum-chill-earn-recurring-revenue-with-zerotiers-partner-program/): This summer, making money while laying on the beach has never been easier. ZeroTier recently teamed up with PartnerStack to... - [Your Network Infrastructure Just Got an Upgrade (And Your Vacation Plans Just Got Safer)](https://www.zerotier.com/blog/your-network-infrastructure-just-got-an-upgrade-and-your-vacation-plans-just-got-safer/): Tired of dealing with clunky, overbuilt networking solutions? ZeroTier recently dropped its latest update, and it’s about to make networking... - [Soak Up the Sun, Not the Stress: Stay Connected During Outages with ZeroTier](https://www.zerotier.com/blog/soak-up-the-sun-not-the-stress-stay-connected-during-outages-with-zerotier/): June’s Google Cloud Platform outage, and the resulting disruption to downstream infrastructure providers, was another reminder of how fragile the... - [Rewriting the Rules of Global Networking: Insights from ZeroTier’s Feature on the Great Things with Great Tech Podcast](https://www.zerotier.com/podcast/zerotier-feature-on-great-things-with-great/): In late May, ZeroTier was featured on the 100th episode of the “Great Things with Great Tech” podcast. During the... - [PartnerStack to Provide Backend for ZeroTier's Partner Program, Help Deliver Modern Networking Solutions to Customers](https://www.zerotier.com/news/partnerstack-to-provide-backend-for-zerotier-partner-program/): SAN FRANCISCO, CALIFORNIA, JUNE 12, 2025 – ZeroTier, one of the world’s leading software-defined networking companies, has announced today that... - [Why RBAC Isn’t Enough (and What ReBAC Gets Right)](https://www.zerotier.com/blog/rbacvsrebac/): If you’re an admin, you spend a lot of time trying to get people the access they need, without putting... - [ZeroTier One Update](https://www.zerotier.com/webinar/zerotier-one-update/): Read the transcript Andrew Gault So Hello, everyone! Thank you for joining us today for a look at what’s new... - [ZeroTier Launches Partner Program to Expand Delivery of its Next-Generation Secure Networking Platform](https://www.zerotier.com/news/zerotier-launches-partner-program-to-expand-delivery-of-its-next-generation-secure-networking-platform/): SAN FRANCISCO, CALIFORNIA, APRIL 22, 2025 — ZeroTier, one of the world’s leading software-defined networking companies, has announced today the... - [Sort Out Segmentation with Mesh Networking](https://www.zerotier.com/blog/sort-out-segmentation-with-mesh-networking/): Note: This is the second installment of a multi-part blog series tackling real-life networking challenges in enterprise environments. Segmentation is... - [ZeroTier Partners with Channel Tools to Provide Enterprises with Secure, Scalable Connectivity Solutions](https://www.zerotier.com/news/zerotier-partners-with-channel-tools/): SAN FRANCISCO, CALIFORNIA, MARCH 3, 2025 – ZeroTier, one of the world’s leading software-defined network companies, has announced today a... - [Tame Multi-Cloud Chaos with Mesh Networking](https://www.zerotier.com/blog/tame-multi-cloud-chaos-with-mesh-networking/): This is the first installment of a multi-part blog series tackling real-life networking challenges in enterprise environments. Networking in the... - [ZeroTier Infrastructure Upgrades: Enhancing Performance & Reliability](https://www.zerotier.com/blog/zerotier-infrastructure-upgrades-enhancing-performance-reliability/): At ZeroTier, we’re committed to continuously improving our infrastructure to provide seamless and reliable connectivity for all users. As our... - [ZeroTier Expands Development and Sales Capabilities with Launch of New European Office, Taps Tech Industry Veterans to Launch EU Operations](https://www.zerotier.com/news/zerotier-expands-development-and-sales-capabilities-with-launch-of-new-european-office-taps-tech-industry-veterans-to-launch-eu-operations/): SAN FRANCISCO, CALIFORNIA, FEBRUARY 4, 2025 — ZeroTier, one of the world’s top software-defined network companies, has announced the opening... - [Deploying an SD-WAN Solution? Consider a Lightweight Alternative](https://www.zerotier.com/blog/deploying-an-sd-wan-solution-consider-a-lightweight-alternative/): Traditional networking solutions were not built for the explosive growth, multi-continental reach and the cloud-based capabilities typical of today’s most... - [5 Reasons to Move Away from a VPN Solution & to a Virtual Networking Platform](https://www.zerotier.com/blog/5-reasons-to-use-a-virtual-networking-platform-instead-of-vpn-solution/): Today’s business functions depend on a reliable and secure internet connection. But, as technology progresses and our networks extend their... - [A Game Changer for ZeroTier on Embedded CPU Devices](https://www.zerotier.com/blog/a-game-changer-for-zerotier-on-embedded-cpu-devices/): Going Faster with Multi-Core Performance We’re excited to announce the launch of multi-threading for ZeroTier. This new feature is designed... - [How to Modernize Device Connectivity](https://www.zerotier.com/blog/how-to-modernize-device-connectivity/): A healthy network makes up the nervous system of any modern organization that leverages IoT technology. Fast, safe, and reliable... - [How to Create a Global, Scalable, Secure Private Network](https://www.zerotier.com/blog/how-to-create-a-global-scalable-secure-private-network/): As your organization steps more fully into the digital age, access to secure and reliable networking that does what you... - [The Business Case for Simpler Global Networking](https://www.zerotier.com/blog/the-business-case-for-simpler-global-networking/): The next big thing in network technology is always right around the corner. Many legacy tools for global networking no... - [ZeroTier Overview](https://www.zerotier.com/video/zerotier-overview/): https://youtu. be/LZJ2BGAnnHg Legacy network infrastructure fails to meet the demands of modern business. It’s full of fragmented networks, complex configurations,... - [ZeroTier partnership means Metropolis can do a (parking) lot more.](https://www.zerotier.com/news/zerotier-partnership-means-metropolis-can-do-a-parking-lot-more/): Your networking solution shouldn’t limit your company’s ability to expand. Instead, global networking should drive your company’s growth and help... - [ZeroTier solution lets Forest Rock walk (and work) through walls.](https://www.zerotier.com/customer-story/zerotier-solution-lets-forest-rock-walk-and-work-through-walls/): “ZeroTier unlocked doors for what we were capable of as a company... ” Gareth Shirley, sales and operations manager at... - [Trust: The Once and Future King of Internet Connection](https://www.zerotier.com/blog/rust-the-once-and-future-king-of-internet-connection/): The technology and networking landscape has changed a lot since then. One of the biggest changes has been the approach... - [Introducing ZeroTier Webhooks](https://www.zerotier.com/blog/introducing-zerotier-webhooks/): Now introducing Webhooks. Automatically receive ZeroTier network notifications. - [What is Industrial IoT (IIoT)? Your 2023 Guide.](https://www.zerotier.com/blog/what-is-industrial-iot-iiot-your-2023-guide/): IIoT, or the Industrial Internet of Things, is a revolutionary technology steadily reshaping various industrial sectors from transportation to manufacturing... - [ZeroTier Review: Everything You Need to Know About ZeroTier in 2023](https://www.zerotier.com/blog/zerotier-review-everything-you-need-to-know-about-zerotier-in-2023/): We answer all the questions you have about ZeroTier, a zero-trust networking solution that securely connects devices anytime, anywhere. - [MSP Remote Access Software: Everything You Need to Know [2023]](https://www.zerotier.com/blog/msp-remote-access-software-everything-you-need-to-know-2023/): Learn everything you need to know about MSP Remote Access and the top software for securely managing client data and... - [ZeroTier and Github Actions](https://www.zerotier.com/blog/zerotier-and-github-actions/): ZeroTier is an SDN platform that allows users to create virtual networks that can span multiple devices, locations, and cloud... - [Using Flow Rules To Direct Users to Services](https://www.zerotier.com/blog/using-flow-rules-to-direct-users-to-services/): Today we’re going to talk about ZeroTier Flow Rules and show you some practical, simple examples. - [The ZeroTier DNS Story](https://www.zerotier.com/blog/the-zerotier-dns-story/): How to enable DNS in ZeroTier, and what it gets you... - [ZeroTier Central now integrates with HashiCorp Terraform](https://www.zerotier.com/blog/zerotier-central-now-integrates-with-hashicorp-terraform/): Managing network settings with a webUI can be tedious. Taking full advantage of ZeroTier means enrolling large numbers of devices,... - [ZeroTier on MikroTik](https://www.zerotier.com/blog/2977-2/): Yes, it’s finally happened, ZeroTier is now available on MikroTik. - [ZeroTier Makes Running Private Cloud Storage More Accessible and Easier to Use](https://www.zerotier.com/blog/zerotier-makes-running-private-cloud-storage-more-accessible-and-easier-to-use/): Today we’re going to replace our cloud storage on our mobile and desktop devices with Seafile, inside of docker-compose, to... - [ZeroTier at Sea](https://www.zerotier.com/blog/zerotier-at-sea/): 5G and boats - [ZeroTier Raises $2M For A Radically Simple Approach To Networking](https://www.zerotier.com/news/zerotier-raises-2m-for-a-radically-simple-approach-to-networking/): ZeroTier has raised an additional $2M in funding in a round co-led by Anorak Ventures and Bonfire Ventures - [Network Collective Shows You How To Connect To Google Cloud Using ZeroTier](https://www.zerotier.com/blog/network-collective-shows-you-how-to-connect-to-google-cloud-using-zerotier/): The good folks at Network Collective - [Research Notes on 2.x Cryptography](https://www.zerotier.com/tips/research-notes-on-2-x-cryptography/): Ephemeral Sudden Death - [The State of NAT Traversal](https://www.zerotier.com/blog/the-state-of-nat-traversal/): NAT murders kittens # # Detailed Content ## Pages Quantum Signals ZeroTier's definitive resource hub for the latest quantum-safe networking insights, news, and webinars tracking quantum readiness, quantum security, and post-quantum cryptography (PQC). Explore how the acceleration of quantum computing reshapes global connectivity, and gain the practical knowledge to build resilient, quantum-safe networks today. Featured Content All Articles Videos See more See more See more Explore ZeroTier Quantum The first networking platform designed for the post‑quantum era. Explore Quantum See more See more See more See more See more See more See more See more Load More See more See more See more Explore ZeroTier Quantum The first networking platform designed for the post‑quantum era. Explore Quantum See more See more See more See more See more See more See more See more Load More We're having trouble finding any posts that match that criteria. Check back again soon. Quantum Is Complex. Network Security Doesn't Have to Be. Learn more about ZeroTier Quantum and where it fits into your Quantum readiness plan and tech stack. Connect With Us Explore the Platform Networking and Cybersecurity Insights There's a lot to keep up with. We can help. All Blog News Webinars Videos Podcasts Customer Stories Previous Page1 Page2 Page3 ... Page6 Next Previous Page1 Page2 Page3 Page4 Next Sign Up for Our Newsletter Don't miss an update. Sign up to receive occasional networking content and news. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Videos, Webinars, and Podcasts Dive into on-demand webinars and expert-led videos designed to help you get the most out of the ZeroTier platform. Sign up for our newsletter Don't miss an update. Sign up to receive occasional networking content and news. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. The Network You'd Build If You Could Start Over ZeroTier creates secure, programmable network overlays that connect devices, infrastructure, and applications anywhere. Overview How ZeroTier Works ZeroTier replaces physical network boundaries with cryptographic identity and secure peer‑to‑peer connectivity. Each network member is identified, authenticated, and connected using four core mechanisms: Devices join networks using cryptographic identity Traffic is encrypted end‑to‑end Connections are established peer‑to‑peer whenever possible Policy is centrally defined and globally enforced Each network member is identified, authenticated, and connected using four core mechanisms. Platform The Platform Stack ZeroTier combines lightweight software agents, a secure peer‑to‑peer networking layer, and a flexible control plane to create a distributed networking platform. skip render: ucaddon_content_slider_new skip render: ucaddon_remote_scroll_control API / Command Line ZeroTier Quantum is managed directly through command-line tools and APIs, giving operators full control over network configuration and behavior. From these interfaces, teams can: create and manage networks define routing and segmentation rules control membership and identity automate provisioning and updates All configuration is distributed as cryptographically signed objects and enforced locally by each node. Control Layer The control layer defines how networks behave. Administrators use it to manage: network membership routing configuration segmentation rules access policy Control information is distributed to nodes, which enforce policy locally. Data Layer The ZeroTier data layer forms a secure peer‑to‑peer overlay network. Devices communicate directly whenever possible, establishing encrypted connections between nodes across the internet. This enables: direct peer‑to‑peer connectivity automatic NAT traversal encrypted end‑to‑end communication adaptive path discovery Agents Every device that... The Network You'd Build If You Could Start Over ZeroTier creates secure, programmable network overlays that connect devices, infrastructure, and applications anywhere. Overview How ZeroTier Works ZeroTier replaces physical network boundaries with cryptographic identity and secure peer‑to‑peer connectivity. Each network member is identified, authenticated, and connected using four core mechanisms: Devices join networks using cryptographic identity Traffic is encrypted end‑to‑end Connections are established peer‑to‑peer whenever possible Policy is centrally defined and globally enforced Each network member is identified, authenticated, and connected using four core mechanisms. Platform The Platform Stack ZeroTier combines lightweight software agents, a secure peer‑to‑peer networking layer, and a flexible control plane to create a distributed networking platform. skip render: ucaddon_content_slider_new skip render: ucaddon_remote_scroll_control ZeroTier Central ZeroTier Central provides the management interface for configuring and operating networks. From Central, administrators can: create and manage networks authorize devices define routing and segmentation rules manage users and permissions Organizations can also run self‑hosted controllers when they require full infrastructure control. Control Layer The control layer defines how networks behave. Administrators use it to manage: network membership routing configuration segmentation rules access policy Control information is distributed to nodes, which enforce policy locally. Data Layer The ZeroTier data layer forms a secure peer‑to‑peer overlay network. Devices communicate directly whenever possible, establishing encrypted connections between nodes across the internet. This enables: direct peer‑to‑peer connectivity automatic NAT traversal encrypted end‑to‑end communication adaptive path discovery Agents and Clients Every device that joins a ZeroTier network runs a lightweight software agent. This agent installs as... Support How Can We Help? ZeroTier provides several ways to help you connect, troubleshoot, and get the most out of your network. Whether you're exploring the platform, solving a technical issue, or managing an enterprise deployment — we're here to help. Direct Support for Subscribers Subscribers on our paid plans have access to direct support from the ZeroTier team by filling out this form or sending us a quick email at support@zerotier. com. We're here to help with escalated technical issues, deployment questions, and account support. Support Hours Monday–Friday, 8 a. m. –5 p. m. Pacific time (excluding U. S. holidays) By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Need to Reach Out to Our Sales Team? Right this way: Contact Sales Contact Sales Sign up for our newsletter Don't miss an update. Sign up to receive occasional networking content and news. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Developers Connect all of your apps, services, and devices without worrying about physical connectivity, firewalls, or VPNs. Start Free Connect With Us Use cases You Focus on Your Application. We’ll Handle the Networking. Modern applications need access to resources spread across the cloud, on-prem, and the edge while supporting users around the world. With ZeroTier, you can stop fighting with flaky on-site Internet service, firewalls, and cloud ingress, and spend your time building features your customers will love. Simple Many Devices, One Solution Use the same lightweight software agent to connect your servers, mobile devices, embedded/IoT systems, and developer machines. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “ZeroTier connects our engineers to key resources quickly and easily, which allows our team to focus on making space simple. ” — Software Lead, Space Infrastructure Provider skip render: ucaddon_content_carousel_new Resilient Reliable, Efficient p2p Connectivity ZeroTier’s peer-to-peer overlay constantly optimizes your network for the fastest possible direct links, reducing latency and providing consistent, peak performance in mission-critical workloads. skip render: ucaddon_uc_icon_accordion “ZeroTier provides the industry’s best platform for simplifying secure connectivity. It has saved us significant development time. ” — CEO, Military Tactical Communications Provider Secure Your Network, Your Data ZeroTier protects your systems by removing the need for public access, ensuring transport security, and providing strong identity for clients and servers. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Tired of Wrestling with Networking? Discover how ZeroTier lets you spend less time fixing networks and more time shipping features. Explore the Platform Check Out the... ZeroTier delivers a software-defined network overlay that connects devices, clouds, and networks anywhere in the world while improving security and reducing complexity. Keep Up With Quantum See More Quantum Content Trusted by 3M+ devices connected worldwide skip render: ucaddon_logo_marquee skip render: ucaddon_logo_marquee Innovation ZeroTier Quantum™ The first networking platform designed for the post‑quantum era. Purpose-built for organizations preparing for the next generation of cryptographic security. CNSA 2. 0 compliant. Deployable in air‑gapped environments. Policy enforced locally at every endpoint. ZeroTier Quantum extends the ZeroTier platform with cryptographic protections designed for tomorrow's security landscape. Explore Quantum Benefits Why Teams Choose ZeroTier skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_slider_new Industries Trusted Across Critical Industries ZeroTier powers secure connectivity for organizations operating in the world's most demanding environments. Defense Mission-critical networking that holds under adversarial conditions. Manufacturing Secure connectivity across factories, robotics, and distributed systems. Government Reliable networking for utilities, infrastructure, and public works. Explore All Industries Testimonials What Our Customers Say “My only regret is that I didn’t go down that path earlier — much earlier. ” — Head of Technical Operations, AI-powered Parking Provider “ZeroTier unlocked doors for what we were capable of as a company and for our own projects. ” — Operations Manager, Smart Building Technology Provider “ZeroTier provides a robust and essential backbone for our communications stack. ” — Mechatronics Engineer, Farming Robots Company “ ZeroTier to improve interoperability between offices in the United States and France. It connects our engineers to key resources quickly and easily, which allows... The Complete Glossary of Networking, Cybersecurity, and Cyberwarfare Terms Networking can sound confusing. We’ve got you covered. All Cybersecurity Cyberwarfare Networking Networking 3G A mobile telecommunications standard offering data rates up to a few megabits per second, enabling mobile internet, video calls, and mobile TV. Networking 4G A broadband cellular network standard providing peak download rates of 100 Mbps (mobile) to 1 Gbps (stationary), powering HD mobile video and VoLTE. Networking 5G The latest generation of mobile networks, delivers faster internet speeds, lower delays, and support for more connected devices. Networking 5Ge A marketing name for an enhanced 4G LTE technology (with features like 256-QAM and 4×4 MIMO) that offers speeds approaching true 5G but is still LTE under the hood. Networking A Record DNS record that maps a domain name to an IPv4 address. Networking AAAA Record DNS record that maps a domain name to an IPv6 address. Cybersecurity Access Control List (ACL) A list of permissions attached to an object specifying who or what has access to the object and what operations are allowed. Cyberwarfare Active Defense Proactive measures taken to defend against cyber threats, such as threat hunting and deception techniques. Networking Address Resolution Protocol (ARP) Protocol used to map an IP address to a physical MAC address. Cybersecurity Address Resolution Protocol (ARP) Spoofing An attack that associates the attacker’s MAC address with the IP address of another host. Cybersecurity Advanced Persistent Threat (APT) A sophisticated, long-term cyberattack targeting specific entities. Cybersecurity Adware Software that displays unwanted... Enterprise Connectivity and Cybersecurity Don’t let complex network challenges slow you down. Connect With Us Centralize your operations, reduce security risks, and get the comprehensive support you need to keep your business running smoothly, no matter your size or industry. Auto and Transport Real-time connectivity for systems that never stand still. Defense Mission-critical networking that holds under adversarial conditions. Education Secure connectivity across campuses, labs, and research environments. Enterprise IT Simplified networking for complex, distributed environments. Finance and Banking Connectivity for financial systems that can’t afford failure. Government Reliable networking for utilities, infrastructure, and public works. Healthcare and Pharma Protect sensitive systems across distributed care environments. Hospitality and Gaming Secure connectivity across properties, systems, and guest networks. IoT and Edge Networking for environments where infrastructure lives everywhere. Manufacturing Secure connectivity across factories, robotics, and distributed systems. MSPs and Telcos Secure networking across clients, infrastructure, and services. Secure Connectivity for Your Project Connect all of your apps, services, and devices without worrying about physical connectivity, firewalls, or VPNs. For Developers Infinitely Scalable From smart bulbs to spaceships, whether you have 10 users or 10,000, ZeroTier has an option that fits you. See Pricing Connect With Us Connect With Us Ready to Transform Your Network? We’re excited you’re considering ZeroTier for tackling your biggest networking connectivity and security challenges. Once you submit your information, somebody from our sales team will review your details and reach out within 1-2 business days. We’ll confirm your interests and gather any additional context needed to make our first conversation as valuable as possible for you. How Can We Help? skip render: ucaddon_list By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Looking for Technical Support? Look no further. Talk to Support Auto and Transport Instantly connect vehicles, fleets, teams, and factories. Our secure networking brings mobile, cloud, and on-prem systems together and keeps them connected, wherever the road takes you. Start Free Connect With Us Simple Simple Networks Built for Complex Fleets Deploy secure networks across fleets in minutes. Make sure vehicles and sensors stay online, even when they move geographically or change internet connections. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “My only regret is that I didn’t go down that path earlier — much earlier. ” — Head of Technical Operations, AI-powered Parking Provider skip render: ucaddon_content_carousel_new Resilient Reliable, Seamless Connectivity on Any Route Connectivity isn’t always predictable. ZeroTier keeps systems online with multipath routing, seamless failover, and smart traversal across networks and firewalls. skip render: ucaddon_uc_icon_accordion “ZeroTier keeps our telemetry flowing fast and secure — even at 30 knots — while giving our techs reliable access to troubleshoot and patch systems on the fly. ” — Computer Engineer, Sail Racing Team Secure Take the Wheel on Secure Networking With critical systems, security can’t be an afterthought. ZeroTier protects every connection with end-to-end encryption, cryptographic device IDs, and future-ready architecture. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Need Reliable Connectivity on Routes? Learn how ZeroTier keeps your operations moving. Explore the Platform Connect With Us Defense Spin up secure, private, and battlefield-ready networks in minutes, without buying any new hardware. ZeroTier works anywhere, adapts fast, and locks down comms with defense-grade encryption. Self-heal, self-host, stay air-gapped, and stay in control. Start Free Connect With Us Simple Field-Ready in Minutes Deploy simple, resilient, and secure networking anywhere with no hardware and no hassle. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “ZeroTier provides the industry’s best platform for simplifying secure connectivity. It has saved us significant development time. "” — CEO, Military Tactical Communications Provider skip render: ucaddon_content_carousel_new Resilient Rugged. Ready. Resilient. Built for dynamic threat environments, ZeroTier networks stay up when conventional systems fail. This makes it ideal for internet-degraded or denied environments, remote sensors, and tactical VoIP systems. skip render: ucaddon_uc_icon_accordion “We’ve tested all the options, and ZeroTier is the fastest and most flexible solution for our battlefield use case. ” — CEO, Military Drone Manufacturer Secure Defense-Grade Security for Global Networks In defense environments, every connection must be secure by design. ZeroTier encrypts every packet, authenticates every device, and offers future-ready cryptography to keep critical systems protected from nation-state level threats. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Need Fast, Reliable Battlefield Connectivity? Discover how ZeroTier can help you stay air-gapped, connected, and in command. Explore the Platform Connect With Us Education ZeroTier helps educational institutions make the grade. Extend your Campus Area Network (CAN) to connect every device and resource securely, from anywhere, without VPN or hardware hassles. Start Free Connect With Us Simple Make Collaboration Easy ZeroTier lets your Campus Area Network (CAN) go global. Access every server, lab computer, and library resource from anywhere, just like you’re on campus. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “ZeroTier gave us secure, ultra-fast connectivity across seismic sensors nationwide, deployed in hours, not weeks. ZeroTier helps us deliver those precious extra seconds of warning to residents before an earthquake strikes. ” — PHD Professor, Leading Disaster Risk Research Center skip render: ucaddon_content_carousel_new Resilient Reliable Connectivity for Every Campus From campus to remote learning, ZeroTier ensures always-on connectivity with multipath routing, failover, and smart traversal. Keeping your classes and resources accessible anywhere. skip render: ucaddon_uc_icon_accordion “ at least 325 ransomware attacks on school districts across the United States between April 2016 and the end of November 2022. ” — K12 Security Information eXchange (K12 SIX) study Secure Secure Remote Access to Campus Resources Securely and privately connect to campus servers, labs, and libraries from anywhere while ditching clunky VPNs and complicated logins. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Need Easier Access to Resources? Explore how ZeroTier keeps your campus connected without the VPN headaches. Explore the Platform Connect With Us Enterprise IT Next-generation software-defined networking built for global enterprises. Manage your network resources like they’re on the same local network, no matter where they are in the world. Start Free Connect With Us Simple Networking, but Simple Spin up secure enterprise-grade networks in minutes. Keep all your devices online, no matter where they are or how they connect. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “ ZeroTier to improve interoperability between offices in the United States and France. It connects our engineers to key resources quickly and easily, which allows our team to focus on making space simple. ” — Software Developer, Space Infrastructure Provider skip render: ucaddon_content_carousel_new Resilient Resilient by Design From branch offices to remote sites, ZeroTier keeps you online with multipath routing, seamless failover, and smart NAT traversal so operations never stop. skip render: ucaddon_uc_icon_accordion “We reserve ZeroTier for the toughest deployments, where traditional tools break down. Even then, setting up point-of-sale systems at customer sites takes minutes, with rock-solid security and zero networking headaches. ” — Director of Engineering, Grocery Delivery Provider Secure Enterprise-Grade Security In enterprise IT, security isn’t optional. ZeroTier safeguards every connection with end-to-end encryption, unique cryptographic device IDs, and a future-ready architecture that keeps you in control. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Looking to Simplify Network Security? See how ZeroTier makes enterprise connectivity effortless. Explore the Platform Connect With Us Finance and Banking In finance, every connection is high-stakes. Establish secure, reliable connectivity in minutes across branches, remote offices, and cloud systems. It’s secure networking that just makes “cents. ” Start Free Connect With Us Simple Simple Networks That Pay Dividends Deploy secure networks across branches and systems in minutes. It only takes a few clicks to set up and manage connectivity. Plus you can skip the hardware upgrades and avoid vendor lock-in. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “72% of CISOs are worried about PQC. ” — Gartner Report skip render: ucaddon_content_carousel_new Resilient Always-on Financial Connectivity From ATM networks to mobile trading platforms, banking connectivity can’t afford downtime. ZeroTier keeps your financial infrastructure rock-solid with smart routing and instant backup connections. skip render: ucaddon_uc_icon_accordion “In the 2024 Gartner Board of Directors Survey, 93% of boards see cyber-risk as a threat to stakeholder value. ” — Gartner Report Secure Secure Networks, Smooth Transactions When it comes to critical financial systems, security can’t be an afterthought. ZeroTier protects every connection with end-to-end encryption, cryptographic device IDs, and future-ready architecture. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Need Safer Banking Network Solutions? Discover how ZeroTier keeps your network in control and secures every transaction, branch, and cloud connection. Explore the Platform Connect With Us Government Government networks demand security and resilience you can trust. ZeroTier’s encrypted, peer-to-peer connections keep sensitive data safe while simplifying access across agencies. Start Free Connect With Us Simple Simple Connectivity for Critical Operations Connect your organizations with secure networks in minutes, no bulky hardware or complex setups required. ZeroTier’s defense-grade security keeps teams, contractors, and emergency responders working together seamlessly from anywhere. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “In high-stakes environments, ZeroTier’s encrypted, reliable connectivity ensures our teams stay connected without compromise. ” — CEO, Full-Service Security Provider skip render: ucaddon_content_carousel_new Resilient Resilient Networks for Every Operation From field units to remote offices, connectivity isn’t always predictable. ZeroTier keeps systems online with multipath routing, seamless failover, and smart traversal, so critical operations never stall. skip render: ucaddon_uc_icon_accordion “ZeroTier transformed how we securely connected critical government sites and historic facilities. Its site-to-site networking delivered military-grade security with remarkable simplicity, and deployment across these locations was seamless and efficient. ” — Engineering Director, Renewable Energy Infrastructure Provider Secure Secure Networks Built for Government Operations Government networks demand security you can trust. ZeroTier encrypts every connection, authenticates every device, and safeguards critical systems against advanced threats. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Looking for Defense-Grade Secure Networking? Learn how ZeroTier keeps teams, contractors, and emergency responders working together, securely and seamlessly. Explore the Platform Connect with Us Explore the Platform Connect with Us Healthcare and Pharma Keep your networks healthy. ZeroTier secures patient and research data with encrypted connections you can rely on. Start Free Connect With Us Simple Simplifying Care Networks Deploy secure networks in minutes and keep clinics, labs, and medical devices online across multiple locations and changing connections. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “ leverage ZeroTier to enhance robot supportability across customer sites worldwide. ZeroTier's simple configuration and robust network segregation play a pivotal role in making this possible. ” — Software Engineering Manager, Enterprise Asset Provider skip render: ucaddon_content_carousel_new Resilient Reliable Connections Wherever You Operate From clinics to remote labs, connectivity isn’t always predictable. ZeroTier keeps systems online with multipath routing, seamless failover, and smart traversal across networks and firewalls so operations never stall. skip render: ucaddon_uc_icon_accordion “According to data obtained from HHS’s Office of Civil Rights, there were approximately 550 hacks of protected health information impacting 108 million individuals in 2023 alone. ” — American Hospital Association (AHA) report Secure Secure Network for Vital Connections When it comes to critical systems in healthcare, security can’t be an afterthought. ZeroTier protects every connection with end-to-end encryption, cryptographic device IDs, and future-ready architecture. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Ready for Seamless Network Operations? Learn more about how ZeroTier can securely manage networks across clinics, labs, and remote sites. Explore the Platform Connect with Us Explore the Platform Connect with Us Hospitality and Gaming Deliver five-star network performance every time. ZeroTier’s end-to-end encryption, unique device IDs, and peer-to-peer connections offer casinos, hotels, and gaming platforms smooth, secure operations. Start Free Connect With Us Simple Check-in to Simple Networking Deploy secure networks across properties in minutes. Keep guest services, gaming systems, and devices online, even as locations or internet connections change. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new "We trust ZeroTier to quietly power our backend, resilient, secure, and effortlessly scalable. " — The Network Architect of a Sports Betting and Gaming Platform skip render: ucaddon_content_carousel_new Resilient Reliable Networks for Every Guest Experience From bustling casino floors to remote properties, connectivity isn’t always predictable. ZeroTier keeps your systems online with multipath routing, seamless failover, and smart traversal across networks and firewalls, so operations never skip a beat. skip render: ucaddon_uc_icon_accordion “61% of organizations today say they have a defined Zero Trust initiative in place. And another 35% plan to implement one soon. ” — Okta Report Secure Secure Networks Across Every Property Hotels and casinos have critical systems connected to the internet and security can’t be an afterthought. ZeroTier protects every connection with end-to-end encryption, cryptographic device IDs, and future-ready architecture. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Want Five-Star Network Connectivity? Learn how ZeroTier’s secure networking lets you stay in control of your hotel or casino’s network. Explore the Platform Connect with Us Explore the Platform Connect with Us IoT and Edge Computing Manage your network resources like they’re on the same local network, no matter where they are in the world. Start Free Connect With Us Simple Simplifying Networks at the Edge ZeroTier reduces complexity by ensuring seamless data flow between edge devices and hybrid/multi-cloud resources. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “ZeroTier unlocked doors for what we were capable of as a company and for our own projects. ” — Operations Manager, Smart Building Technology Provider skip render: ucaddon_content_carousel_new Resilient Stay Connected When Conditions Get Rough From IoT sensors to edge devices, connectivity can be unpredictable. ZeroTier ensures your network stays online with multipath routing, automatic failover, and intelligent traversal across networks and firewalls. skip render: ucaddon_uc_icon_accordion “We needed a way to easily connect our growing IoT product-base to our systems. ZeroTier provided an easy and reliable way to achieve that, and has been growing with us. ” — Principal Software Engineer, Solar Energy Equipment Supplier Secure Secure Every Edge Connection Systems at the edge are more vulnerable to threats, so security has to be a top priority. ZeroTier encrypts every connection, uses cryptographic device IDs, and builds future-ready networks you can trust. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Have a Large-Scale Iot Deployment? We have flexible packing to fit your needs as well. Reach out to our team so we can walk you through it. Explore the Platform Connect with Us Explore the Platform Connect with Us Manufacturing Keep your network running like a well-oiled machine: ZeroTier’s easy set up, instant failover, and centralized device management make it easy to secure factories, production lines, and manufacturing systems. Get smooth, uninterrupted operations today. Start Free Connect With Us Simple Simple Networks for Complex Operations Deploy secure enterprise-grade networks across factories and IoT devices in minutes. Keep machines, sensors, and equipment online, even across multiple sites with fluctuating internet connections. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “This solution made our infrastructure remarkably resilient and streamlined day-to-day management, which gave our team more time to focus on innovation. ” — Product Manager, Leading Car Manufacturer skip render: ucaddon_content_carousel_new Resilient Resilience for Every Industrial Network From factory floors to remote warehouses, ZeroTier keeps machines and IoT devices online with multipath routing, seamless failover, and intelligent network traversal. skip render: ucaddon_uc_icon_accordion “ZeroTier provides a robust and essential backbone for our communications stack. ” — Mechatronics Engineer, Farming Robots Company Secure Secure Connections for Today’s Industrial Operations With critical industrial systems, security can’t be an afterthought. ZeroTier protects every connection with end-to-end encryption, cryptographic device IDs, and future-ready architecture. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Want to Know More? Discover how ZeroTier simplifies connectivity and lets you gain full control over your factories and IoT networks. Explore the Platform Connect with Us Explore the Platform Connect with Us MSPs and Telcos Keep your clients and devices connected, even when internet conditions get rough. ZeroTier helps keep MSP and telco networks secure and reliable with end-to-end encryption, multipath routing, and centralized management. Start Free Connect With Us Simple Complex Networks, Simplified Simplify client connectivity with secure, scalable networks that are ready in minutes. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new “As an MSP juggling dozens of vendors, ZeroTier lets us unify, secure, and scale faster than any platform overlay we've seen. The ability to resell and work closely with the platform team is also a win. ” — CTO, Large Managed Service Provider skip render: ucaddon_content_carousel_new Resilient Keep Client Networks Running Networks can be unpredictable, especially when you have many clients to manage. ZeroTier keeps MSPs and telcos connected with multipath routing, seamless failover, and smart traversal across networks and firewalls. skip render: ucaddon_uc_icon_accordion “Our time to triage and resolve an issue might have been five days. It's now minutes ... Now, we can just load up a laptop, log in, diagnose. ” — Operations Manager, Smart Building Technology Provider Secure Take the Wheel on Secure Networking With critical systems, security can’t be an afterthought. ZeroTier protects every connection with end-to-end encryption, cryptographic device IDs, and future-ready architecture. skip render: ucaddon_uc_icon_accordion skip render: ucaddon_content_carousel_new Interested in Flexible Packing to Fit Your Needs? Reach out to our team and we can walk you through it. Explore the Platform Connect with Us Explore the Platform Connect with Us Contact us Let's talk about the future of networking We're always interested in new ideas and challenging the status quo. If you have an innovative use case, a collaboration proposal, or just want to pick our brain on decentralized networking, this is the place. Looking for technical help? Support Support Want to speak to sales? Sales Sales What's This Form For? You have an innovative idea or use case to share. You're a researcher or developer with a non-support question. You want to discuss potential collaborations or integrations. You have a general inquiry about our company culture or team. For technical assistance with an existing ZeroTier deployment, or if you're ready to discuss purchasing and scaling our platform for your organization, use the dedicated buttons below. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. How else can we help? Whether it’s technical support for your ZeroTier deployment or something else, we’ve got you covered. Support Contact sales Contact sales Support Terms of Service August 2024Welcome to the website and online services of ZeroTier, Inc. (“we”, “our” or “us”). This page explains the terms and conditions (the “Terms”) by which you may use our online services, website, software and documentation provided on or in connection with our services (collectively, the “Service”). When you access or use our Service, or by clicking a button or checking a box marked “I Agree” (or something similar), you signify that you have read, understood, and agree to be bound by these Terms whether or not you are a registered user of our Service. You also understand and acknowledge that your personal information will be collected, used, and otherwise processed in accordance with our Privacy Policy available at https://www. zerotier. com/privacy-policy (“Privacy Policy”). We reserve the right to modify these Terms and will provide notice of these changes as described below. These Terms apply to all visitors, users, and others who access our Service (“Users”). PLEASE READ THESE TERMS CAREFULLY TO ENSURE THAT YOU UNDERSTAND EACH PROVISION. THESE TERMS CONTAIN A MANDATORY INDIVIDUAL ARBITRATION AGREEMENT IN SECTION 13. 2 (THE “ARBITRATION AGREEMENT”) AND CLASS ACTION/JURY TRIAL WAIVER PROVISION IN SECTION 13. 3 (THE “CLASS ACTION/JURY TRIAL WAIVER”) THAT REQUIRE, WITH ONLY SPECIFIED EXCEPTIONS IN SECTIONS 13. 1 AND 13. 2 OR UNLESS YOU OPT OUT PURSUANT TO THE INSTRUCTIONS IN SECTION 13. 2, THE EXCLUSIVE USE OF FINAL AND BINDING ARBITRATION ON AN INDIVIDUAL BASIS ONLY TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS, COLLECTIVE,... ZeroTier Data Processing Addendum October 2025This Data Processing Addendum ("DPA") supplements and forms part of the agreement (the "Agreement") entered into between an individual business subscriber or organization (the Organization) and ZeroTier in relation to the transfer and processing of Covered Data in connection with the performance of the Agreement. 1. Definitions 1. 1 Capitalized terms used but not defined within this DPA will have the meaning set forth in the Agreement. The following capitalized terms used in this DPA will be defined as follows:"Administration Data" means(a) contact details relating to, and the content of correspondence with the Organization's main account holder or administrator; and(b) support enquiries submitted by the Organization's authorized users in relation to the Service. "Applicable Data Protection Laws" means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time, including (without limitation): the GDPR, Swiss Data Protection Laws and the US Data Protection Laws. "Authorized Sub-processor" means the Sub-processors listed in Schedule 4, and any other Sub-processors appointed in accordance with paragraph 7. 4. "CCPA" means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798. 100 et seq. , as amended, including its implementing regulations and the California Privacy Rights Act of 2020. "Controller Purposes" means: (a) undertaking internal research and development to develop, test, improve and alter the functionality of ZeroTier’s products and services; (b) creating anonymized datasets for training or evaluation... Networking and Cybersecurity Stories Learn how ZeroTier makes networking simple for small- and large-scale deployments across a variety of industries. Customer Stories Sign Up for Our Newsletter Don't miss an update. Sign up to receive occasional networking content and news. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. The Network You'd Build If You Could Start Over ZeroTier creates secure, programmable network overlays that connect devices, infrastructure, and applications anywhere. Overview How ZeroTier Works ZeroTier replaces physical network boundaries with cryptographic identity and secure peer‑to‑peer connectivity. Each network member is identified, authenticated, and connected using four core mechanisms: Devices join networks using cryptographic identity Traffic is encrypted end‑to‑end Connections are established peer‑to‑peer whenever possible Policy is centrally defined and globally enforced Each network member is identified, authenticated, and connected using four core mechanisms. Choose the Platform Right for You ZeroTier One The networking platform trusted by millions of devices worldwide. Simple to deploy. Infinitely flexible. Built for developers, operators, and distributed systems. Explore ZeroTier One ZeroTier Quantum The first networking platform designed for the post‑quantum era. Built for environments where security, sovereignty, and resilience are non‑negotiable. Explore Quantum Architecture Flexible Network Design ZeroTier networks operate as secure virtual overlays on top of existing infrastructure. Connectivity is defined through identity and policy rather than physical topology. Networks can span public clouds private data centers on‑prem environments remote devices and edge systems Core Features Platform Capabilities ZeroTier enables modern distributed networking across environments. skip render: ucaddon_content_carousel_new skip render: ucaddon_uc_icon_accordion Simple Deploy networks in minutes using a lightweight client. Resilient Peer‑to‑peer connectivity removes single points of failure. Secure All traffic is authenticated and encrypted by default. ZeroTier powers secure connectivity for organizations operating in the world's most demanding environments. Trusted by 3M+ Devices Connected Worldwide skip render: ucaddon_logo_marquee skip render: ucaddon_logo_marquee... Privacy Policy of zerotier. com Welcome to the privacy policy of zerotier. com. This policy will help you understand what data we collect, why we collect it, and what your rights are in relation to it. Latest update: December 9, 2025 Table of contents Owner and Data ControllerTypes of Data collectedMode and place of processing the DataThe purposes of processingInformation on the types of processing of Personal DataInformation on opting out of interest-based advertisingCookie PolicyFurther Information for Users in the European UnionFurther information for Users in SwitzerlandFurther information for Users in BrazilAdditional information for Users in the United StatesAdditional information about Data collection and processingDefinitions and legal references Owner and Data Controller ZeroTier, Inc. 548 Market St #911530, San Francisco, CA 94104 GDPR EU Representative for ZeroTier, Inc. and Data Controller for data it processes itself ZeroTier Europe B. V. Stadsplateau 29 3521 AZ UtrechtOwner contact email: privacy@zerotier. com Type of Data we collect Among the types of Personal Data that this Application collects, by itself or through third parties, there are:Personal data, including your name, address, email address, language and resume. Approximate geolocation (derived from IP address); ZeroTier does not collect precise GPS or continuous location data. Device information, including IP address and operating systems. Usage Data, including browsing and search history, page views, data communicated while using the service. TrackersPayment infoComplete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy and our Trust Center, or by specific explanation texts... ZeroTier | Zero Trust and Mesh Networking Articles Skip to content Docs Support Download Company Login Docs Login Search Search Platform Overview Architecture Features ZeroTier One ZeroTier Quantum Industries Automotive and transport Defense Education Enterprise IT Finance and banking Government Healthcare and pharma Hospitality and gaming IoT and edge computing Manufacturing MSPs and telcos Developers Insights Blog Newsroom Webinars Customer Stories Product Resources Getting started Documentation Developer Tools Download FAQ Glossary About ZeroTier Pricing Start Free Talk to Sales Platform Industries Close Industries Open Industries Industries Find the right fit for your organization. Defense Enterprise IT Finance and Banking Government IoT and Edge Computing Manufacturing MSPs and telcos Developers View all industries Customer Story Mission-Critical Video Made Simple See more Resources Close Resources Open Resources Insights Learn and explore. Blog Newsroom Webinars Customer Stories View All Resources Product Resources Build and deploy. Getting Started Documentation Developer Tools Downloads FAQ Glossary Pricing Partners Start Free Connect With Us Networking and Cybersecurity Blog There’s a lot to keep up with. We can help. Blog Blog The Quantum Weak Link: How to Choose Crypto-Agile Vendors See More Blog Defusing the Q-Bomb: How to Assemble Your Quantum-Ready Team See More Blog Beyond the Threat: Building Your Quantum Defense See More Blog Advanced Access: Custom Flow Rules Arrive in ZeroTier One See More Blog Loss of Communications Security: When Encryption Fails, Everything Starts Talking See More Blog Harvest Now, Decrypt Later: The Breach Already Happened, You Just Haven’t Seen it Yet See More Blog A... About ZeroTier ZeroTier started with a simple idea: networking shouldn’t be hard. We cut through the chaos of legacy systems with secure, encrypted connections that just work, whether it’s one device or a fleet. Forget complexity. Just connect and go. Daily Active Devices 0 + Business Customers 0 + Countries and Territories 0 + Ethos and What We’re Proud of ZeroTier enables partners to solve some of today’s most critical connectivity challenges. Philosophy We know simplicity is harder than complexity. We believe networking should be both simple and intuitive. Impact and Resilience We've helped shift the industry toward decentralized networking, proved “impossible” demos could become reality, and endured where most startups fade. Culture and Outlook Rooted in curiosity and resilience, we take pride in solving hard problems together and know the most exciting work still lies ahead. From a Spark to a Global Platform What began as a side project to make networking simpler has grown into a platform used by millions worldwide. This is the story of ZeroTier’s journey. The Spark Frustrated by slow, manual networking inside a U. S. government project, our founder, Adam Ierymenko, began coding a better way. His goal: make it effortless to connect devices directly, supporting privacy and decentralization. Two years of spare-time coding led to an open-source release in 2013. On the day it went live, his newborn daughter helped tap the enter key to publish the first version, a fitting start to something built for the next generation. First lines of code... Infinitely Scalable From home use to enterprise-scale, whether you have 10 devices or 10,000, we have pricing to fit your needs. skip render: ucaddon_remote_tabs Plan Details Included Devices Additional Devices Networks Network Admins Premium Relays SaaS Cloud Sovereign Air-gapped Platform SSO Local DNS Access Control ReBAC Admin Social Sign-in Service Accounts Audit Logs Netconf Support Teams Support Local Logging Memory Safety Hardware Acceleration Memory Footprint Embedded Processor Support Hardware Security Module (HSM) Support Interfaces API CLI UI AI Agent Webhooks Networking Protocol Policy Engine Policy Enforcement Policy Management Templated Flow Rules Custom Flow Rules Topology Architecture Offline Network Connectivity Sovereign Network Control Custom Routes Multipathing Fast Failover Multihoming Programmable Kernels NGFW Kernel Template IPS Kernel Template Agentic NetOps Kernel Template Configuration Distribution Network Specific Relays Low Bandwidth Mode Control Plane Data Plane Virtual L2 (Ethernet) Virtual L3 (IP) RTT Throughput Performance† CPU Efficiency† Memory Efficiency† Fragmentation Support Telemetry Security Symmetric Encryption Key Exchange Algorithm Metadata Privacy†† pqNoise-based Single-Key Compromise MitM Double-Key Compromise MitM D/DoS Protection Key Rotation Perfect Forward Secrecy Quantum Perfect Secrecy Identity Forward Secrecy Data Forward Secrecy Ratchet Forward Secrecy Online / Offline Identity Keys Cryptographic Agility Silent by Default Compliance SOC 2 Compliance GDPR Compliance DORA Compliance ISO 27001 Compliance 889 Compliance Mission Grade Compliance CSNA 2. 0 Compliance FIPS 140-3 FIPS 203 FIPS 204 Support Support Documentation Onboarding Account Managment Security Assessment Custom Engineering SLA skip render: ucaddon_content_carousel_new † Performance has been validated in controlled, comparable environments; however, real-world customer deployments and environments may result in... Downloads Version 1. 16. 0–1. 16. 2View the changelog Windows Apple Android Linux Docker FreeBSD OpenWRT NAS GitHub Microsoft Windows Current version: 1. 16. 2 Be sure to approve installation of the driver during the install process. Note: Windows 7 and Server 2012 users, please download ZeroTier One 1. 6. 6, as there is no Windows 7 support in ZeroTier One 1. 8 or later. MSI Installer (x86/x64) MacOS Current version: 1. 16. 2 MacOS 10. 13+ or newer is supported. MacOS PKG Installer iOS Mobile Current version: 1. 16. 0 ZeroTier One for iOS allows you to join ZeroTier virtual networks as VPN connections on your iPhone or iPad. Download ZeroTier One Android Mobile Current version: 1. 16. 0 ZeroTier One for Android allows you to join ZeroTier virtual networks as VPN connections on your Android phone or tablet device. Download ZeroTier One Linux (DEB/RPM) Current version: 1. 16. 2 Debian and RPM based distributions, including Debian, Ubuntu, CentOS, RHEL, Fedora, and others are supported via a script that adds the right repository and installs the package. Other Linux distributions may have their own packages. If not, try building and installing from source. If you are willing to rely on SSL to authenticate the site, a one line install can be done with: curl -s https://install. zerotier. com | sudo bash If you have GPG installed, a more secure option is available: curl -s 'https://raw. githubusercontent. com/zerotier/ZeroTierOne/main/doc/contact%40zerotier. com. gpg' | gpg --import && if z=$(curl -s 'https://install. zerotier. com/'... Media Kit ZeroTier has been making headlines for re-defining secure networking. Everything you need to tell that story starts here. Our media kit gathers our brand assets, boilerplate, and press resources to help you share ZeroTier with clarity and consistency. Boilerplate About ZeroTier ZeroTier gives organizations exactly what they need: a modern solution to the overengineered chaos of legacy networking. It’s secure, direct, global connectivity that actually works. Whether managing a single device or an entire enterprise fleet, ZeroTier connects everything directly through a secure network you create and control and is SOC 2 compliant. ZeroTier Quantum, which meets NIST and NSA’s highest standards at CNSA 2. 0, extends that simplicity as the world’s first end-to-end quantum-secure networking platform. Trusted by leaders across every industry, ZeroTier received a 2026 Cybersecurity Excellence Award and is backed by Anorak Ventures, Battery Ventures, and Bonfire Ventures. Learn more at zerotier. com. Contact Media ZeroTier Public Relations: pr@zerotier. com Brand Logos Primary logo Download Download For light background Download For dark background Quantum-branded logo Download Download For light background Download For dark background 1-color logo Download Download For light backgrounds Download For dark background Icons Download Download Default Download Quantum-branded Download 1-Color Dark Download 1-Color Light Sign up for our newsletter Don't miss an update. Sign up to receive occasional networking content and news. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal... Revolutionize Connectivity Whether you're reselling, integrating, or powering your operation with our secure network overlay, ZeroTier can help. Partnerships Why Partner with ZeroTier? Whether you're reselling, integrating, or powering your operation with our secure network overlay, ZeroTier can help. Our platform provides secure, scalable, and seamless connectivity. Together, we’ll transform how both you and your customers connect by making your networking simpler, stronger, and more secure. skip render: ucaddon_list Ways to Earn There are a few different relationships that can add value to your offering and drive revenue with ZeroTier:Affiliate Partners: Developers, OEMs, content creators, and community builders who promote ZeroTier using a unique affiliate link. Referral Partners and Resellers: VARs, system integrators, service providers, and consultants who help customers navigate their networking needs. Commission-based, they partner with our sales team to collaborate on closing deals. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Powering Connectivity for Innovators Everywhere Partnerships A Few Key Use Cases ZeroTier enables partners to solve some of today’s most critical connectivity challenges. skip render: ucaddon_uc_icon_accordion Find Your Fit with ZeroTier We collaborate with partners across industries to expand what’s possible in networking. Explore how your business can thrive by partnering with ZeroTier: skip... ## Posts Legacy remote access tools silently drain budgets through security gaps, IT overhead, and compliance failures — here's the real cost. Outdated remote access tools create costs far beyond their licensing fees. The real price shows up in security incidents, IT overhead, failed audits, and the engineering hours spent keeping legacy infrastructure alive. For distributed workforces, those costs compound fast. This article breaks down exactly where legacy remote access bleeds money, why it creates unacceptable risk in 2026, and how to know when it is time to replace it. What hidden costs do legacy remote access tools actually create? Legacy remote access tools carry three categories of hidden cost: operational overhead, security incident exposure, and compliance friction. The licensing fee is the smallest line item. The real expense is the IT labor required to maintain, patch, and troubleshoot aging infrastructure across a workforce that no longer sits in one building. Consider what "maintaining" a traditional virtual private network (VPN) actually involves. Someone has to manage certificates, push client updates, handle split-tunneling configurations, and field help desk tickets every time a remote employee cannot connect. In a distributed workforce, that volume scales with headcount. Ten remote employees is manageable. Five hundred is a full-time job. Then there is the hardware dependency. Traditional VPN concentrators and perimeter appliances require physical maintenance, firmware updates, and eventual replacement cycles. When a device fails at 2 a. m. , someone pays for that outage in lost productivity and emergency response time. Compliance costs are the third hidden layer. Legacy tools were not built for modern audit requirements. Generating access logs, proving least-privilege enforcement, and demonstrating encryption... Flat networks, legacy VPNs, and unpatched systems leave agencies dangerously exposed — here's what modern secure architecture actually requires. Most agency networks are not ready. The threats already in motion in 2026 — ransomware moving laterally across flat networks, nation-state actors exploiting legacy remote access, and quantum-capable adversaries harvesting encrypted traffic today to decrypt it later — outpace the architecture most agencies are still running. If your network was designed around perimeter defense and traditional virtual private networks (VPNs), you are defending a boundary that no longer exists. The sections below answer the specific questions security and compliance leaders are asking right now. What are the most common attack vectors targeting agency networks right now? The most common attack vectors targeting agency networks in 2026 are compromised credentials used against remote access infrastructure, supply chain intrusions through third-party contractors, lateral movement across flat internal networks, and encrypted traffic interception by adversaries preparing for post-quantum decryption. These are not theoretical. They are the documented methods behind the most damaging breaches of the past three years. Legacy VPN concentrators remain a primary target. They are single points of failure with large attack surfaces, and many agencies run versions with known, unpatched vulnerabilities. Once an attacker gets past the perimeter, a flat network gives them room to move. There is no internal segmentation to slow them down. The supply chain vector is particularly dangerous for defense industrial base (DIB) organizations. Contractors and subcontractors connect to agency systems with varying levels of security hygiene. Every third-party connection is a potential entry point. And the quantum threat is no longer distant — adversaries are... Legacy hardware is costing government IT teams more than money — discover why software-defined networking is now mission-critical. Government IT teams are moving away from hardware-dependent networking because the operational costs, security risks, and compliance demands of legacy infrastructure have become impossible to justify. Physical routers, switches, and appliances were designed for a different era — one where networks were static, perimeters were clear, and change happened slowly. In 2026, none of those conditions apply. The sections below break down exactly why the shift is happening and what it looks like in practice. What are the biggest operational costs of hardware-dependent government networks? The biggest operational costs of hardware-dependent government networks are procurement cycles, maintenance contracts, on-site labor, and the compounding expense of technical debt in defense networks. Hardware takes months to procure, requires physical installation, and demands ongoing vendor support contracts that rarely get cheaper over time. When something breaks at a remote facility, someone has to fly there. Beyond the obvious line items, the hidden costs are what really add up. Every hardware refresh cycle forces agencies to re-certify equipment, retrain staff, and often rearchitect segments of the network. Agencies running aging infrastructure frequently operate parallel systems — the old one that still handles critical workloads, and the new one being phased in — paying for both simultaneously. Staffing is another pressure point. Specialized network hardware requires specialized people. Finding and retaining engineers who know how to configure proprietary appliances is harder and more expensive than it used to be. And when those engineers leave, institutional knowledge walks out with them. The result is a budget... VPNs are failing classified environments — encrypted overlay networks offer zero-trust, post-quantum security that legacy infrastructure simply can't match. Encrypted overlay networks are more secure than traditional virtual private networks (VPNs) for classified environments — and the gap is widening. VPNs were designed for a different era of networking. They create a single encrypted tunnel between two points, but they were never built to handle the distributed, zero-trust demands of modern defense and government infrastructure. Overlay networks take a fundamentally different approach: they build a software-defined private network on top of the public internet, with encryption and access control baked into every connection. The sections below break down exactly where VPNs fall short, how overlay networks work, and when making the switch is the right call for a classified environment. What security gaps do traditional VPNs expose in classified environments Traditional VPNs create a perimeter-based security model that assumes everything inside the tunnel is trusted. In a classified environment, that assumption is dangerous. Once an attacker or a compromised credential gets inside the VPN tunnel, lateral movement across the network is largely unconstrained. The perimeter collapses, and the blast radius is enormous. The structural problems run deeper than access control. Most VPN architectures route all traffic through a central gateway. That gateway becomes a single point of failure and a high-value target. In defense industrial base environments, where uptime and integrity are non-negotiable, a gateway outage or compromise can take down connectivity across an entire operation. VPNs also carry significant technical debt in defense networks. Many deployments still rely on legacy cipher suites, outdated key exchange protocols, and hardware... Assume breach flips network security on its head — here's what that means for segmentation, access control, and blast radius. "Assume breach" changes network design by shifting your default assumption from "we will keep attackers out" to "an attacker is already inside. " That single shift rewires how you segment, monitor, and control access across your entire infrastructure. Instead of building a hard perimeter and trusting everything inside it, you design every layer of the network as if it has already been compromised. The questions below unpack what that means in practice. How does 'assume breach' change the way you segment your network? Under an assume breach model, network segmentation stops being a compliance checkbox and becomes your primary damage-control mechanism. You stop drawing one big perimeter around the whole organization and start drawing many smaller ones around individual workloads, device groups, and data flows. The goal is to make sure that when something gets in, it cannot move freely. Traditional flat networks treat internal traffic as trusted by default. That assumption is exactly what attackers exploit. Once they are inside, lateral movement is trivial. Assume breach flips that logic entirely. Practical segmentation under this model means: Isolating workloads so that a compromised application server cannot reach your database tier without explicit, verified permission Separating IoT (Internet of Things) devices from corporate systems, because IoT endpoints are frequently the weakest link in manufacturing, automotive, and industrial environments Enforcing microsegmentation at the identity and device level, not just at the network boundary Treating east-west traffic (traffic moving between internal systems) with the same scrutiny you apply to north-south traffic (traffic entering... Quantum decryption is coming by 2030—the contracts you sign today determine your exposure tomorrow. Harvest-now-decrypt-later (HNDL) is a procurement decision because the contracts you sign today determine whether encrypted data collected right now can be decrypted in three to five years, when quantum computers capable of breaking current encryption become viable. Security teams can patch software. They cannot retroactively re-encrypt data that has already left the building. That makes vendor selection, contract terms, and supply chain requirements the real line of defense. This article works through the specific questions procurement and security leaders need to answer together. What data are attackers actually collecting right now? Attackers are collecting anything encrypted with classical asymmetric cryptography, specifically RSA (Rivest-Shamir-Adleman) and ECC (Elliptic Curve Cryptography) key exchanges. That includes VPN (Virtual Private Network) session traffic, TLS (Transport Layer Security) handshakes, authentication tokens, and bulk data transfers. The content looks useless today. That is the point. The bet is that quantum hardware will make it readable later. The targets are not random. Nation-state actors and well-resourced criminal groups prioritize long-shelf-life data: intellectual property, defense procurement documents, regulated health records, financial transaction histories, and government communications. If the data will still matter in five to ten years, it is worth storing now. For organizations in the defense industrial base, this is not theoretical. Classified and controlled unclassified information (CUI) flowing between contractors, subcontractors, and government agencies travels over networks every day. Much of that traffic uses encryption standards that post-quantum computers will eventually break. The collection is already happening. The decryption is the part that is coming. When does... Multi-cloud breaks perimeter security by design—discover why identity is now your only reliable boundary. Multi-cloud environments break perimeter-based security because they eliminate the fixed boundary that perimeter security depends on. When your workloads run across AWS, Azure, Google Cloud, and on-premises infrastructure simultaneously, there is no single edge to defend. Traffic moves between environments in ways that traditional firewalls and network perimeters were never designed to handle. This is not a configuration problem. It is a structural mismatch between an old security model and a fundamentally different kind of network. The questions below unpack exactly where the model fails and what replaces it. What assumptions does perimeter security make that multi-cloud violates? Perimeter security assumes there is a clear inside and outside. It treats the network boundary as a wall: everything inside is trusted, everything outside is not. Firewalls, intrusion detection systems, and network access controls all operate on this assumption. Multi-cloud destroys it. When your data and workloads live in three different cloud environments plus a corporate data center, there is no single wall to build. The perimeter model also assumes that traffic flows in predictable directions, typically from users outside to servers inside. In a multi-cloud setup, traffic flows laterally between cloud providers, between microservices, between regions, and between environments. None of that fits the hub-and-spoke mental model that perimeter security was built around. A third assumption is that the network itself is relatively static. Perimeter controls are configured manually and updated infrequently. Multi-cloud environments spin up and tear down resources constantly. A firewall rule written for a workload that existed last... The TL;DR: Securing your own network is a great first step, but a titanium deadbolt won't protect a cardboard door. Because sensitive data constantly flows through third-party APIs, older hardware, cloud routing, and SaaS platforms, your post-quantum defense is only as strong as your weakest vendor. To eliminate hidden cryptographic debt and mitigate "harvest now, decrypt later" (HNDL) risks, organizations must look beneath the surface and demand true, NIST-compliant crypto-agility through their entire vendor tech stack and supply chain. Want a deeper breakdown of the terminology used in this article? Look no further than our complete networking, cybersecurity and cyberware glossary. Congrats! You did the hard part. You’ve started building a quantum-secure network strategy. Maybe you deployed ZeroTier Quantum to protect data in transit. Maybe you’re inventorying cryptographic debt. Maybe you’re finally asking the uncomfortable question: What happens when RSA and ECC stop being enough? Now it’s time to consider the next question: What about everyone else in your stack? Your quantum defense is only as strong as your weakest vendor link. If your edge is protected but your cloud provider, hardware stack, SaaS estate, APIs, log-in/authentication systems, or internal routing still depend on brittle legacy cryptography, you haven’t solved the problem. You’ve put a titanium deadbolt on a cardboard door. The Iceberg Illusion: What’s the Cloud Blindspot in Post-Quantum Security? Most teams spend their time on the part they can see above the waterline: firewalls, VPNs, identity tools, and endpoints. That makes sense. These controls are visible. They’re owned.... Legacy remote access tools hide compliance gaps that auditors will find — learn what's at risk before they do. Yes, legacy remote access tools are almost certainly creating compliance exposure you cannot see. The core problem is that most of these tools were built before modern regulatory frameworks existed, and they lack the audit granularity, encryption standards, and access controls those frameworks now require. If you are running a defense industrial base environment, a regulated manufacturer, or any organization subject to frameworks like CMMC, NIST SP 800-171, or ITAR, the gap between what your legacy infrastructure does and what compliance demands is likely wider than your last audit revealed. The exposure is not always a breach. Sometimes it is a configuration that fails a control. Sometimes it is an unlogged session. Sometimes it is a protocol that a framework has quietly deprecated. The sections below break down where the risk lives, why it hides so well, and what to do about it. What compliance risks do legacy remote access tools actually introduce? Legacy remote access tools introduce compliance risk in three primary areas: weak encryption standards, insufficient access logging, and poor identity verification. Most tools built before 2015 rely on cryptographic protocols that current frameworks explicitly prohibit or flag as inadequate. They also tend to grant broad network access rather than least-privilege access, which violates the segmentation requirements in nearly every modern compliance standard. The specific risks stack up quickly. Older virtual private network (VPN) implementations often use pre-shared keys rather than certificate-based authentication, making them vulnerable to credential theft. Session logging is frequently incomplete or stored locally on... Salt Typhoon exposed a fatal flaw in public sector networks — and quantum threats are making it worse. Act now. Salt Typhoon didn't just compromise a few government systems. It exposed a fundamental flaw in how public sector networks are built and defended. This state-sponsored intrusion campaign, attributed to Chinese threat actors, burrowed into U. S. telecommunications infrastructure and sat there — quietly — for months. The lesson wasn't subtle: legacy network architectures aren't equipped for the threat environment we're operating in right now, let alone the one that quantum computing is about to create. For IT and network teams in government and regulated industries, the window to act on post-quantum network security is closing faster than most procurement cycles can move. This isn't a theoretical future problem. NIST finalized its post-quantum cryptography standards in August 2024. The CNSA 2. 0 deadline for U. S. national security systems lands in January 2027. And in 2026, both NIST's CSF 2. 0 and the EU's NIS2 directive are pushing auditors to ask hard questions about cryptographic posture across critical sectors. The clock is running. What Salt Typhoon Revealed About Public Sector Network Security Salt Typhoon was a wake-up call that most in public sector IT didn't want to receive. The campaign targeted major U. S. telecom providers and, through them, gained access to sensitive government communications. Attackers didn't kick down the front door. They found gaps in aging infrastructure, moved laterally through poorly segmented networks, and stayed undetected long enough to do serious damage. What made Salt Typhoon particularly damaging wasn't just the breach itself. It was what the breach revealed about... The TL;DR: A Cryptographic Center of Excellence (CCOE) helps enterprises prepare for post-quantum cryptography by finding cryptographic debt, setting migration policy, coordinating vendors, and building crypto-agility into DevSecOps. Here’s how to assemble the right team, prioritize the highest-risk systems, and move toward quantum-safe networking without creating operational chaos. Want a deeper breakdown of the terminology used in this article? Our complete networking, cybersecurity and cyberware glossary has you covered. Quantum risk isn’t a countdown clock. It’s an inventory, management, and PMO issue rolled into one. “Harvest now, decrypt later” (HNDL) tactics mean adversaries don’t need a quantum computer today to create damage tomorrow. They can capture encrypted data now, wait for quantum capabilities to mature, and come back for anything still valuable. That puts traditional security mainstays in the blast radius: digital signatures, identity systems, TLS communications, and the trust models enterprises rely on every day. The fix doesn’t start in a physics lab. It starts with a Cryptographic Center of Excellence (CCOE): a cross-functional team built to find cryptographic debt, set policy, pressure vendors, and manage the transition to quantum-safe standards before attackers get the better timeline. What Is the First Step Toward Quantum Readiness? Start by assessing your cryptographic blast radius. For example, for an enterprise with 1,000 team members, this isn’t a theoretical physics problem, it’s a serious asset-tracking hurdle. You likely have thousands of internal applications, legacy databases, and microservices all running different security protocols. To tackle this without halting production, you need a “nuts-and-bolts” framework... FIPS 203 is now federal law — defense architects must migrate to ML-KEM before the 2027 CNSA 2.0 deadline or risk exposure. Post-quantum migration is quickly moving from research discussion to operational planning. For defense and government network architects, NIST FIPS 203 marks an important step toward standardizing how sensitive systems prepare for the next generation of cryptographic threats. NIST FIPS 203 is the federal standard that defines how organizations must implement ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism) — the first finalized post-quantum cryptographic algorithm approved for protecting sensitive government data. If you architect networks for defense or government environments, this is not something you can push to next year's roadmap. Procurement cycles have already started, and the January 2027 CNSA 2. 0 deadline is closer than most upgrade timelines can comfortably accommodate. The real challenge isn't understanding what the standard says — it's figuring out how to build toward it without tearing out infrastructure that still has to work today. What NIST FIPS 203 Actually Is (and Why It's Different) NIST published FIPS 203 in August 2024. It standardizes ML-KEM, a key encapsulation mechanism built on the mathematical hardness of module lattice problems. A KEM lets two parties establish a shared secret over an untrusted channel, which is the foundation of encrypted communications. What separates FIPS 203 from earlier standards governing RSA or elliptic curve cryptography (ECC) is the underlying math. RSA and ECC get their security from problems — integer factorization and discrete logarithms — that a sufficiently powerful quantum computer running Shor's algorithm can solve efficiently. ML-KEM is based on the Learning With Errors (LWE) problem over module lattices, which... SAN FRANCISCO, CALIFORNIA, JUNE 25, 2026 — ZeroTier, one of the world’s top software-defined networking companies, today announced the launch of release candidate 2 (RC2) for ZeroTier Quantum, the world’s only end-to-end quantum-secure networking platform. This milestone marks the final testing phase, positioning the platform just one step away from general availability (GA). ZeroTier Quantum addresses the looming threat of quantum computing to traditional encryption by meeting NIST and NSA’s highest standards at CNSA 2. 0 — meeting or exceeding post-quantum cryptographic (PQC) hurdles defined by the U. S. government and targeted by regulated industries from 2027 onward. "Reaching our final release candidate milestone brings us to the precipice of a new era in network security," said Andrew Gault, CEO of ZeroTier. "ZeroTier Quantum isn’t an incremental update; it’s a fundamental paradigm shift. We’ve successfully added quantum-resistant cryptographic agility into our core architecture, while increasing the performance and resilience our customers depend upon. As we finalize our path to general availability, we’re giving organizations the tools to protect their data today against the quantum threats of tomorrow. " Following this milestone, ZeroTier Quantum’s immediate roadmap includes finalization of a comprehensive, independent third-party code audit and penetration test ahead of full commercial availability. Parallel cryptographic validation and robust support for AI platforms are also nearing delivery. Delivering Security, Performance, and Flexibility ZeroTier Quantum RC2 delivers on the brand’s foundational pillars of security, performance, and flexibility, providing robust quantum defense capabilities without layers of operational and implementation friction. To maximize security, the... CNSA 2.0 compliance is mandatory by January 2027 — is your agency's encryption strategy ready in time? The deadline is real. By January 2027, all U. S. national security systems must meet CNSA 2. 0 requirements, meaning post-quantum cryptography — or encryption designed to resist attacks from quantum computers — is no longer optional for government IT teams. It's mandatory. And with procurement cycles running 12 to 18 months, the window to act is already closing. If your agency is still running classical encryption across its network infrastructure, you're behind. CNSA 2. 0 compliance isn't just a checkbox exercise. It requires rethinking how government networks handle encryption, key exchange, and algorithm selection at a fundamental level. Here, we'll break down exactly what the standard demands, where most government networks fall short, and what a realistic path to compliance actually looks like. What CNSA 2. 0 Actually Requires CNSA 2. 0 is the NSA's updated cryptographic framework for protecting national security systems. It replaces CNSA 1. 0 and mandates a full transition to post-quantum cryptographic algorithms, specifically the standards NIST finalized in August 2024. At the algorithm level, CNSA 2. 0 requires ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism, formerly CRYSTALS-Kyber) for key establishment, ML-DSA (Module-Lattice-Based Digital Signature Algorithm) for digital signatures, and XMSS or LMS for firmware and software signing. Classical algorithms like RSA and elliptic curve cryptography aren't being supplemented — they're being replaced entirely. The standard also sets minimum key sizes significantly larger than what most current systems use, which has real implications for performance and infrastructure capacity. The January 2027 deadline applies specifically to national security... Adversaries are harvesting encrypted defense data today to decrypt it tomorrow — your window to act is closing fast. Somewhere right now, an adversary could be recording your encrypted network traffic. Not to read it today. But to store it, waiting for the moment quantum computing makes today's encryption obsolete. When that moment comes, the data they captured years ago becomes an open book. This is a "harvest now, decrypt later" (HNDL) attack — and it's not a theoretical future threat. It's happening now, targeting defense infrastructure, government communications, and critical systems around the world. The uncomfortable truth is that most organizations are already compromised in this sense. They just don't know it yet. Understanding what HNDL attacks are, why defense networks are prime targets, and what post-quantum encryption actually demands from your infrastructure is the first step toward closing that exposure window before it's too late. What is a harvest now, decrypt later attack? A harvest now, decrypt later attack is exactly what it sounds like. An adversary intercepts and stores encrypted data today with no intention of decrypting it immediately. They wait until they have access to a quantum computer powerful enough to break the encryption protecting that data. At that point, everything they collected becomes readable. The attack exploits a fundamental asymmetry in time. Data captured right now may still be sensitive in five, ten, or twenty years. Intelligence reports, weapons specifications, diplomatic communications, personnel records — none of these expire quickly. Current encryption standards like RSA and elliptic curve cryptography (ECC) hold up fine against classical computers, but they're mathematically vulnerable to sufficiently powerful quantum... The TL;DR: How do enterprises prepare for quantum computing security threats? Transitioning to a quantum-resistant architecture requires moving from panic to a phased roadmap. This guide outlines three-steps — Assessment, Mitigation, and Agility — to protect enterprise networks from today’s "harvest now, decrypt later" (HNDL) attacks and setting up for a long-term, secure future using hybrid post-quantum cryptography (PQC). Want a deeper breakdown of the terminology used in this article? Our complete networking, cybersecurity and cyberware glossary has you covered. We hear a lot of noise about Q-Day. It may sound like a bad sci-fi movie, but the threat is real. Cryptographically Relevant Quantum Computers (CRQCs) are coming. Recent advances in stabilization and error correction have suggested the timeline will be before the end of the decade. And that means the systems we trust every day, from VPNs and messaging to software updates, identity, cloud services, and critical infrastructure, will need a new security foundation. The next phase of quantum security isn’t about fear. It’s about readiness. We’ve spent years talking about what quantum computing could break. Now the conversation needs to move toward what enterprises can build, change, and protect before the risk becomes operationally urgent. The countdown has already begun. And waiting for a future deadline is a losing game. Defensive panic isn’t a business strategy. This post shifts the focus from what we stand to lose to how we actively defend our data. So, let’s lay the groundwork for a robust, quantum-resistant architecture. Shifting Gears: From Panic... Adversaries are harvesting encrypted government data today—quantum decryption is coming. Is your agency ready? Adversaries are already collecting encrypted government data. They're storing it now, waiting for quantum computers powerful enough to break the encryption protecting it. This isn't a theoretical scenario — it's an active, documented strategy called "harvest now, decrypt later," and it's happening against government networks today. The quantum threat isn't a future problem. It's a present one, and the clock on legacy cryptography is running out faster than most agencies realize. The path forward does exist. Post-quantum cryptography (PQC) standards are finalized, compliance deadlines are set, and modern networking platforms can migrate without tearing out existing infrastructure. But none of that helps if agencies treat quantum computing network security as something to sort out in the next budget cycle. Here's what government IT teams need to understand right now. Why Quantum Computing Is Already a Threat to Government Networks The threat isn't that quantum computers will break encryption tomorrow. The threat is that adversaries don't need to wait for that. Nation-state actors are intercepting and archiving encrypted government communications today, betting that quantum decryption capability will arrive within the decade. When it does, everything captured in the meantime becomes readable. This matters most for data with long-term sensitivity: classified communications, personnel records, infrastructure schematics, diplomatic cables, and intelligence assessments. The value of that data doesn't expire when the encryption eventually breaks. And it may actually increase. Government networks carry exactly the kind of information that makes harvest-now-decrypt-later attacks worth the investment. Treating quantum risk as a future problem ignores the... The TL;DR: ZeroTier has launched Custom Flow Rules in the new Central dashboard, allowing administrators to seamlessly transition from standard, template-based configurations to advanced, programmable network policies. This update delivers the granular control required for scaling Zero Trust Network Access (ZTNA) environments without sacrificing operational simplicity. ZeroTier networks give you policy control at the network layer without forcing everything through a brittle perimeter. You can define which identities are allowed to communicate, what resources they can reach, and how traffic should behave across distributed environments, leveraging centralized controls with decentralized ZTNA security principles. This is where flow rules come in. Flow rules are ZeroTier’s programmable policy engine for controlling traffic inside a ZeroTier network. Rules are checked from top to bottom. Each flow rule pairs one or more match conditions with an action, and the engine checks them top to bottom for every packet. The terminating actions are "accept" (allow the packet and stop), "drop" (block it), and "break" (stop the base rule set but still let capabilities apply). Rules can also tee or redirect traffic without ending evaluation. If a packet reaches the end of the rule set without being accepted, the engine drops it, which is why ZeroTier's default template ends in an explicit accept. The result is predictable policy: Traffic flows only where a rule allows it, and you tighten a network by deciding what to accept before that final rule. So, with this latest update, we’ve made flow rules and policy management significantly more flexible. The... The Southwest Missouri Cyber Crimes Task Force needed to securely share evidence, connect field investigators, and accelerate mobile forensic investigations. Secure Connectivity for High-Stakes Forensics The Southwest Missouri Cyber Crimes Task Force needed to securely share evidence, connect field investigators, and accelerate mobile forensic investigations. Download the White Paper Download the white paper The Challenge Critical Evidence in Fragile Workflows The Southwest Missouri Cyber Crimes Task Force investigates internet crimes against children across 22 counties, or roughly a quarter of the state. Operating across a large geographic region, with investigators frequently deployed in the field, the task force required a secure and operationally efficient way to transfer sensitive forensic data between investigators, mobile response teams, and centralized forensic labs. Investigators routinely worked from active field environments, often handling highly sensitive evidence during criminal investigations, search warrants, and school response cases, where secure and reliable access to investigative data was critical. That created two operational challenges: First, investigators needed a secure way to access and share sensitive evidence files, including photos and videos tied to active criminal investigations, without exposing that data to interception or third-party systems. Additionally, the rapid evolution of AI-driven cyber attacks and the emerging threat of quantum computing have drastically escalated these data transfer risks. While current cryptographic standards cannot fully prevent the "Harvest Now, Decrypt Later" (HNDL) or "Trust Now, Forge Later" (TNFL) attacks posed by future quantum decryption, reducing the immediate visibility and accessibility of these data streams remains a critical priority. Second, the digital forensics teams needed a faster way to move extracted device data from the field back to their forensic labs. “ZeroTier... Modern networks run on trust. Every HTTPS session, VPN tunnel, SSH login, certificate exchange, and software update depends on one thing: the cryptography underneath it still works. That trust keeps the internet moving. It keeps businesses running, infrastructure connected, and private communication private. This is the foundation of communication security (COMSEC), the systems, protocols, and cryptographic controls that protect trusted communication across modern networks. But trust isn't a strategy. It only holds until the math breaks. And Quantum computing changes and reinvisions that math. The risk isn't just that quantum computers could crack today’s encryption faster. The real risk is what happens next. When the cryptography securing modern communication fails, trust fails with it. Systems can no longer prove who they are talking to. Data can no longer prove it stayed private. Updates can no longer prove they came from the right source. And once that trust collapses, the network starts talking to anyone. Which Encryption Algorithms Are Vulnerable to Quantum Attacks? Public-key encryption algorithms, specificallyRivest-Shamir-Adleman (RSA) and Elliptic Curve Cryptography (ECC), are vulnerable to quantum attacks because their underlying mathematical problems can be reimagined and solved by a cryptographically relevant quantum computer (CRQC). In fact, nearly all legacy asymmetric cryptography is at risk, including RSA, Diffie-Hellman (DH), and Elliptic Curve Diffie-Hellman (ECDH). Legacy hashing algorithms like MD5 are also worth noting because they’re already considered weak and shouldn’t be part of any long-term security strategy. However, most of today’s secure communication relies on public-key cryptography, specifically RSA and ECC.... Many organizations think about quantum risk as a future problem. It isn’t. The data being targeted by quantum attacks is already moving across your network today. Attackers know they can’t break modern encryption yet. But they’re collecting it anyway and, from their point of view, for good reason. This is the reality behind “Harvest Now, Decrypt Later” (HNDL) attacks, a cybersecurity threat where adversaries intercept and store encrypted data traffic today so they can decrypt it in the future once cryptographically relevant quantum computers (CRQCs) become viable. The breach happens first. The visibility comes years later. And encryption is only the first half of the problem. When Trust Is the Target: What Is a "Trust Now, Forge Later" Attack? A “Trust Now, Forge Later” (TNFL) attack is a quantum-era threat where attackers collect trusted digital assets today so they can forge or abuse them in the future. The same quantum capabilities that threaten confidentiality also threaten trust itself. Security teams now have to think about TNFL attacks as well. In this scenario, adversaries collect certificates, digital signatures, identity material, and authentication credentials, and other cryptographic proof mechanisms today with the expectation that future quantum computers will enable them to break the underlying algorithms. This could let attackers forge signatures, compromise certificate chains, impersonate trusted users and systems, and undermine the integrity of software, communications, and critical business transactions long after the data was originally captured. The implications are far bigger than just encrypted traffic exposure. This becomes a direct challenge... Modern infrastructure doesn’t stay still. Devices move, users shift, networks grow, and the tools managing all of it need to keep pace without adding friction. Today, we’re releasing ZeroTier One 1. 16. 2, a housekeeping update with some real operational weight. It brings important cleanup, customer-driven fixes, broader platform support, and another step forward for the new Central experience. This release makes the platform cleaner, sharper, and easier to trust at scale. A New Look for Central The biggest visible changes start within the new Central navigation, which is now ready, active, and live in the UI. It’s a cleaner, more modern foundation for how customers move through ZeroTier, and it begins the path toward higher data density across the main interface. That matters for teams managing more users, more devices, more networks, and more operational detail inside a single view. For older ZeroTier customers already comfortable with ZeroTier’s single-pane-of-glass experience in Central, the new Central navigation preserves that familiar usability while opening the door to the next generation of features. Core Updates That Clean Up the Edges The 1. 16. 2 update to ZeroTier One includes several core updates that make day-to-day use smoother. On Windows ARM, we fixed an issue in the . msi installer that could block clean installation. That patch is now included, giving Windows ARM users a more reliable setup path. We’ve also increased the bridge node limit from 256 to 512. This change came from real-world customer needs and is already in the branch.... Quantum computing is usually framed as a cryptography problem: broken encryption, obsolete algorithms, and a race toward post-quantum standards. That framing is accurate, but incomplete. Because a zero-day vulnerability is fundamentally an unknown flaw written into software, it’s important to separate general zero-day risk from quantum-specific risk. Whether that flaw enables privilege escalation, remote access, service disruption, or something else entirely, the existence of a quantum computer doesn’t automatically make it more dangerous. Simply put: Quantum doesn’t inherently change the nature of a zero-day exploit. The real concern is what happens around it. If an unknown vulnerability sits inside an exposed endpoint that still depends on classical encryption, quantum could weaken the protections around that system. The risk isn’t that quantum computing creates new zero-day vulnerabilities. The risk is that it can discover more quickly and make already-exposed systems easier to reach, inspect, or compromise. Paired with AI and Quantum Machine Learning (QML), the risk is increased. That matters because finding exploitable flaws today still requires enormous manual effort, automated testing, or years of accumulated attacker knowledge. AI-driven analysis is already changing that by accelerating vulnerability discovery across massive codebases, identifying dangerous patterns, modeling software behavior, and surfacing potential attack paths far faster than human researchers alone. Quantum computing changes the next stage of the equation. Rather than discovering entirely new classes of vulnerabilities on its own, quantum systems could dramatically accelerate the exploitation of already-identified weaknesses by breaking or weakening the cryptographic protections that normally limit attacker speed, scale,... Post-quantum security is becoming an infrastructure and a compliance problem. Enterprises need a plan before “eventually” turns into “too late. ” During our recent Quantum Live! webinar, ZeroTier CEO Andrew Gault joined Lennon Day-Reynolds, CTO of Tech Integrity Lab, and Angelo Rodriguez, ZeroTier’s SVP of Global Operations, for a practical conversation about what the post-quantum era actually means for enterprises and their networks. Hundreds of ZeroTier users, IT specialists, and cybersecurity professionals joined the session, bringing thoughtful questions and clear urgency to this topic that’s quickly reshaping enterprise network strategy. The discussion got past the hype and answered: What is the real quantum threat? How should security teams think about it? Why is long-lived infrastructure exposed? What can enterprises do now, before standards, auditors, and attackers force timelines upon them? From cryptographic risk to distributed networking architecture, the conversation focused around one central idea: waiting for “Q-Day” isn’t a strategy. Here are three key takeaways from the session: 1. Is the Quantum Threat Real? Yes, and Here’s Why. One of the biggest misconceptions around post-quantum security is that quantum computing is still too far away to matter today. Quantum Live! debunked that myth, detailing how the threat is already becoming a real-world concern for your enterprise infrastructure. The countdown begins with the advent of a Cryptographically Relevant Quantum Computer (CRQC) or the moment a quantum computer achieves the computational power to execute Shor's algorithm effectively. Upon reaching this threshold, the clock runs out on foundational security protocols like TLS/SSL, standard... On May 13, ZeroTier hosted Quantum Live! , a practical look at one of the biggest security shifts in decades: the move to post-quantum infrastructure. The session drew hundreds of attendees and focused on what quantum computing changes, why post-quantum cryptography is becoming an operational priority, what enterprises can do now to prepare, and how ZeroTier Quantum helps enterprises prepare now for the quantum-era. Hosted by ZeroTier CEO Andrew Gault, the session featured Lennon Day-Reynolds, CTO of Tech Integrity Lab, and Angelo Rodriguez, SVP of Global Operations at ZeroTier. Together, they unpacked what’s now being called “Q-Day” — the point where cryptographically relevant quantum computers (CRQCs) become capable of breaking the encryption standards protecting modern systems today. Why the Quantum Threat Matters Now The session kicked off with a practical look at what quantum computing actually means for security teams and discussed how advances in qubits, superposition, and quantum-leverage against algorithms like Shor’s are turning once-theoretical concerns into real planning priorities. The discussion also took a look at “harvest now, decrypt later” attacks, where adversaries collect encrypted data today with the intention of decrypting it once quantum systems mature while touching on “trust now, forge later” identity attacks. The key takeaway was simple: Organizations handling long-lived sensitive data can’t afford to wait for mandates before acting. The conversation also expanded into the wider blast radius of (5, 6 or 7) key quantum-scale attacks: digital signatures, identity systems, TLS/SSL traffic, hardware security modules, and critical infrastructure all came into focus. PQC... Modern networking infrastructure doesn’t wait around. Users join, permissions change, systems update, and teams need those changes to trigger the right action and quickly. That’s what makes webhooks so useful. They give your environment an easy, event-driven way to react when something changes, instead of relying on scheduled polling, manual checks, or someone noticing a dashboard update. This is especially true for disparate systems, intermixing and connecting different vendors, or enhancing your own custom software stack. This week, ZeroTier has rolled out webhooks for the new Central dashboard within ZeroTier One, giving teams a simpler way to connect ZeroTier events to the tools and processes they already use. Existing users on the original Central experience will continue to have access as usual, with no changes to their current workflows. Instead of repeatedly polling the API for updates, webhooks can push changes instantly to your systems the moment they happen. That means less overhead, faster workflows, and a cleaner way to integrate ZeroTier into the tools and processes your teams already rely on. This latest release continues ZeroTier’s push toward more scalable, automation-friendly infrastructure management across the new ZeroTier Central experience. Real-Time Events for Faster Workflows Webhooks are designed to help teams react to changes in real time. Whether you’re tracking organization membership updates, triggering downstream workflows, or syncing activity across platforms, webhooks eliminate the need for constant API requests just to check if something changed. The first release focuses on organization membership events, making it easier for IT and security... Quantum computing is moving from theory to real-world strategy. This shift in computational paradigms changes how teams think about cybersecurity, risk, and network design. You don't need to become a quantum expert overnight. But, you do need to know where your systems are exposed, then build infrastructure that can adapt before the threat arrives. Grasping quantum dynamics requires distinguishing them from classical frameworks. These machines aren't just high-speed traditional computers. Instead, they use fundamentally different logic gates and information processing methods. As a result, they introduce unique threat vectors that necessitate a complete re-evaluation of current security protocols. How Quantum Changes Compute At a basic level, classical computers that we use today process bits as 0s or 1s. This has been our norm for decades. However, quantum architectures leverage qubits via superposition, which occupy multiple states simultaneously. That may sound abstract, but the practical effect is simple: quantum systems can explore many possible solutions simultaneously, which exponentially increases their computing power. Coupled with a second principle, entanglement, where qubits maintain instantaneous correlations, these systems operate well beyond classical computational limits. A cryptographically relevant quantum computer (CRQC) is the point where that power becomes strong enough to threaten the encryption standards modern networks depend on. This “quantum impact” extends beyond accelerating existing tasks. It also addresses computationally difficult problems like prime factorization. Shor’s algorithm is the clearest example of why quantum security matters. It’s a quantum algorithm designed to solve the hard math behind RSA and ECC encryption far faster than... The nation that leads in space will lead the future. That starts not just with rockets and satellites, but also with secure communication, resilient navigation, strong national security, and the proper networks we’ll need to explore the solar system. From spacecraft development, to launch, to ground control and more, the commercial space industry is growing fast to meet the challenges ahead. The growing number of manufacturers and contractors innovating and operating in space will encounter a range of networking and cybersecurity challenges, in an endeavor where millimeters and milliseconds separate success from catastrophe. Connecting it all demands flexible, high-performance and secure networking. Not since the days of Apollo has the U. S. national attention been so focused on the skies. Commercial space companies are launching at a rapid pace and scaling just as quickly. From 2015–2024, investors poured $66 billion into space startups, according to space engineering and analytics firm BryceTech. Startups are innovating in spacecraft manufacturing, launch, ground equipment, satellite communications, geospatial analytics, human spaceflight, and more. The international presence in space consists of two occupied spacecraft, ISS and Tiangong, with a total crew of 10 in orbit, plus about 14,200 satellites and a further 30,000 objects tracked by space surveillance networks. Following the success of Artemis II’s voyage to the moon and back, the U. S. and other nations will pursue manned exploration and colonization. Satellites in orbit and development provide a range of services: global communications and relay, positioning, navigation and timing systems like GPS, surveillance and... Today’s security models were designed for the threat environment we know, and, in many cases, they still work. But quantum introduces a different kind of risk: data intercepted today may become readable later. That’s what changes the equation. The threat is not only future compromise. It’s present-day exposure with delayed consequences. Just last March 2026, Google accelerated its internal post-quantum cryptography (PQC) migration deadline to 2029, citing rapid advances in quantum hardware, error correction, and factoring estimates. This wasn’t a press release. It was a revised threat model from one of the most sophisticated security organizations in the world — and it signals that the window for quantum-enabled decryption is compressing into the late 2020s. The NSA reached the same conclusion. CNSA 2. 0 mandates migration to post-quantum cryptography for national security systems, with timelines already underway and extending through 2033. NSM-10 and OMB M-23-02 require agencies to inventory cryptographic assets, identify exposure, and execute formal migration plans. These aren’t guidelines. They’re compliance requirements tied to reporting, budget, and procurement. For enterprise security leaders, this is the shift: quantum risk is no longer theoretical. It’s a forcing function reshaping how security is evaluated and purchased. The question isn’t whether the risk is real. It’s whether your organization will be ahead of the transition — or catching up to it. The Threat Already in Motion Hackers and nation-state adversaries are already penetrating defense and intelligence networks, maintaining persistent access, and exfiltrating encrypted data for future use. This is the “harvest now,... Automation is only as reliable as the access behind it. APIs make it possible to manage networks programmatically, but when that access is tied to individual users, things break down quickly. Sessions expire, permissions change, and workflows that should run continuously become fragile. As part of ZeroTier’s bedrock commitment to zero-trust principles, systems need a more stable way to authenticate and operate without depending on a person being logged in. Today, we’re rolling out new capabilities in ZeroTier One accessible via the new Central dashboard, including service accounts, API keys, and plumbing for an upcoming release of webhooks. Together, these updates give users more practical ways to build, automate, and integrate with ZeroTier One. Service Accounts for Security and Always-On Access Service accounts are designed for system-level access. Instead of tying automation to an individual user login, customers can create an account meant specifically for software, scripts, and administrative or operational workflows. That matters for any use case where access or permissions need to persist for a long time. A human’s session may expire, and a person’s role and privileges may change over time. A service account is different. It gives organizations a stable way to connect systems to ZeroTier One without depending on a single employee’s credentials. This is useful in a range of scenarios. A customer may need to automate how devices are assigned. An MSP or reseller may need a cleaner way to manage multiple customer environments. In both cases, service accounts create a more durable foundation... SAN FRANCISCO, CALIFORNIA, APRIL 14, 2026 — ZeroTier, one of the world’s top software-defined networking companies, announced today it has been named “Cybersecurity Solution of the Year 2026” by The Cyber Security Review magazine. The award recognizes ZeroTier’s leadership in delivering a secure, software-defined networking platform that meets the demands of modern enterprises. As organizations continue to scale across cloud, edge, and hybrid environments, including an explosion of AI agents, ZeroTier provides a simple, identity-based way to connect users, workloads, and devices, without the complexity of legacy networking. ZeroTier replaces rigid infrastructure with direct, encrypted connectivity. It enables enterprises to build flat networks across clouds, data centers, and edge environments with defense-grade security. Its peer-to-peer architecture and end-to-end encryption aligns to any network topology to create resilient connectivity from enterprise IT to regulated industries to defense and mission-critical systems. “Networking is still too complex, too exposed, and too expensive,” said Andrew Gault, CEO of ZeroTier. “We’re changing that. This recognition reinforces our mission to give organizations a simpler, more secure way to connect everything. ” In a special award feature, The Cyber Security Review highlighted ZeroTier’s forward-looking, innovative approach to connectivity and security, especially as enterprises prepare for AI-driven traffic growth, distributed systems, and emerging quantum threats. To combat these threats, ZeroTier recently rolled out ZeroTier Quantum, the first software-defined, end-to-end quantum-secure networking platform in the world. Designed for on-wire, data center level performance, ZeroTier’s quantum cryptographic construction meets NIST and NSA’s highest standards at CNSA 2. 0 — exceeding... The U. S’s most sensitive computer networks are under daily attack today by adversarial hackers, and these networks’ data encryption needs to hold off the supercomputers of the future. Adversaries, including nation state actors, have demonstrated they can break into defense and intelligence networks, lie low and live off the land, and gather intelligence for future strategic planning and commercial advantage. They’re playing the long game, waiting patiently for the advent of quantum computing so powerful it can crack today’s standard encryption algorithms. The U. S. military and intelligence community and the contractors and vendors who serve them — along with militaries around the world — must immediately begin migrating sensitive networks and data stores to encryption systems running algorithms that quantum computers won’t be able to crack. The U. S. government knows this. This is not fantasy or fiction. The NSA's Commercial National Security Algorithm Suite 2. 0 (CNSA 2. 0) mandates the transition to post-quantum cryptography for national security systems, with compliance timelines beginning now and running through 2033. CISA and NIST have finalized the first quantum-resistant standards. At RSAC 2026, that mandate showed up as execution pressure: vendors shifted from theory to deployment, rolling out crypto discovery, hybrid PQC, and hardware-level implementations built explicitly for CNSA 2. 0 timelines. Before that, the Department of War in November launched the migration, including ordering the department to catalog “all cryptography used in any type of system” and to identify internal leads to run the migration. “Now is the time... https://youtu. be/n83GxYKHXd4? controls=0 Read the transcript Andrew GaultWelcome everyone to Quantum Live. We’re excited to walk you through the quantum threat and how ZeroTier Quantum is addressing the challenges of post-quantum cryptography. Today’s session is May 13th, 2026. Okay, so I’m Andrew Gault, CEO of ZeroTier, and I’ll be your host today. I’m pleased to introduce our experts. First, we haveLennon Day-Reynolds, CTO of Tech Integrity Lab, who will guide us through the threat landscape and defense strategies. And later, we’ll hear fromAngelo Rodriguez, SVP of Global Operations at ZeroTier on the ZeroTier Quantum solution and many of our common use cases. Would you guys like to do a quick intro? Lennon Day-ReynoldsYeah, sure. Hi, as Andrew mentioned, I’m Lennon Day-Reynolds. I actually worked at ZeroTier for several years before leaving to co-found the Tech Integrity Lab. What we do is advance research into AI and machine learning algorithms. I lean on ZeroTier every day to secure the connections and systems that we use for that research. I was also still at ZeroTier for a lot of the development of ZeroTier Quantum, and so I’m very excited to get to share with the team kind of why we’re so excited about what it can do. So thanks. Angelo RodriguezHi, I’m Angelo Rodriguez. I’m the SVP of Global Operations at ZeroTier. I’ve been with the company for several years, working very closely with our engineering team as we develop this quantum platform. I also lead our customer success and pre-sales engineering... Quantum computing is forcing a shift in how we think about security. Quantum computing isn’t theoretical anymore. It’s forcing a fundamental shift in how we think about security. If you’ve tried to understand post-quantum cryptography (PQC), you’ve probably run into: Dense academic papers Math-heavy explanations A lot of “trust us, it’s complicated” Here’s what you need to know: 1. What actually is post-quantum cryptography? Post-quantum cryptography is a new class of encryption designed to remain secure, even against quantum computers. Instead of relying on problems quantum systems can solve efficiently, PQC uses fundamentally different approaches. One of the most important is Lattice-based cryptography (used in standards like ML-KEM). You don’t need the math to understand the impact. These problems are hard in a different way, and current quantum approaches don’t break them efficiently. 2. What modern post-quantum security looks like Modern systems, like ZeroTier Quantum, are built differently. They: Use quantum-resistant cryptography aligned to emerging standards Combine classical and post-quantum methods (so both must be broken) Continuously rotate keys (forward secrecy) Protect identity and metadata — not just payload data Assume attackers can record everything today This is where the conversation shifts from “Which algorithm should we use? ” to, “How is security built into the system itself? ” 3. Why this matters now (and not later) Here’s what most organizations miss: Attackers don’t need to break encryption today to benefit from quantum. They can capture encrypted data now and: Store it Decrypt it later when quantum systems mature This... RSAC 2026 made one thing clear: networking and cybersecurity are no longer separate conversations. They’re becoming one operating model. Beneath the AI headlines, the real shift was structural. Security is moving from alerting to action. Identity is becoming the control plane for everything, including users, workloads, and AI agents. And zero trust is finally turning into real infrastructure. Together, these trends point to a deeper change. The network is no longer just where traffic flows. It’s where decisions get made. It’s where trust is enforced in real time. Here are the three shifts that mattered most — and why they’re redefining how security and networking work together. Fix it, Don’t Flag it First, security is moving from detection to action. For years, security teams bought tools that found problems faster. That’s no longer enough. At RSAC 2026, the market signal was clear: finding issues is table stakes. The real value is fixing them. Multiple conference analyses pointed to a shift away from point solutions toward platforms that integrate detection, response, and remediation. Security teams are also moving beyond using AI just to detect threats and toward automated remediation and policy enforcement. At the same time, security operations are becoming increasingly automated, with workflows that include triage, investigation, isolation, and patching. That changes the role of the network. It becomes part of the response loop. The platforms that win will not just see what’s happening. They’ll help contain, route, isolate, and enforce in real time. Identity Runs the Stack The second... Quantum computing isn’t breaking your network tomorrow. But it is changing the clock. Post-quantum cryptography (PQC) refers to new encryption algorithms designed to withstand attacks from future quantum computers. Today’s widely used public-key cryptography, like RSA and elliptic curve, could eventually be vulnerable to sufficiently powerful quantum systems. We’re not there yet. But the transition won’t happen overnight either. For enterprise network teams in 2026, the question isn’t “Are we quantum-safe? ” It’s “Are we architected to adapt? ” Here’s what enterprise network teams can do now to prepare for the post-quantum transition. Build Around Evolving PQC StandardsThe National Institute of Standards and Technology (NIST) has already selected several post-quantum cryptographic algorithms for standardization, with more guidance continuing to evolve. Vendors have already begun integrating these standards into browsers and some select hardware, but full hardware, cloud platforms, operating systems, and more areas across the networking stack will take the next several years. This is not a rip-and-replace event. It’s a phased transition. The enterprises that handle it well will be the ones that treat it as a lifecycle issue, not a crisis response. Your job today isn’t to deploy PQC everywhere but to prepare your environment so you can. Find the Friction PointsCryptography already runs through the modern network. The question is not where it exists. It’s where it will be hardest to change. Focus on systems that rely on public-key cryptography and will be difficult to update as standards evolve. VPN infrastructure. TLS inspection. Load balancers. Internal services.... SAN FRANCISCO, CALIFORNIA, MARCH 23, 2026 — ZeroTier, a leading software-defined networking company, announced today the launch of ZeroTier Quantum, the world’s highest performance, most secure software-defined networking platform. Designed for on-wire, data center level speed, ZeroTier’s quantum cryptographic construction meets NIST and NSA’s highest standards at CNSA 2. 0 — exceeding PQC hurdles targeted by governments and regulated industries from 2026 onward. ZeroTier Quantum is the only software-defined, full end-to-end quantum platform on the market. Organizations today operate far beyond traditional network boundaries — autonomous devices, machines, vehicles, agents, and infrastructure span continents, oceans, and remote environments, constantly transmitting sensitive data that must stay secure. At the same time, AI leverage and quantum computing are ushering in a new class of risk: encrypted data captured today can be stored and decrypted later, and attackers will be able to launch direct attacks at scales impossible to imagine even a few years ago. Purpose-built from the ground up, ZeroTier Quantum addresses the challenges of both an explosion of the attack surface and the realities of the quantum era by delivering end-to-end quantum-secure networking that integrates directly into existing platforms, infrastructure, and products. Rather than forcing organizations to redesign the key technologies they already operate, ZeroTier Quantum opens up a wide range of use cases, including: Defense and government high-security, resilient, and even offline network connectivity use cases, including dynamic, high threat environments Scaled enterprise IT connectivity, including AI cloud, hybrid cloud, and remote employees On-floor and remote player secure communications for... SAN FRANCISCO, CALIFORNIA, MARCH 18, 2026 — ZeroTier, one of the world’s top software-defined networking companies, announced today it was named a winner in the Software Industry Solution category of the 2026 Cybersecurity Excellence Awards. This recognition highlights ZeroTier’s commitment to providing a robust, resilient, end-to-end encrypted networking platform for customers across the globe. The Cybersecurity Excellence Awards, produced by Cybersecurity Insiders, celebrate companies, products, and notable professionals that demonstrate excellence, innovation, and leadership in information security. Each year, hundreds of nominations are reviewed by an independent jury of cybersecurity practitioners, analysts, CIOs and CISOs from the Cybersecurity Insiders community. Past Cybersecurity Excellence Award winners have included CISCO, CrowdStrike, AT&T Business, Palo Alto Networks, Fortinet, and Zscaler among many others. “We congratulate ZeroTier for your outstanding achievements in the ‘Software’ category of the 2026 Cybersecurity Excellence Awards,” said Holger Schulze, founder of Cybersecurity Insiders and organizer of the Cybersecurity Excellence Awards. “As we celebrate 10 years of recognizing global excellence in cybersecurity, ZeroTier’s innovation and leadership sets a powerful example for the entire industry. ” ZeroTier is critical for modern enterprises, defense and government organizations, and software and technology providers that need to securely connect users, workloads, and devices across an increasingly fragmented digital landscape. The recently released Central for ZeroTier One included a completely new streamlined user interface, enhanced onboarding, and a modernized backend architecture designed to make network management faster, simpler, and more powerful than ever. “With AI changing the landscape of cyberattacks and the quantum threat just... Imagine a swarm of UAS’s launching on a mission to surveil and test adversary air and EW defenses and strike targets of opportunity. The force constitutes a range of VTOL and tiltrotor platforms from different vendors, with varying software and modular payloads. The swarm’s advanced C2 system incorporates elements of centralized control for efficient ISR data transmission, hierarchical or orchestrated control, and then decentralized action by consensus. ZeroTier’s mesh network and rapid failover give the system the flexibility to adapt and adjust to both the threat environment and normal flight operations. Millisecond multi-pathing speeds are crucial, not only to prevent flight trajectory problems local to the swarm, including intra-swarm considerations, but also to allow for seamless communication with GCS for updates and rerouting. The drones themselves are linked to a range of classified and unclassified systems and networks, forward-deployed tactical units and edge sensors, all in a peer-to-peer mesh. Back at GCS, RPA pilots, sensor operators and others monitor ZeroTier’s Central dashboard. The drones are linked up on a ZeroTier SDN on a secure Wi-Fi network. An enterprise system pushes software updates, giving the drones new algorithms, datasets and software for the mission at hand — maps for navigation over GNSS-denied terrain, fresh computer vision algorithms for target identification. ZeroTier creates virtual network segments based on software versions and trust levels: One set of drones, say performing an ISR mission, runs older, battle-tested software, while another sent to provide overwatch and close combat support for a mounted infantry unit has... In the chaos of a firefight, infantry units need more than ammunition, ISR, and fire support. They need ultra-robust and resilient networking to comms with allied or Blue force tracking, command and control, and sensor data from squad level up to brigade. Infantrymen across the unit will carry a range of devices, all linked in the C2 ecosystem. The enemy will do what it can to jam communications nodes. Equipment will be damaged or destroyed, and units move. The warfighter demands networking technology that can easily scale up to link every device on the battlefield, operate on every communications channel, and find the most efficient available path around choke points in the toughest comms environments. Built for the Fight You Actually Have ZeroTier’s next-generation connectivity and cybersecurity platform is resilient, secure, and simple, and can handle infantry maneuver in the toughest comms environments without configuring hardware and manually hopping frequencies. It can link any device and every part of the tactical network architecture: tactical radios and smart phones, sensors, hardened computing platforms, vehicle mounted routers and switches, MUOS terminals, UAV relays, and drones for overwatch, and much more. It is the strongest and most economical networking solution for the future of tactical infantry maneuver. ZeroTier’s lightweight client meets the most stringent SWAP-C requirements and can operate on any device, so users aren’t locked into vendor networking devices. That helps U. S. and allied militaries keep abreast of innovation. And in a conflict with a peer adversary possessing advanced electronic warfare... The Pentagon’s plan for U. S. drone dominance envisions masses of attritable UAVs performing every conceivable mission set in support of the warfighter. That demands global networking that can scale and connect all those devices as seamlessly as if they were in the same room — even if they’re swarming over water toward an adversary target and uploading sensor data and ISR imagery to enterprise systems. Autonomous systems will come in a range of platforms and will rely on an array of enterprise and GCS systems. They will need simple, resilient and secure communications on multiple channels and bands. To keep abreast of innovation, they can’t be locked into vendor networking devices. And in a conflict with a peer adversary equipped with advanced electronic warfare and cyber capabilities, the network connecting those devices and systems must deliver ultra-fast failover across satellite and terrestrial links, including line-of-sight (LOS) and other ground-based channels, to maintain uninterrupted operations. ZeroTier’s next-generation connectivity and cybersecurity handles scenarios that traditional networking struggles with: edge devices, remote industrial or IoT deployments, multi-vendor environments, userless devices, complex NAT traversal, and distributed teams, while working dynamically over different connectivity mediums. It’s simple, resilient and secure: the strongest and most economical networking solution for the future of tactical autonomy. If it Flies, ZeroTier Can Network it A ZeroTier software-defined network is highly flexible, enabling the dynamic command and control architecture that autonomous missions will demand. Using ZeroTier, drone units can rapidly build a decentralized mesh network linking up the dozens... When people talk about quantum threats, they usually jump straight to cryptography. Broken encryption. Shattered trust models. A clean before-and-after moment where everything old stops working. That framing is comforting, because it suggests quantum is a single event we can prepare for, patch around, and move past. In practice, it won’t be that clean. The common approach today is straightforward. Organizations inventory their networks, rank systems by criticality, focus on public-facing services, and plan a phased migration to new cryptographic standards. It’s careful, deliberate work designed to avoid outages and compliance surprises. For large enterprises, that process takes years. The problem isn’t the rigor, it’s the assumption that the threat model stays stable while the work is underway. Part of the real danger isn’t that quantum suddenly arrives later in the decade and flips a switch. It’s that the threats we’re already struggling with are evolving quickly, and quantum capabilities will amplify them. The bleeding is already here. AI Is Changing the Shape of Attacks We’ve moved past the phase where AI just helps attackers write better phishing emails or automate reconnaissance. The next generation of attacks won’t be “AI-assisted. ” They’ll be autonomous — intelligent agents that don’t just execute a playbook, but adapt in real time once they’re inside your network. Imagine an attacker that compromises a certificate, exfiltrates data, and then keeps going. It notices a forgotten server running an unpatched Windows build from years ago. It understands the risk, pivots, escalates, corrupts data, and deliberately crashes... Firewalls and policy engines exist for a simple reason: the internet doesn’t provide trust by default. It was designed to move packets reliably, not to verify identity, intent, or safety. Any reachable system can be scanned or attacked, and any exposed service becomes part of the global attack surface. Firewalls reduce that risk by deciding which traffic is allowed to exist at all, shrinking exposure and narrowing the blast radius before problems spread. We’re excited to officially announce the roll out of ZeroTier’s latest release for Central, which introduces ”flow rules” in template form. Flow rules themselves aren’t new to ZeroTier. They’ve existed for years as an element of ZeroTier One and have quietly powered some of the most sophisticated ZeroTier deployments. What’s new is bringing that capability forward into Central’s UI, making a proven, powerful policy engine easier to use, easier to reason about, and available to a much broader set of users. If you’ve spent years building and maintaining rulesets around static perimeters, IP ranges, and edge-bound appliances, flow rules are a deliberate reset. They’re ZeroTier’s native policy model, built for decentralized, zero-trust networks where location fades into the background and identity takes over. What Are Flow Rules? Before we break it down further, let’s first answer: what exactly are flow rules? Flow rules define how devices and services can communicate on a ZeroTier network. Rules are enforced locally on each device, not through a central firewall. By default, all traffic is permitted within whatever existing traffic and... Firewalls and policy engines exist for one simple reason: the internet doesn’t provide trust by default. It was designed to move packets reliably, not to verify identity, intent, or safety. Any system that’s reachable can be scanned or attacked, and any exposed service becomes part of the global attack surface. Firewalls impose the first layer of control by deciding which traffic is allowed to exist at all. They reduce exposure, limit blast radius, and prevent unauthorized access from spreading unchecked. Policy engines extend this model by adding context and intent. Instead of relying only on static attributes like IP addresses or ports, they evaluate who is communicating, why, and under what conditions. This enables least-privilege access and zero-trust models, where connectivity is explicit and continuously enforced rather than assumed based on network location. Together, firewalls and policy engines make it possible to run complex systems securely on an otherwise open and hostile network. How Does this Fit with a Zero Trust or Centralized Posture? In a zero-trust model, firewalls and policy engines are no longer just perimeter defenses. They’re the mechanisms that make trust explicit. Zero trust assumes there is no safe “inside,” no inherently trusted segment, and no device or workload that should be allowed to communicate simply because it’s connected. Firewalls shrink the attack surface by ensuring that connectivity exists only where it’s intentionally allowed. Policy engines take this further by deciding whether a connection should be permitted based on identity, role, posture, and intent, not where traffic... The biggest security shift heading into 2026 isn’t a new exploit, a breakthrough vulnerability, or some yet-to-be-known attack technique. It’s access. And more specifically, how easy access the variations on gaining it are becoming to obtain, abuse, and scale. Advancements in AI are accelerating this trend at a pace most organizations aren’t structurally prepared for. Capabilities that once belonged to highly skilled, well-funded teams are now widely available. AI can explain, generate, and adapt code at machine speed. It can reason through unfamiliar architectures, identify likely failure points, and help troubleshoot broken implementations in real time. Entry-level hackers can punch far above their weight, not because they’re more talented, but because the tooling around them is dramatically more capable. And while quantum computing isn’t here yet, its shadow is already forcing hard decisions about cryptography, data lifetimes, and architectural longevity. The common thread across all of this is simple: the cost of being dangerous is dropping fast. AI Amplification of Existing Attacks Systems like Anthropic’s Claude aren’t “hacking tools” in the traditional sense. They aren’t designed to find zero-days or automatically compromise systems. What makes them disruptive is something more subtle and more impactful: they act as accelerants. Claude can read unfamiliar code, explain protocols, reason about system architecture, and help troubleshoot broken or incomplete implementations. For engineers, that’s a productivity multiplier. For attackers, it removes one of the biggest historical barriers to entry: understanding how a system is supposed to work before figuring out how to break. This proves... Active Security needed to stream real-time video from OT sensors across cellular, satellite, and fiber networks to secure high-stakes events. Mission-Critical Video Made Simple Active Security needed to stream real-time video from OT sensors across cellular, satellite, and fiber networks to secure high-stakes events. Access the Case Study Access the Case Study The Challenge High-Stakes Video Via Fragile Networks Active Security faced a complex technical challenge: delivering real-time video streams from operational technology (OT) sensors and systems during high-visibility events. These streams needed to reach a global audience reliably across cellular, satellite, and fiber WANs. Each event required low-latency video from multiple remote locations, and traditional VPNs and hardware-based SD-WANs were too inflexible, costly, and slow to deploy. “Traditional VPN and hardware-based solutions simply couldn’t meet the speed, flexibility, and security requirements our discerning clients demand. ” — JP Rike, Chief Technology Officer at Active Security The Solution Secure Connectivity without Compromise Using ZeroTier, Active Security designed a software-defined network that created low-latency peer-to-peer connections through a virtual ethernet overlay. It unified disparate networks across satellite, 5G, and fiber into a single virtual fabric while securing all traffic with end-to-end encryption and strict access controls. Access the Full White Paper Want to learn how Active Security uses ZeroTier to deliver real-time OT video across cellular, satellite, and fiber for high-stakes events? By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by... 2026 is here. And if your network still feels like a patchwork of VPNs, firewalls, cloud dashboards, and workarounds, you’re already behind. Small and mid-sized businesses don’t need enterprise level budgeting to be enterprise-ready. All they need is a network that’s secure, flexible, and designed for how work actually happens now. Use this checklist to pressure-test your network and make sure it’s built for 2026 and not stuck defending 2016. 1. Your Network Works Everywhere (Not Just in the Office) If your network still assumes people and apps live in one building, it’s already obsolete. In 2026, your workforce is remote or hybrid by default, cloud-first, and constantly moving between devices and locations. Your network should follow your business automatically — without brittle VPN tunnels or manual reconfiguration every time someone logs in from somewhere new. In 2026, your workforce should be: Remote or hybrid by default Cloud-first and SaaS-heavy Able to connect from multiple devices and locations Your network should move with your business. If you’re still stitching together VPNs just to make basic access work, that’s a huge red flag. 2. Access Is Identity-Based, Not Location-Based Trusting anything “inside the perimeter” is a relic of a simpler time. Modern networks authenticate who and what is connecting, not where they’re connecting from. If access decisions are still tied to IP addresses or office walls, you’re taking on risk that zero-trust networking’s already solved. Networks in 2026 need to: Authenticate users and devices individually Enforce least-privilege access Operate on zero... In 2025 the pace and sophistication of cyber hacks reached alarming levels. A sweeping cyber espionage campaign targeting Microsoft SharePoint servers compromised roughly 100 organizations in July. Only one month later, the automotive industry was hit when Jaguar Land Rover faced what’s been called the costliest cyberattack in U. K. history. And across dozens of industries, from retail to education, data breaches exploded as hackers found open doors in exposed endpoints and flat networks, gaps that encrypted connections could have closed. 2025 wasn’t an anomaly; it was a warning. 
This past year exposed how fragile modern networks still are — flat, overexposed, and dependent on centralized infrastructure. The biggest damage didn’t come from clever phishing emails. It came from open doors, shared blast radiuses, and brittle network design. Here, we count down the 10 most impactful cyberattacks and failure modes of 2025, and what they reveal heading into 2026. 10. Beware 2026: The Rise of AI-Driven Malware AI was everywhere in 2025, including in the cyber hack conversation. According to Experian’s newly released 2026 Data Breach Industry Forecast, cyber threats in 2026 will be dramatically reshaped by the adoption of AI — not just by defenders, but by attackers. One highlight example in 2025 was Anthropic’s report on the manipulation of its AI coding tool, Claude Code, by a China-linked group to perform “the first reported AI-orchestrated cyber espionage campaign” that required significantly less human tactical work for a large-scale attack. Some of the key predictions in Experian’s report included... UAVs have become a core part of modern defense and security operations. They support ISR missions, perimeter monitoring, supply delivery, and real-time decision making. Drone swarms add even more capability, giving teams coordinated autonomy, distributed sensing, and built-in redundancy. These aircraft generate a constant stream of telemetry, video, and sensor data. They also need reliable communication with edge nodes and command systems to stay coordinated. Unlike commercial fleets, defense systems must perform under pressure, operate with limited infrastructure, and respond to unpredictable conditions — or even respond to hostile jamming activities. Networking becomes the backbone of every flight and every decision. And it’s what every pilot needs: a strong networking backbone that guarantees every flight and decision. The Connectivity Challenge Across Degraded, Contested, and Remote Environment Defense teams regularly work in environments where communication is disrupted or unavailable. UAVs often fly through degraded, contested, or remote areas where interference, jamming attempts, and unstable routing are part of the landscape. SATCOM, private 5G, tactical radios, and ad hoc networks can appear, disappear, or degrade without warning. This isn’t just a challenge for the aircraft. Ground operators and field teams move through the same shifting landscape. A mobile command vehicle might start on private 5G, lose coverage behind terrain, and switch to a line-of-sight radio link. A field operator could move between Wi-Fi, tactical mesh, and cellular coverage in a matter of minutes. Everyone needs secure handoffs that keep communication intact through every transition. Traditional networking tools break under these conditions. They... This is the second installment of a multi-part blog series exploring how drones can stay connected, secure, and mission-ready with device-level networking. Anyone who’s spent time flying a drone has seen it happen: the feed stutters, the signal dips, and for a few seconds you’re flying half-blind. Now raise the stakes. Swap that hobby flight for a defense mission, an inspection run, or a live broadcast. That same hiccup becomes a real operational risk. Connectivity breaks at the device level, and that’s exactly where ZeroTier is built to hold the line. ZeroTier brings secure networking directly to the drone. Not the router. Not the command center, but the device. The moment a drone boots up, the ZeroTier Agent activates a Virtual Network Interface Controller (VNIC), effectively a virtual card that gives the drone a stable, cryptographically verified network identity. From that point on, the drone behaves as if it’s plugged into a clean, local network, whether 10 feet or 10,000 feet in the air, switching between LoRa, LTE, 5G, or satellite. Joining the network: How a drone actually connects with ZeroTier At the device level, onboarding is simple: install the lightweight ZeroTier Agent and authorize it in ZeroTier Central. The drone immediately generates a cryptographic identity that stays consistent across power cycles, flight paths, network changes, and coverage gaps. There’s no dealing with static IPs, port forwarding, or fragile VPN tunnels. The VNIC handles all of it. ZeroTier sets up a secure, peer-to-peer channel that follows the drone wherever it... The internet began as a simple, open network where every device could reach every other directly. Researchers and engineers built new applications on top of that open foundation, and collaboration thrived. Over time, new layers of protection fractured that simplicity. Firewalls, NAT gateways, and corporate perimeters made it harder for devices to reach one another directly. What began as a peer-to-peer web of trusted connections turned into a maze of intermediaries. This expanding complexity also introduced more weak spots and an ever-growing attack surface, increasing the risk and maintenance burden for network operators. Most of the internet’s traffic now flows through centralized providers and cloud systems that decide who can connect, how, and when. That shift created new single points of failure, breaking the original peer-to-peer design. Networks became harder to manage, slower to adapt, and more dependent on static infrastructure. ZeroTier was built to unbreak that model: to restore the simplicity of direct, secure, peer-to-peer connection across the modern internet. It was designed to overcome the barriers introduced by NAT, firewalls, and IPv4 exhaustion while maintaining the open, end-to-end principles that defined the early internet. By rebuilding these fundamentals on top of modern encryption and intelligent routing, ZeroTier makes it possible to connect devices anywhere in the world as if they were still part of one continuous network. The foundation: virtual ethernet everywhere ZeroTier creates a virtual ethernet network that runs on top of any existing IP network. Every device, server, or container you connect becomes part of a... SAN FRANCISCO — NOVEMBER 13, 2025 – Active Security, a defense contracting firm specializing in the design, implementation, and sustainment of C5ISR solutions, has announced it has entered into a strategic partnership with ZeroTier, one of the world’s leading software-defined networking and cybersecurity companies. The collaboration enables Active Security to offer secure, software-defined networking capabilities to federal, military, and enterprise clients requiring secure, real-time operations across distributed environments. The partnership was proven through several successful high-visibility event deployments where Active Security used ZeroTier's platform to securely stream low-latency, real-time HD video from operational technology sensors to global audiences across cellular, satellite, and fiber networks. “Traditional VPN and hardware-based solutions simply couldn’t meet the speed, flexibility, and security requirements our discerning clients demand,” said JP Rike, Chief Technology Officer at Active Security. “So, our technical team at Active Security engineered a purpose-built, software-defined network leveraging ZeroTier’s advanced platform. ”The solution addresses key challenges facing organizations with distributed operations through rapid deployment, 256-bit end-to-end encryption, universal connectivity across network types, and real-time performance for extremely mission-critical applications. Across multiple events and deployments, Active Security’s ZeroTier-based architecture has connected more than 50 OT devices across a variety of networks, delivering continuous, high-quality video in real time. The system handled surges in usage, seamlessly adapted to fluctuating network conditions, and provided a reliable backbone for mission-critical visibility. “We were pleased to be able to help Active Security deliver mission-critical video workflows with zero disruption,” said Angelo Rodriguez, SVP of Operations at ZeroTier. “Active Security’s... During our recent webinar, ZeroTier One Update for Enterprise, we highlighted some exciting work underway to enhance the ZeroTier platform. ZeroTier is already trusted by thousands of businesses and installed on millions of devices worldwide, and we’re continuing to make it even better. Two weeks ago, we opened up a key new platform element to our Early Access Program members to get a sneak peek. Today, we’re excited to announce the new Central for ZeroTier One is available for general release for all new users. This new release includes an enhanced and optimized UI and UX and also marks a big step forward in making network management faster, simpler, and more intuitive. Here’s what’s new in this release. Your network — simplified The new ZeroTier Central introduces a streamlined onboarding experience designed to help users get up and running quickly. The new sign-up flow consolidates account creation, GDPR acceptance, and Terms of Service agreement into one seamless process. Independent users who join are automatically set up as owners of their own organizations, giving them full control from the start, a new concept to ZeroTier. This provides them with full administrative control from day one, and establishes the basis for ReBAC (Relationship-Based Access Control), a model that manages permissions through the connections between users, resources, and roles. A new and improved UX With this release, ZeroTier Central introduces a complete redesign of the user interface and experience. Navigation has been simplified for faster, more seamless access to networks, devices, and settings.... SAN FRANCISCO — NOVEMBER 04, 2025 — ZeroTier, one of the world’s leading software-defined networking and cybersecurity companies, has announced today the launch of the next-generation update to its dashboard, ZeroTier Central, for its flagship platform, ZeroTier One. This release introduces a completely streamlined user interface, enhanced user experience, and a modernized backend architecture designed to make network management faster, simpler, and more powerful. “With this ZeroTier Central release, we’re redefining what intuitive, powerful network management can be,” said Andrew Gault, ZeroTier CEO. “As discussed during our May webinar, our vision is to empower our users with simple, secure, resilient network connections, anywhere, at scale. This release executes on that vision and makes network management faster, easier, and more intuitive than ever before. ” The new ZeroTier Central features a simplified onboarding flow that integrates account creation, GDPR acceptance, and Terms of Service into a single seamless process. Users joining independently are automatically provisioned as organization owners with full administrative control immediately. Navigation has been re-imagined for faster, more seamless access to networks, devices, and settings. Key actions are now prominently displayed, reducing clutter and cutting down the time it takes for users to manage their deployments. New performance tracking features capture core analytic and usage metrics, helping the support team continuously fine-tune the ZeroTier experience. Future updates will extend this functionality, offering users insight into how their networks perform, along with providing recommendations to optimize connectivity and efficiency. With the new release also comes the introduction of ZeroTier’s updated... This is the first installment of a multi-part blog series exploring how drones can stay connected, secure, and mission-ready with device-level networking. Drones have moved far beyond their origins as hobbyist gadgets. They inspect power lines, monitor crops, deliver packages, and assist in search and rescue missions. Governments and enterprises alike now rely on them to collect critical data and perform mission-critical tasks. And analysts project the global drone market will surpass $90 billion by 2030. That growth brings opportunity and complexity. Every new drone adds another device in the sky that must connect, communicate, and be secured. The problem? The networks drones depend on weren’t built for this kind of mobility. Wi-Fi coverage is fragmented. Cellular carriers impose strict NAT policies. Satellite links are expensive and variable. Yet reliable, low-latency communication is the foundation of flight safety and operational efficiency. Connectivity is a competitive advantage The next wave of drone innovation will not be about airframes or batteries. It will be about networks. Whether a company is flying a handful of inspection drones or managing a fleet of autonomous delivery vehicles, its ability to move data securely and predictably between aircraft, operators, and analytics systems defines its success. Consumer-grade networking tools do not scale to this challenge. Static IPs, manual port forwarding, and fragile VPN tunnels fail in real-world conditions. Operators need connections that simply work, wherever a drone flies and whatever network it traverses. Similarly, commercial-grade solutions were never built for mobility. They’re bulky, outdated, and designed for... During our last webinar, ZeroTier One Update for Enterprise, we highlighted some new projects and ongoing efforts to enhance the ZeroTier One platform already in use by thousands of businesses and installed on millions of devices worldwide. Today, we’re excited to announce the Early Access launch of our new Central for ZeroTier One update, which includes an enhanced and optimized UI and UX. This new release makes managing ZeroTier networks easier, faster, and more intuitive. Starting today, we’re pleased to announce that Early Access Program (EAP) and Customer Advisory Board (CAB) members will be receiving access to the new Central launch features on a rolling basis. Here are a few highlights of this release. A new beginning The new Central launch introduces a simplified onboarding experience designed to get users up and running quickly. Our streamlined signup flow guides ZeroTier users through creating an account, accepting GDPR cookies, and agreeing to the Terms of Service, all in one seamless experience. For those joining independently, the system automatically sets them up as owners of their own organization, giving them full control off the bat. We’ve also started rolling out some of our new ZeroTier visual branding with this Early Access Program (EAP) release. A greatly improved UX With this Central update, we’ve completely overhauled the UI. We’ve cleaned up navigation, making it tidier and more seamless for faster access to networks. The new layout reduces clutter, highlights key actions, and makes it easier to find what’s needed without extra clicks. New... In an Oct. 15 article on Forbes. com, contributor Jaime Catmull explored the “hidden tax” companies pay due to cyberattacks, not just in ransom payments or remediation costs, but in soaring insurance premiums, per-user licensing fees, and the operational drag of managing disparate VPN and network systems. The piece outlines how these costs quietly erode margins and hamper growth, even for firms that never make headlines for a breach. Catmull also noted how some companies are beginning to “opt out” of the traditional model of layered legacy VPNs and are rethinking how they build and manage a secure network infrastructure. Within that context, ZeroTier was highlighted as part of the emerging toolkit enterprises are using to avoid the “tax” of inefficient, costly legacy networking. By unifying connectivity with software-defined networks, ZeroTier enables organizations to reduce complexity, lower licensing, and hardware refresh cycles, and avoid the hidden drag of fragmented access architectures. We’re proud to be featured in this conversation as one of the tools leading the charge in helping enterprises take control of connectivity and cost. Check out the full article here: Forbes – The Hidden Tax A Company Pays To Hackers — And How Some Are Opting Out. Casinos and gaming operations never stop, and neither should your network. From gaming floors packed with connected machines to remote players coming in via the cloud, properties managing players, guests, and their data need reliable connectivity. With a software-defined networking (SDN) platform, casino and resort owners can easily deploy secure networks in minutes. This keeps operations running seamlessly, no matter how complex the underlying infrastructure is. Furthermore, security, regardless of physical, digital, or both, is paramount in casino operations especially for sensitive data in transit (DITS). The same technology trusted by video gamers for years now powers the next generation of casino networks. As hybrid play or cross-platform play expands, software-defined networks can improve and secure operations. Here are four key ways: Stay online, no matter what With a bustling casino floor, downtime isn’t an option. Whether it’s a network outage, ISP issue, or system overload, a SDN platform’s multipath routing and seamless failover capabilities keep operations connected and running. If one connection drops, traffic automatically reroutes in milliseconds, so games stay online, guests stay happy, and operations keep running. For remote or multiplayer gaming types, traffic can also be optimized for the lowest latency routing or even low-bandwidth conditions for mobile-first games. Simplify multi-property networking Multiple properties shouldn’t mean multiple headaches. ZeroTier connects systems across any cloud, data center, or property into one cohesive network. And it does all this without complex configurations or additional hardware, meaning faster setups and fewer vendor dependencies. Manage apps, devices, and services across... Metropolis needed a way to remotely manage a massive number of devices within parking facilities, all while securely transmitting and receiving data in difficult geographic locations. A (Parking) Lot of Options Metropolis, a parking management company, needed a way to remotely manage a massive number of devices within parking facilities, all while securely transmitting and receiving data in difficult geographic locations. Download the Case Study Download the Case Study The Challenge Too Many Devices, Too Little Control Metropolis faced a daunting technical challenge. As it expanded into parking garages and other facilities across the U. S. , the team needed to manage and connect a rapidly growing fleet of remote cameras, routers, and sensors, many installed in locations they didn’t own and far from on-site technicians. Network management was slow, performance lagged, and security concerns mounted. The Solution Zero-Touch Networking, with Maximum Impact Metropolis found its answer with ZeroTier. The platform provided the performance and scalability Metropolis needed without complex configurations. It provided the flexibility to fully automate deployments, leading to a "zero-touch provisioning model" that enabled the company to go from nothing to a fully operational, revenue-collecting parking garage in just two hours. “My only regret is that I didn’t go down that path earlier — much earlier. ” — Todd Shipway, Head of Technical Operations at Metropolis Download the Full Case Study Interested in learning how ZeroTier can help you achieve a zero-touch deployment model and streamline your network management? Download the full Metropolis case study to get all the details. Download Now Download Now Forest Rock, a UK-based IoT solutions provider specializing in smart buildings, needed real-time, secure visibility into sensors monitoring energy usage across their customers' facilities. Building a Remote Solution Forest Rock, a UK-based IoT solutions provider specializing in smart buildings, needed real-time, secure visibility into sensors monitoring energy usage across their customers' facilities. Download the Case Study Download the Case Study The Challenge Tracking Energy Usage without Real-Time Insight Forest Rock struggled to maintain real-time visibility across hundreds of customer facilities. Without insight into on-site sensors and building systems, problems could escalate quickly, risking inefficiency and higher energy costs. They needed a secure, scalable way to monitor and manage operations remotely to keep buildings running smoothly. The Solution From Days to Mere Minutes ZeroTier has dramatically improved response times for Forest Rock. The time to triage and resolve an issue has been reduced from five days to mere minutes. This has allowed the company to improve customer service, as its clients can log in from anywhere in the world to view building statistics. “ unlocked doors for what we were capable of as a company. ” — Gareth Shirley, Forest Rock’s Sales and Operations Manager Download the Full Case Study Want to learn how Forest Rock leverages ZeroTier to provide secure and cost-effective remote monitoring solutions? Download the full case study to get all the details. Download Now Download Now Picture this: It’s the middle of August. The sun’s out, temps are pushing 90 degrees, and the office AC is the only thing standing between your tenants and a total summer meltdown. What’s the last thing you need? A building system going offline with no quick way to fix it. For Forest Rock, a UK-based IoT solutions provider focused on smart buildings, this is a would-be nightmare. With hundreds of sites across the UK and Ireland, Forest Rock knows that during the dog days of summer, there’s no time for tech delays at the many buildings it manages. That’s why Forest Rock turned to ZeroTier to provide fast, secure, and remote access to their entire network of smart devices, no matter where they’re installed. Summer-smart, not summer-stressed Before ZeroTier, Forest Rock’s team often had to wrestle with unreliable 4G public IPs or traditional VPNs that were slow and complex to set up. Diagnosing issues remotely could take up to five days, not exactly ideal when your client’s air conditioning just quit during a heatwave. Now? The company deploys ZeroTier’s secure, peer-to-peer network to access systems instantly, from their laptops, wherever they are. Setup takes minutes, and there’s no need for port forwarding or on-site visits. Forest Rock’s Gareth Shirley described it perfectly: “We can just load up a laptop, log in, and diagnose,” said Shirley, sales and operations manager for Forest Rock. Cool results (literally and financially) The results have been impressive. Since adopting ZeroTier, Forest Rock has slashed triage... Imagine you're lounging on a beach somewhere, margarita in hand, disconnected from Slack notifications when your phone buzzes: “Urgent: Production is down. A memory corruption bug in our vendor’s software crashed the entire system, and we need you online now. ” There goes your vacation. Don’t let memory bugs ruin your summer plans. Select vendors who use memory-safe code to prevent crashes and reduce security vulnerabilities. What is memory-safe code? Memory-safe code automatically stops your program from accessing data it shouldn't, using old invalid data, or executing code that was never meant to run. Languages like Rust, Go, Python, Java and C# do this checking for you automatically. Traditional C/C++ code is like leaving your house keys scattered around your coffee table. Memory-safe languages are like having a smart home system that puts everything exactly where it belongs. As ZeroTier's founder Adam Ierymenko explained in an article on Builtin. com, these memory vulnerabilities happen constantly, even though we know how to prevent them. Microsoft revealed 90 vulnerabilities in August 2024 alone, including one that could have given attackers full control of any Windows system. Remember CrowdStrike crashing millions of machines and costing Fortune 500 companies $5. 4 billion? That was a memory bug in C/C++ code. Your summer memory-safe code checklist Here's where things get urgent. AI is getting scary good at finding bugs in code. What used to take security researchers weeks, AI can now do in minutes. If your system uses memory-unsafe languages, you're leaving the door wide... It’s summer. You should be thinking about sunscreen and spritzers, not who accidentally got admin rights to your entire network. That’s where ZeroTier’s new support for ReBAC (Relationship-Based Access Control) comes in, making things a whole lot smoother for your systems and your sanity while on PTO. Originally announced during our spring platform updates webinar, ReBAC controls let you hand out permissions based on real-world relationships, like “this person manages that team” “or “this is the manager for a specific geographic region” or (maybe most importantly) “only folks in IT are allowed to touch this. ” If you’re used to RBAC (Role-Based Access Control), you know the drill: you assign roles like “admin” or “user” that have a static set of permissions and hope they still make sense three months from now. RBAC is straightforward, but it’s also rigid. It doesn’t consider relationships between people, teams, or devices. So, when your company grows or your projects shift, access control becomes a game of catch-up. And that’s the last thing you want to deal with while you’re poolside. With ZeroTier’s new ReBAC features, you have a more flexible, contextual way of managing access. Instead of just saying who someone is, ReBAC lets you define how they relate to others or to a resource. For example, you can say, “Only team leads can approve new device joins,” or “Only people on the West Coast engineering team can access this network. ” It’s smarter, cleaner, and doesn’t require you to rewrite your whole... This summer, making money while laying on the beach has never been easier. ZeroTier recently teamed up with PartnerStack to power its new Partner Program, which lets tech providers earn recurring revenue by referring, reselling, or promoting ZeroTier’s secure networking platform. And with PartnerStack running behind the scenes, all the backend business is handled. That means you can enjoy your mai tai or mocktail in peace, all while providing next-generation connectivity for your customers. Why this matters for your summer hustle ZeroTier makes software-defined networking a breeze: secure, scalable, and much easier than dealing with VPN headaches. PartnerStack handles the backend magic: onboarding, tracking referrals, and firing off commission payments. That means you can earn while lounging poolside, with no network admin degree required. Here are steps to get your ZeroTier Partner Program instance up and running: Add ZeroTier to your travel toolkit. Getting your ZeroTier Partner Program up and running is as simple as setting up your tiers, commissions, and onboarding flows in PartnerStack, then connecting it to your systems for tracking and payouts. Once it’s live, you can start selling, referring, sharing resources, and scaling with ease. Promote with real stories. Want to grow your user base? Invite folks to check out ZeroTier. Mention how you stay securely connected while camping in Yosemite or surfing in San Diego thanks to ZeroTier. Share how ZeroTier replaced your bulky VPN, letting you troubleshoot clients or deploy networks from wherever, whenever. Sit back and let the earnings roll in. When someone... Tired of dealing with clunky, overbuilt networking solutions? ZeroTier recently dropped its latest update, and it’s about to make networking exponentially easier. Like, actually-take-a-real-vacation-without-your-phone-buzzing-every-five-minutes easier. Launched during a live updates webinar, which you can rewatch here, ZeroTier founder Adam Ierymenko, CEO Andrew Gault, and SVP of Global Operations Angelo Rodriguez toured attendees through the platform updates, which included new ReBAC features, a fresh UI, and more. Here are a few takeaways from the updates webinar highlighting how ZeroTier can help you enjoy your summer vacation and leave your laptop behind. Access controls that don’t suck. Traditional role-based access control (RBAC) is like giving someone keys to every door in a building when they only need access to one office. Relationship-based access control, or ReBAC, is now available on the ZeroTier platform and fixes this problem by giving permissions in context. A UI that empowers its users. Traditional RBAC assigns broad roles like “network admin” with sweeping permissions across all resources. ReBAC assigns contextual permissions like “admin on domain 2,” limiting access to only the specific resources required for that role. This approach scales effectively across large deployments without creating a complex web of overlapping permissions that can plague enterprise access control systems. One major part of this latest update is the fully redesign UX. ZeroTier’s new domain-based organization lets you group networks logically instead of drowning in an endless list. More importantly? Your junior admin can actually navigate the UI while you sip mojitos poolside. Devices take center stage. Your... June’s Google Cloud Platform outage, and the resulting disruption to downstream infrastructure providers, was another reminder of how fragile the internet can be. Sites went dark, services dropped, and many frustrated users spammed the reload button on Spotify. But devices running on ZeroTier? They stayed connected. That’s because ZeroTier is built for situations like this. And it’s the reason you don’t have to stress about your network going down while you’re sipping margaritas on the beaches of Mexico this summer. Your devices stay connected, no matter where you are and what goes on with the internet. There’s been no shortage of outages lately. From backbone disruptions to DNS issues, these incidents can quickly take down apps, servers, and even critical infrastructure. But users who’ve moved to a network overlay solution, like ZeroTier, have seen their critical services continue to run uninterrupted, even when parts of the wider internet hit a snag. How can you keep things connected? ZeroTier creates a virtual network that operates over the existing internet, but with added resilience woven in. ZeroTier uses peer-to-peer connections and decentralized control. Devices don’t have to rely on centralized servers that could go down during an outage. Instead, they build direct, encrypted tunnels to each other. As a result, your applications don't depend on any single system deployed in the cloud: if they have an internet connection, their ZeroTier networks keep running. There’s no need to manually change providers, wait for DNS/service discovery updates to propagate, or worry about firewall rules... In late May, ZeroTier was featured on the 100th episode of the “Great Things with Great Tech” podcast. During the hour-long episode, ZeroTier’s founder Adam Ierymenko and CEO Andrew Gault sat down with podcast host Anthony Spiteri to discuss ZeroTier’s unique beginnings and how it’s redefining connectivity for a cloud-driven, edge-connected world. Looking for a few key takeaways? Check them out and watch a recording of the full episode below. https://youtu. be/VQFN3ldspXU? si=Ewko0roWteKCw233 From open source roots to global impact Adam Ierymenko’s journey to developing ZeroTier began with early programming on a Commodore 64 and a career marked by frustration with the complexity and rigidity of enterprise networking. Inspired by open-source ideals and a desire to make networking simpler, Ierymenko built a solution that would let people connect devices effortlessly, no matter where they are. That idea turned into ZeroTier in 2011 — a platform that blends the best parts of VPNand SDN into one seamless, ready-to-use solution. It’s this focus on simplicity and flexibility that ZeroTier customers benefit from today, whether they’re setting up remote access for a small team or managing thousands of devices across the globe. Use cases: from gaming to industrial automation ZeroTier’s flexibility has led to adoption across a wide range of industries and applications. Gamers use it to connect rigs across continents, while industrial operators rely on it to manage everything from oil wells to drones in remote or hostile environments. It’s the kind of tool that just works — whether you’re looking for... SAN FRANCISCO, CALIFORNIA, JUNE 12, 2025 – ZeroTier, one of the world’s leading software-defined networking companies, has announced today that partner ecosystem platform, PartnerStack, will provide the backend of ZeroTier’s recently announced Partner Program. The new Partner Program is designed to empower technology providers to deliver modern networking solutions to customers. PartnerStack’s platform helps B2B SaaS companies grow by managing and scaling their partner programs — such as affiliates, referrals, and resellers — all in one place. It automates everything from onboarding and tracking to commission payouts, making it easier for businesses to expand through partnerships. “ZeroTier’s partner motion is entering a new phase, and we’re proud to be the platform supporting that scale,” said Luke Swanek, Co-founder of PartnerStack. “We design every feature with the partner experience in mind, from seamless onboarding to scalable payouts, to empower SaaS companies, VARs, MSPs and integrators to grow faster through partnerships. We are excited to support ZeroTier's next phase of growth. "ZeroTier’s recently announced Partner Program offers a range of scalable connectivity options built on the ZeroTier platform, including the ability to drive recurring revenue, differentiate offerings with software-defined networking, and dedicated partner support. As a part of the Partner Program, PartnerStack will help empower partners, like VARs, MSPs, and integrators, to deliver secure, scalable networking solutions while streamlining program operations and accelerating consistent revenue. “At ZeroTier, we believe our partners are the force multipliers of our mission,” said Angelo Rodriguez, ZeroTier’s Senior Vice President of Global Operations. “PartnerStack helps us turn... If you’re an admin, you spend a lot of time trying to get people the access they need, without putting everything else at risk. Too much access means security gaps. Too little means broken workflows and a flood of support tickets. Somewhere in the middle is the sweet spot: giving people just enough access to do their job. That’s the promise of access control. And for a while, RBAC, or Role-Based Access Control, looked like the answer. Assign roles like "admin" or "viewer," and let the system do the rest. But in practice, RBAC creates new problems. The trouble with RBAC RBAC works by assigning users to predefined roles, each with a fixed set of permissions. It’s tidy in theory. In reality, it breaks down as soon as you try to model a real-world organization. You either end up with too few roles, forcing people to share broad access they don’t actually need, or you spin up dozens of custom roles to handle edge cases, some of which may be necessary today, but will change tomorrow. That’s a recipe for confusion, inconsistency, and role sprawl. Want a contractor to see just one customer’s network? That’s a new role. Need to let someone view logs but not change anything? Another role. Month after month, year after year, it’s access control by duct tape, and it gets harder to manage with every new team, region, or project. How ReBAC changes the model ReBAC, or Relationship-Based Access Control, starts with a different assumption:... https://youtu. be/4YDmdXyCvZ4 Read the transcript Andrew GaultSo Hello, everyone! Thank you for joining us today for a look at what’s new and what’s next for ZeroTier One for Enterprise. I’m Andrew Galt, CEO, here at ZeroTier. I joined last year and I work closely with our founder Adam. Every single day. My joining has really freed up Adam to focus on our roadmap and push forward a lot of what we’re going to show you today. And of course, some very exciting announcements. Later in the yearI’m joined today by Lennon and Angelo. Gentlemen, would you like to introduce yourselves. Lennon Day-ReynoldsSure. Hi! I’m Lennon Day-Reynolds. I head up solutions architecture here at ZeroTier. I joined a little over 2 years ago, and I’ve been working on the engineering team since then, so definitely been right in the middle of a lot of what you’re going to see today. And I’m really excited for both. Show it to you. And then, in the coming months, you know, maybe work hand in hand with a number of you to sort of adopt and explore all these new improvements. So, thanks. Angelo RodriguezHey, everyone Angelo Rodriguez. I’m the SVP of Global Operations. I’ve been with the company for a little over 2 years. Of course, work closely with Andrew and Lennon. I oversee areas like customer success technical support Channel partnerships. And I do a lot of work with our self-serve products and other areas of ZeroTier operations. But really, really excited... SAN FRANCISCO, CALIFORNIA, APRIL 22, 2025 — ZeroTier, one of the world’s leading software-defined networking companies, has announced today the official launch of its Partner Program and initial participants. This new program is designed to empower channel partners, resellers, integrators, and other technology providers to deliver modern networking solutions to their customers. It offers a range of scalable connectivity options built on the ZeroTier platform, including the ability to drive recurring revenue, differentiate offerings with software-defined networking, and dedicated partner support. “ZeroTier is redefining how enterprises and government entities connect by offering a next-generation networking platform while simultaneously simplifying security within modern environments,” said Andrew Gault, ZeroTier CEO. “Now, through the launch of our Partner Program, we’re changing the game in terms of gaining access to ZeroTier. Companies across industries can integrate ZeroTier’s seamless networking into their solutions, providing their customers with effortless, secure connectivity. ”With its newly launched Partner Program, ZeroTier aims to collaborate with technology distribution companies across industries. Initial partners include TD SYNNEX, leading global IT distributor and solutions aggregator, which recently joined ZeroTier’s Partner Program to enhance its downstream partners’ success. MikroTik, Teltonika, and OPNsense are other key technology partners also included in the program, as well as: Channel Partners, including leading IT providers that help businesses set up and manage their tech infrastructure, including cloud services, cybersecurity, and networking. Value-Added Resellers (VARs) who can differentiate their portfolio with a secure, flexible networking solution. Systems Integrators (SIs) and Integrated Solution Partners who can simplify complex deployments... Note: This is the second installment of a multi-part blog series tackling real-life networking challenges in enterprise environments. Segmentation is one of the most common and effective ways for companies to improve their network security in today’s digital landscape. But what is network segmentation? In its most basic form, network segmentation is dividing a network into isolated sections with access controls. Instead of letting everything communicate freely, segmentation applies predefined rules to restrict traffic flow between different devices, users, or sections of the network. This not only enhances security, but it also improves network performance by reducing congestion. There are several ways to achieve segmentation — including physical segmentation, or using separate hardware like switches and routers to create isolated networks; logical segmentation, implementing VLANs and subnetting to separate traffic within the same physical infrastructure; and microsegmentation, a software-defined approach that restricts access based on roles or workloads. But why does network segmentation matter? Enterprises handle massive amounts of sensitive data and must protect critical systems for unauthorized access. Without segmentation, an attacker could easily move laterally across the entire network, exposing critical systems. Aside from outside attacks, by using segmentation, an enterprise also limits insider threats. Employees only access what they need, reducing accidental or intentional misuse. Segmentation also ensures compliance. Many regulations — such PCI-DSS and HIPAA — require strong access controls. There are many ways an enterprise might use network segmentation. Here are a few examples: An IoT provider that offers smart building automation for multiple clients... SAN FRANCISCO, CALIFORNIA, MARCH 3, 2025 – ZeroTier, one of the world’s leading software-defined network companies, has announced today a strategic partnership with Channel Tools, a leader in driving new technology distribution and integration solutions, to expand the reach of its innovative virtual networking platform. This collaboration aims to provide enterprises with seamless, secure, and scalable connectivity solutions, enhancing both security and operational efficiency across numerous industries. This new partnership will also offer access to ZeroTier’s platform and sub-products through the expansive network of Channel Tools and will be available via TD Synnex. ZeroTier’s platform enables the creation of secure cross-connectivity of devices and applications bringing them into seamless, segmentable and fully managed network, regardless of their physical locations or cloud type. In addition the platform offers enterprise-grade security and controls. ZeroTier’s software-defined solution eliminates the need for complex hardware setups, offering a streamlined and secure approach to network management. Based in the UK, Channel Tools has been delivering sales and marketing to complement enterprises’ go-to-marketing teams for the last 15 years. Channel Partnerships, a division of Channel Tools, works with some of the world’s leading technology sales channels of technology companies who are looking to reach a wider audience through established distribution channels. Kewal Gupta, CEO of Channel Tools, expressed his enthusiasm about the partnership: “Collaborating with ZeroTier allows us to offer our clients a cutting-edge networking solution that simplifies connectivity and greatly enhances security,” Gupta said. “ZeroTier’s platform aligns perfectly with our mission to deliver innovation in an... This is the first installment of a multi-part blog series tackling real-life networking challenges in enterprise environments. Networking in the modern enterprise environment is evolving. Storing data in multiple clouds is now a necessity, rather than an option. Today, 80% of enterprises are using multiple-cloud environments — and for good reason. Some aim to optimize costs, while others focus on boosting reliability. In some cases, companies inherit a multi-cloud setup through mergers, acquisitions, or data residency requirements. But what exactly is a multi-cloud environment? Simply put, it’s a modern approach to managing data and company assets across multiple cloud providers, such as AWS, Google Cloud, and Azure. There are many ways an enterprise might use a multi-cloud environment. Here are a few examples: A smart building IoT company that manages automated systems across multiple properties might have the following multi-cloud structure: AWS IoT Greengrass to control HVAC, lighting, and security systems locally. Google Cloud AI to analyze energy usage and optimize efficiency. Microsoft Azure Digital Twins to create virtual models of buildings for real-time monitoring and predictive maintenance. An auto manufacturer might utilize a multi-cloud environment to streamline production, manage vehicle connectivity and supply chain: AWS IoT Core to monitor and manage connected vehicle telemetry. Google Cloud storage for securely archiving design and manufacturing data. Microsoft Azure DevOps to coordinate software updates and deployment across their global production facilities. A hospital’s multi-cloud environment might be used to enhance patient care, data security, and operational efficiency and could follow a similar... At ZeroTier, we’re committed to continuously improving our infrastructure to provide seamless and reliable connectivity for all users. As our global customer base grows, we’ve been upgrading our root servers to ensure they can handle increased traffic efficiently. While these upgrades are designed to enhance long-term performance, a small group of customers recently experienced temporary slowdowns or disruptions, particularly for devices relying on relays. Upgrades & Connectivity Issues We recently implemented infrastructure upgrades to our root servers, which play a crucial role in facilitating device discovery and connectivity. These servers help establish direct peer-to-peer connections and serve as temporary relays when direct connections are not possible. During the upgrade process, some users experienced brief slowdowns or disruptions, particularly those relying on relays for connectivity. Our core engineering team has been focused on improving the reliability and scalability of these systems. We’ve already deployed upgraded root servers in several regions, with full upgrades expected to be completed shortly. Additionally, we’ve enhanced our monitoring and alerting systems to proactively identify and resolve potential issues before they affect users. For customers with particularly latency-sensitive use cases, we’re also improving support for self-hosting roots and relays, allowing for even greater control and optimization of network performance. How You Can Optimize Your Experience For the best connectivity experience, we recommend reviewing our router configuration guides and documentation on using ZeroTier behind corporate firewalls. These resources can help you reduce reliance on relays and optimize your network for more direct peer-to-peer connections. Need Assistance? We recognize... SAN FRANCISCO, CALIFORNIA, FEBRUARY 4, 2025 — ZeroTier, one of the world’s top software-defined network companies, has announced the opening of its European office in Utrecht, The Netherlands — a strategic move that brings the secure network platform provider closer to its European customers where the company has seen significant growth over the last 12 months from individual users to enterprise-level customers. “We are excited to officially announce the opening of our new European office in The Netherlands,” said Andrew Gault, ZeroTier CEO. “This new office will allow us to both supplement our development efforts and better serve our growing EU customer-base, demonstrating our confidence in the pan-EMEA market. ”In addition to an expanded development and sales presence, ZeroTier is leveraging tech industry veterans Janjaap Bos and Alexander Colenbrander to head up the new European office. Bos has an extensive background in cloud networking as the founder and CEO of Capitar IT Group, a leader in cloud-agnostic hosting and networking solutions. At Capitar, Bos has worked to help scale and grow the company to be a leader in IT support and managed services. Bos has also served as an advisor to the ZeroTier board. Colenbrander has extensive experience working with scaling early stage companies, having co-founded multiple successful start-ups including Claimingo and Loft. He has also played a critical role expanding the footprint of global tech VC firm Antler. “I am very excited to be joining the ZeroTier team in this capacity,” Bos said. “As the number of individual users... Traditional networking solutions were not built for the explosive growth, multi-continental reach and the cloud-based capabilities typical of today’s most successful enterprises. Designed for static setups and cloudless internet configurations, the systems of yesteryear are heavily dependent on expensive hardware. This makes them difficult to oversee and expensive to update as organizations continue to expand their scope. As network management grows increasingly complex, organizations of all sizes are seeking a streamlined device-connection strategy that maintains both security and performance. While SD-WAN products have emerged as a solution to the limitations of hardware-centric approaches, they fall short in several key areas. It's essential for enterprises that have implemented, or are considering SD-WAN, to understand the cost-effective and accessible alternatives currently available in the market. But let’s start with a look into SD-WAN. What Is SD-WAN? Short for “software-defined wide area network,” SD-WAN is a network structure that uses a software-based solution to connect a number of smaller, independently-defined networks into a supernetwork, even to the level of large enterprises. SD-WAN helps companies connect their offices and data centers over the internet more efficiently and securely. Modern SD-WAN Use Cases — and Why You Likely Need a Different Platform  SD-WANs and other software-defined device connectivity systems are becoming increasingly popular. In 2022, nearly 95% of organizations surveyed by IDC have deployed SD-WAN or planned to deploy SD-WAN technology within the next 2 months. A few of the driving forces behind this statistic are: A remote workforce. An SD-WAN allows remote workers to securely... Today’s business functions depend on a reliable and secure internet connection. But, as technology progresses and our networks extend their reach across the globe, security can become increasingly complicated. Establishing a scalable, lightweight security solution that maintains connectivity while keeping important data protected is imperative. In the past, many users have relied on a VPN to help them do just this. But, what is a VPN? A VPN, or virtual private network, is an application that lets local devices securely and privately connect to resources over the public internet. When using a VPN, any data sent from a device, such as an IP address, is routed through a remote server on its way to the end destination. The data is encrypted until it reaches the server, at which point it’s unencrypted but now labeled with the routing server’s IP address instead of the individual user’s own. This protects both the identity and the location of the original device, as well as whatever other information they might be sending via the public internet. The Pros & Cons of VPNs Like any modern networking platform, VPNs have advantages and drawbacks. While VPNs protect your privacy and your data integrity, they can also slow you down. Because data is routed through at least one external server, as well as being encrypted along the way, the speed of internet processes can be slowed down significantly. This can disrupt connectivity and some basic functions, like streaming or video conferencing. A 2024 VPN Risk Report found that 96%... Going Faster with Multi-Core Performance We're excited to announce the launch of multi-threading for ZeroTier. This new feature is designed to boost performance on power-efficient devices with embedded CPUs, such as multi-core routers, DVR machines used for video security, and Raspberry Pi devices. Previously, ZeroTier only used a single core on these multi-core devices. This could lead to slower data transfers and issues with video streaming, especially on devices with lower clock-speed cores. With the introduction of multi-threading, customers can see up to a 2x increase in performance on the same hardware. Multi-threading makes it easier to implement ZeroTier across several use cases including video monitoring, SD-WAN, and more. Use Cases and Business Benefits This multi-threading enhancement is currently available for Linux-based devices and offers substantial benefits across several key use cases. Organizations in industrial IoT, smart buildings, security, and automotive can use this feature to improve the performance of their ZeroTier deployments, without upgrading hardware. For example, network administrators and security teams who had trouble with video streaming because of low frame rates or connection issues will now see clearer and more reliable video. Plus, data transfers on ARM-based devices, like those used in autonomous vehicles or industrial robots, will be faster and more efficient. Adopting the multi-threading feature offers several specific benefits: Improved Performance: Experience clearer video streams and faster file transfers, even on resource-constrained devices. Cost Savings: Continue using your existing hardware without worrying about bandwidth limitations or the need for costly upgrades. For new IoT deployments,... A healthy network makes up the nervous system of any modern organization that leverages IoT technology. Fast, safe, and reliable connections between devices empowers the many branches of a thriving business to stay in step with one another and keep moving forward. As technology continues to advance, maintaining these networks can become more complex, and often more expensive. But protecting, monitoring, and controlling the flow of your data is now more important than ever before. A modern approach to device connectivity becomes critical for companies who want to stay ahead of the curve. So let’s discuss a few steps you can take to bring your connection strategy to the front-line of IoT networking. What are we modernizing, anyway? Even now, many IoT networks are restricted by limited provider scopes. Device connection solutions that are optimized for individual users tend to be prohibitively expensive for growing organizations. These typically charge a per-person use rate, rather than per-device. This means that enterprise or start-up organizations with a large or expanding number of devices on their network can expect to pay a premium for this kind of service. And those that have been designed for industrial application are often married to that same provider’s in-house architecture. Implementing this solution could mean undertaking a total tech-overhaul if the business didn’t already have the right hardware in place. Even with a compatible tech stack, scaling up device connectivity might mean creating a makeshift, overly-complex network to achieve the desired level of unification. This approach is... As your organization steps more fully into the digital age, access to secure and reliable networking that does what you need it to do (and nothing you don’t) becomes increasingly critical. Whether you’re working to better protect customer data, speedup communications between globally-distributed devices, or get all your remote employees in the same virtual room, a good connection is the thing that’s going to help you do it. So let’s talk about how you can build your organization’s ideal networking solution, today. What’s the problem? In the past, network admins had to take a ‘pick-two’ approach to their device connectivity. Networks could be safe and reliable, reliable and fast, or fast and secure, but not all three. And scalability was a thing that you would have to invent for your own organization, often at great expense. That’s because the device-networking solutions commonly available to mid-market and enterprise businesses were not designed for the modern landscape. Built initially for cloudless, site-bound networks, legacy infrastructure locks you into rigid protocols which are often dependent on the provider’s native hardware. This makes system maintenance and management prohibitively expensive. It also can create a performance bottleneck as your technicians struggle to create communication pathways between disparate devices over fragmented networks. The added complexity from these cobbled-together solutions then increases the attack surface of your network, leaving gaps for bad actors to Finally, when dealing with more than one network, you’re usually not the one in control. Devices at different locations may be accessing the... The next big thing in network technology is always right around the corner. Many legacy tools for global networking no longer offer the efficient, reliable, and secure connectivity they once did. The quality of their product may be the same, but the landscape has changed: growth-oriented organizations can no longer afford the costly and hardware-heavy systems that were designed for the smaller and more static businesses of the past. The task now is to create a lightweight product that is scalable, reliable, fast, and secure – and that’s what ZeroTier did. A better way to network ZeroTier is a software-defined network overlay that simplifies the complex issue of organizational connectivity. The solution can be both deployed and managed from anywhere. It requires no manual setup, and no overly-complicated or expensive tech stack in order to make it work. Once deployed, ZeroTier’s virtual ethernet technology creates a direct connection between all devices on a defined network, as though they were all on the same site. End-to-end encryption and cryptographic IDs ensure top-level security for globally-distributed devices, without sacrificing speed or reliability. Who is ZeroTier for? ZeroTier offers advantages to teams of any size, across diverse industries. From construction and manufacturing to retail and tech companies, ZeroTier’s flexible application can be customized to meet the precise and industry-specific needs of most enterprise organizations. ZeroTier advantages Here are some of the business benefits offered by the ZeroTier solution. Scalability. New devices are easily incorporated into your network, without the need for manual set-up... https://youtu. be/LZJ2BGAnnHgLegacy network infrastructure fails to meet the demands of modern business. It's full of fragmented networks, complex configurations, and unreliable connections. ZeroTier offers a better way. We provide a secure, software-defined network overlay that lets you create global private networks instantly. You can connect all your devices as if they were in the same office, regardless of their physical locationSkip the hardware and manual setup. Our self-healing network bridges multiple networks and firewalls for seamless connectivity. A lightweight agent is easy to install on nearly any device, and the central dashboard gives you a comprehensive view. With developer-friendly webhooks and APIs, ZeroTier is the smarter way to ensure your business stays connected. Sign up for our newsletter Don't miss an update. Sign up to receive occasional networking content and news. By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it's awesome! Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. Your networking solution shouldn’t limit your company’s ability to expand. Instead, global networking should drive your company’s growth and help you to do something extraordinary – say, build your IoT deployment from 5,000 devices to 100,000+. That’s what our partner Metropolis is doing as they use ZeroTier to rapidly expand their IoT infrastructure. Meet Metropolis Metropolis is in the business of delivering a better driving experience. They don’t manufacture cars or build roads. Instead, they aim to improve your experience in day-to-day locales like parking garages and similar facilities. We’ve all experienced how the payment system at most parking structures can create a frustrating bottle neck for people who just want to park and get on with their days. Let’s say you’re in a parking garage – first there’s the hard-to-reach button that spits out your parking ticket. If the machine breaks or runs out of paper, you’ll need to call the guard to let you through, adding even more time to your parking experience. But let’s just assume everything works; you take your ticket and move on. Now, maybe you remember to bring it with you. Paying on your way out should be quick and easy. But maybe you left your ticket in your cup holder, and now you have to trek back and forth between your car and the payment kiosk before you can leave. Or, if your ticket is gone completely, you might be forced to pay for a day’s worth of parking instead of the hour... “ZeroTier unlocked doors for what we were capable of as a company... ” Gareth Shirley, sales and operations manager at Forest Rock, said. This is what the ZeroTier solution was built for. It is our goal to provide a similar experience to all our users, from hyper-local startups, to global enterprises. Or, as the case may be, UK-based smart-building management companies. Meet Forest Rock Forest Rock is an organization at the leading edge of IoT technology and smart building infrastructure in Ireland and the United Kingdom. The company’s primary mission involves “... connecting people, places, and things... ” to make industry-scale building management easier and more sustainable. “Our solutions help customers better manage buildings and therefore reduce energy consumption and associated expenses,” Gareth said. How do they do it? Forest Rock supports commercial, residential, educational, and other large-scale human-occupied buildings and building networks. By engaging the most up-to-date hardware and software available, the company is able to better monitor and manage internal building systems. This includes overall building functions, as well as energy usage, and cybersecurity. Forest Rock’s N4EM (N4 Energy Manager) leveraged machine learning to help facilities track and improve their building management practices over time. This enables Forest Rock’s network of clients to bolster efficiency, save money, and improve their profits over the long term. Forest Rock offers top IoT technology to their building clients, but until they met ZeroTier, the company struggled to make their networking dreams a reality. The (seemingly) insurmountable problem Clear visibility into building... The technology and networking landscape has changed a lot since then. One of the biggest changes has been the approach to security. The original paper describing TCP/IP was published 50 years ago this May. The technology and networking landscape has changed a lot since then. One of the biggest changes has been the approach to security. Today’s Internet is so defined by security concerns that it can be difficult to imagine a world where global networking is simple and safe. There are whole conferences dedicated to Internet security and a multi-billion dollar industry committed to foiling the attempts of bad actors. But if we look far enough back, the first iterations of the Internet were built on trust. In the beginning, every device on the Internet could talk to every other Internet-connected device. Most organizations were primarily interested in mutual access to resources. College campuses and research labs shared specialized instruments and data sets. The postal service and other agencies created international communications channels. Put another way, the Internet was developed and used by a mutually-known and trusted community. That trust created a beautiful thing. Communities of known good actors could easily access shared resources and direct peer to peer connections made the flow of data seamless. Innovative new tools and applications proliferated, often without any central coordination or planning. In the current environment where “zero trust” is the ultimate goal, those long-ago days may seem rose-tinted and impossible to replicate. But ZeroTier was founded to “unbreak the Internet”, and we believe that global organizations can have the benefits of a high-trust Internet, without sacrificing security. Let’s take a quick look back... Now introducing Webhooks. Automatically receive ZeroTier network notifications. We have a special treat for all of the network administrators out there for Halloween this year: Webhooks! Now our paid customers can receive notifications from ZeroTier Central in the form of a webhook for many actions performed on our UI and/or API so you can log or react to things happening in your ZeroTier networks. Actions that will call out to webhooks include: A new machine joins a network An administrator authorizes or deauthorizes a network member An administrator changes the network configuration An administrator changes a member configuration An administrator creates or deletes a network An administrator deletes a member A new user is invited to, removed from, or accepts/rejects an invite to join your organization. A user performs an SSO login to your network This new feature requires some initial work on your end to set up an endpoint to receive hooks from us. Read on for more details. Configuring Webhooks There’s a new spot for paid accounts on the account page to configure webhooks: The Endpoint URL field is the URL to your hook receiver where we will send the requests. This URL must be accessible from the internet and should preferably be secured with https. The description is optional. Event Types lets you select which event(s) you want to receive callbacks for. You can also configure multiple webhook receivers, each with their own list of events to receive. Standing Up a Webhook Receiver If you just want to test things out and see how they... IIoT, or the Industrial Internet of Things, is a revolutionary technology steadily reshaping various industrial sectors from transportation to manufacturing to energy management and IIoT, or the Industrial Internet of Things, is a revolutionary technology steadily reshaping various industrial sectors from transportation to manufacturing to energy management and beyond. Sometimes referred to as “industrial internet” or “Industry 4. 0,” IIoT uses smart sensors and machines, real-time analytics, and connected actuators to improve industrial and manufacturing processes. This guide will provide an in-depth exploration of the Industrial IoT, with a review of its benefits, limitations, and, most importantly, its potential to revolutionize industries worldwide. What is the Industrial Internet of Things (IIoT)? The Industrial Internet of Things (IIoT) is a subcategory of the broader Internet of Things (IoT). IoT refers to the network of physical devices, vehicles, appliances, and other items embedded with sensors and software that allow them to connect, interact, and exchange data over the internet. IIoT is similar, but it focuses specifically on industrial applications. It allows manufacturing devices to be remotely monitored, controlled, and automated via connected sensors and actuators. IIoT is often used to improve: Quality control Sustainability practices Supply chain tracking and efficiency Predictive maintenance Energy management Asset tracking How Does IIoT Work? At its core, the IIoT works by connecting industrial assets to the digital world, a process often referred to as machine-to-machine (M2M) communication. Assets range from a simple sensor or manufacturing line to complex smart grids regulating energy management. These internet-connected devices collect crucial data through embedded sensors. This data is then transmitted via cloud computing to software applications that can analyze it in real time.... We answer all the questions you have about ZeroTier, a zero-trust networking solution that securely connects devices anytime, anywhere. ZeroTier, as its name suggests, is a zero-trust networking solution that securely connects devices anytime, anywhere. Its lightning-fast speed, flexibility, and top-notch security features pave the way for modern, secure, multi-point virtualized networks that transcend physical boundaries. But what exactly is ZeroTier, and what is it used for? Is it secure and can it be trusted (spoiler alert: yes)? As ZeroTier experts, we figured we’d be in the perfect position to address these questions–and more. We’ll examine its features, explore pros and cons, and verify how ZeroTier compares to competitors. This article is intended for any person—from a network engineer to a software developer to a CISO—interested in understanding what ZeroTier offers. If you’re actively seeking an advanced solution for modern virtual networking, stay tuned as we dissect this powerful connectivity tool. ZeroTier Review ZeroTier is a networking solution gaining traction for seamlessly integrating Virtual Private Network (VPN) and Software-Defined Wide Area Network (SD-WAN) technologies. It’s designed to connect devices across diverse locations as if they were on the same local network. With the increasing need for remote access and security, ZeroTier is a flexible, efficient, and secure option for organizations of all sizes–from SMBs to enterprises. What is ZeroTier used for? ZeroTier is a versatile networking tool designed to securely connect devices and networks over the internet. Its vast applications cater to engineers, IT teams, DevOps, embedded systems, and Chief Information Security Officers (CISOs). Here’s a breakdown of its varied uses: IT Teams: For IT professionals, ZeroTier is a... Learn everything you need to know about MSP Remote Access and the top software for securely managing client data and applications In an age where technology is king, Managed Service Providers (MSPs) need to stay at the forefront of innovation to provide top-tier services to their customers. MSP Remote Access is an indispensable tool that empowers these providers to remotely manage and monitor their client’s networks and systems efficiently. With remote access software, technical staff can resolve issues, manage file transfers, and ensure cybersecurity—all without being on-site. This not only saves time but also allows for immediate response to any problems that might arise. This article will explore MSP Remote Access Software's specifics, features, benefits, and limitations. It will also cover how solutions like ZeroTier can transform the industry by providing a stable and scalable connection, centralized management, endpoint management, customization and integration opportunities, reporting, and enhanced security. So whether you’re an MSP looking to upgrade your technology or are seeking to understand how MSP Remote Access can streamline your operations, stay with us as we uncover everything you need to know about this web-based, advanced solution. What is Remote Access Software for Managed Service Providers? Remote access software for Managed Service Providers (MSPs) is a technology that facilitates the ability for technicians to connect to and control a client’s network, servers, computers, or other devices remotely. Essentially, this software acts as a bridge between the MSP and their client’s systems, allowing for seamless communication, management, and monitoring without needing physical presence at the client’s location. How Does MSP Remote Access Work? MSP remote access software operates primarily through the internet,... ZeroTier is an SDN platform that allows users to create virtual networks that can span multiple devices, locations, and cloud providers. ZeroTier is an SDN platform that allows users to create virtual networks that can span multiple devices, locations, and cloud providers. ZeroTier creates an encrypted peer-to-peer mesh overlay that handles NAT traversal and authentication to network resources. The ZeroTier Github Action allows users to easily integrate ZeroTier into their CI/CD workflows by temporarily connecting runners to a private ZeroTier network. - name: ZeroTier uses: zerotier/github-action@v1 with: network_id: ${{ secrets. ZEROTIER_NETWORK_ID }} auth_token: ${{ secrets. ZEROTIER_CENTRAL_TOKEN }} - name: ping host shell: bash run: | count=5 while ! ping -c 1 ${{ secrets. ZEROTIER_HOST_IP }} ; do echo "waiting... " ; sleep 1 ; let count=count-1 done echo "ping success" ZeroTier and Github Actions can now be used to securely access internal file servers, package repositories, and container registries, as well as enterprise API endpoints like OpenShift and VMWare. This action works on the Ubuntu, MacOS and Windows runner types. After your workflow has completed, it automatically cleans up by revoking the runner’s access to the network. Today we’re going to talk about ZeroTier Flow Rules and show you some practical, simple examples. The setup I have a network with several services on it: Plex ZeroNSD Gitea And I want to make sure a number of things are possible: All users can reach the above 3 services on their appropriate ports All users can resolve DNS. Users cannot see each other or interact with each other. This is actually quite simple with flow rules in a way that is not affected by name or IP changes. Identity ZeroTier has the notion of universal identity which is a key pair that identifies your client, stored with the client is the private key, and the public key is used for interactions with external entities. With this identity you can authenticate yourself to networks; if you’ve used the product you’re probably familiar with what an identity is at its basics. Flow Rules can be used to manage networks by identity by providing an authorization layer. The ztsrc and ztdest flow rule directives can be used to allow traffic to and from identities; something we’ll see used later on in this article. Rule Evaluation In ZeroTier Flow Rules, rules are evaluated to the end of the rule set unless a break, drop, or accept statement is received. This means: break not ethertype ipv4; accept; Will accept packets for ipv4 but will not accept ipv6. Grouping Flow Rules have a unique method of grouping themselves: simply left to right. What this means is that this will have a different effect than you think: accept ztdest 1234567890 and dport... How to enable DNS in ZeroTier, and what it gets you… Let’s start with the basics, a summary of what is in this post: How to enable DNS in ZeroTier, and what it gets you... ZeroNSD — the flagship DNS implementation for ZeroTier — version 0. 4. 2 is out, with tons of new features, which we’ll talk about below. We’ll cover the differences from the 0. 1 series forward. zerotier-systemd-manager is here to make your lives easier on Linux with split-horizon DNS, which ZeroTier needs to behave like an adult on your device. We’ll cover setup and how it works under the hood. If you don’t have or can’t use systemd, you’re good if you’re on OS X or Windows. Otherwise, you may want to consider the polyresolver project which works a lot like systemd-resolved. We’ll cover setup of polyresolver in those situations. Finally, some thanks to the community who has made this possible, notably Benjamin Fry and the trust-dns team, what most of this work is based on. And rust, of course. But most importantly, I’d like to thank the rest of the team at ZeroTier for being so generous with time allocation and understanding as this project has matured. Proper DNS support has been nearly a year in the making at ZeroTier at this point, and without that, it probably would have failed miserably. Why DNS? So some of you who have been using ZeroTier for a while may be wondering “why bother with DNS? ”. This part isn’t for the rest of you. Notably, DNS enables portable... Managing network settings with a webUI can be tedious. Taking full advantage of ZeroTier means enrolling large numbers of devices, segmenting networks, and utilizing the rules Managing network settings with a webUI can be tedious. Taking full advantage of ZeroTier means enrolling large numbers of devices, segmenting networks, and utilizing the rules engine. At scale, manual management quickly breaks down. Describing ZeroTier networks as code can make life much easier. Code lets you dynamically generate settings, keep things in version control, and integrate with automated workflows. The HashiCorp Terraform verified provider for ZeroTier lets you do just that. It drives the ZeroTier Central API, allowing you to manipulate ZeroTier in a declarative way. To help you get started, we have written not one, but two interactive quickstart tutorials using Github, ZeroTier Central, and Terraform Cloud. With these tutorials, you will learn how to manage ZeroTier networks with Terraform, bootstrap cloud instances with ZeroTier, and learn about ZeroTier’s Layer 2 SD-WAN capabilities. What you need to get started: A GitHub account A ZeroTier Central account A Terraform Cloud account Both tutorials use Terraform Cloud and Github’s in-browser code editor. Hello World The ZeroTier Terraform Quickstart is for ZeroTier users new to Terraform. It shows how to describe ZeroTier Networks as code, featuring tutorial classics, like “Hello World! ”. resource "zerotier_network" "hello" { name = "hello" description = "Hello World" assignment_pool { start = "192. 168. 42. 1" end = "192. 168. 42. 254" } route { target = "192. 168. 42. 0/24" } } resource "zerotier_member" "alice" { name = "alice" member_id = "a11c3411ce" description = "Alice's laptop" network_id = zerotier_network. hello. id } resource "zerotier_member" "bob"... Yes, it’s finally happened, ZeroTier is now available on MikroTik. Yes, it’s finally happened, ZeroTier is now available on MikroTik routers as part of the standard RouterOS installation. This also means that ZeroTier now has a recommended hardware platform for people who want ZeroTier-enabled routers and other hardware networking devices, especially for small and medium business applications. Per the MikroTik forum: *RC2 package available here: https://box. mikrotik. com/f/c9a303113884413bbdca/? dl=1 But from the next v7 release, it will be included in the release system (all packages ZIP archive). To join a Zerotier network, it is as simple as this:* /zerotier/interface> add network=YYYYYYYYY instance=zt1 /zerotier>enable zt1 MikroTik now joins Ubiquiti, Teltonika Networks, OpenWrt, and OPNsense on our list of supported 3rd party networking firmware and routers. If you are a networking hardware or software provider interested in integrating ZeroTier, let us know. —– Update 07 December 2021: MikroTik has officially announced the release of RouterOS v7! Watch the announcement clip below featuring ZeroTier. MikroTik RouterOS v7 is finally here! https://youtu. be/Zp-U7Anv5-0 Today we’re going to replace our cloud storage on our mobile and desktop devices with Seafile, inside of docker-compose, to run at home. Today we’re going to replace our cloud storage on our mobile and desktop devices with Seafile, inside of docker-compose, to run at home. Why? In a time where I am increasingly concerned with data security, it behooves me to consider who is able to view my personal content. I don’t like the idea of making it easier for any company to review my personal life like I live in some sort of digital fishbowl. Seafile empowers me to store my data where I please, over the network methods I choose, and this article is an explanation of how it can be done, so you can employ it yourself. What are we doing today? Here’s a rundown of what we’ll be doing (largely in the Setup section): Configure ZeroTier on a server and at least one client Configure Docker & docker-compose on the server Install and configure a docker-compose. yml for Seafile, bound to our zerotier interface Initialize and configure the Seafile instance (over ZeroTier! ) Finally, configure a client to run ZeroTier and Seafile client, synchronizing files over the network. Services This section describes the various services we are deploying. Please be advised that other than Seafile itself, and ZeroTier, most techniques/technologies are interchangeable with other similar stuff. Like, you can set up Seafile on the Cloud, you can use a VM to deploy to instead of using docker-compose. These change the narrative only slightly. If you want to skip this section because you know this stuff really well; we... 5G and boats Want to see a real-life example of ZeroTier in the background, enabling customers to do impactful, world-changing work? Our friends at deepbv. nl shared a powerful vendor video with us about how they use 5G for maritime surveying. What they said: "ZeroTier helps me keep sessions seamlessly up while our gateway switches / network providers / sat connections work in the background. " ZeroTier at Sea ZeroTier has raised an additional $2M in funding in a round co-led by Anorak Ventures and Bonfire Ventures February 17th, 2021 — ZeroTier, a rapidly growing company with the goal of connecting the world’s devices, has raised an additional $2M in funding in a round co-led by Anorak Ventures and Bonfire Ventures. With proven technology and over ten million active networks globally, ZeroTier will deploy funding to further expand sales, product, and engineering capabilities. ZeroTier’s software solution allows devices, applications, and services to be connected simply and securely regardless of their physical location. It can be used in a variety of use cases including VPN, multi-cloud/hybrid-cloud, SD-WAN, peer-to-peer networking, and IoT remote access, allowing all these things to be achieved with a single system for vastly reduced complexity and associated costs. Founder Adam Ierymenko says, “ZeroTier was founded to realize the Internet’s true potential as a connectivity platform. Our mission is to directly connect the world’s devices, radically simplify networking, and enable a new generation of private, secure, and scalable networking applications. ” “The simplicity, flexibility, and speed of ZeroTier, combined with their open-source core has attracted a massive cult following in the networking and security space,” said Greg Castle, Managing Partner at Anorak Ventures. “ZeroTier has made it easy for developers to try with a generous free tier and they’re seeing incredible community-led growth. I’m excited and humbled to be part of such an amazing team! ” “ZeroTier is like the best-kept secret for IT companies and managed service providers. ” Said Mark Mullen, General Partner at Bonfire Ventures. “Thousands of IT providers all over the world... The good folks at Network Collective We wanted to give the good folks at Network Collective — Jordan Martin and Tony Efantis — a shoutout because they and their audience not only said some very nice things about ZeroTier, but Tony gave an incredibly awesome ZeroTier demo. In this real life network engineering use case, Tony shows how to spin up a ZeroTier network to connect his laptop to a Google Cloud VM running EVE-NG. Take a look! And give the guys a follow at @netcollectivepc. Network Collective Weekly Live Stream https://youtu. be/DzCgMVNH9P0 Ephemeral Sudden Death Since releasing ZeroTier 1. 4 and LF we have shifted most of our effort over to developing our upcoming 2. 0 release. Not much has been announced about this release, though in the LF documentation we hinted at how it will be used with 2. 0 roots. In 2. 0 we’re improving numerous things: performance, multicast efficiency, the ability to run independent infrastructure, and cryptography. This post discusses the latter. Since its first release ZeroTier has relied on simple and quite boring cryptography that uses Salsa20 as a stream cipher, Poly1305 for message authentication, and Curve25519/Ed25519 for key agreement and signatures. Our straightforward implementation has proven itself to be quite secure but it lacks some advanced features, most notably forward secrecy / ephemeral keys. Omitting ephemeral keys has been controversial. Our main rationale has been simplicity and statelessness, as discussed in an issue on the topic at GitHub. It’s also important to note that a large fraction of the traffic people send over ZeroTier is SSH or SSL encrypted already, providing defense in depth and a second layer that usually (in modern implementations) does support forward secrecy and ephemeral keys. Nevertheless we have always intended to implement ephemeral keys some day, and now is that day. Salsa20 was a good choice of cipher in 2011 to achieve wide platform support with high performance. Back then many mobile and even smaller and older desktop CPUs did not possess hardware AES acceleration. Without hardware acceleration Salsa20 is quite a bit faster than... NAT murders kittens For those who don’t know, NAT stands for Network Address Translation. If you’re on a typical network, your system probably has an IP address like 10. 1. 2. 3or 192. 168. 0. 66. These are private IPs. They are not your real Internet IP address. Between you and the network there is a device called a “NAT router” that performs intelligent address translation back and forth. NAT was invented because IPv4, the IP scheme that still runs most Internet sites, has an address space that is too small to allow all devices to have “real” addresses. Its successor, known as IPv6, does not have this limitation but is still fairly early in its adoption curve. Migrating a system as huge as the Internet to a new protocol version takes a very long time. ZeroTier One runs over a peer to peer network, which means that allowing devices to communicate directly is central to how it operates (at scale and with acceptable performance). Since most users are behind NAT devices, people often wonder how exactly peer to peer connectivity is established. NAT is Traversable In reading the Internet chatter on this subject I’ve been shocked by how many people don’t really understand this, hence the reason this post was written. Lots of people think NAT is a show-stopper for peer to peer communication, but it isn’t. More than 90% of NATs can be traversed, with most being traversable in reliable and deterministic ways. At the end of the day anywhere from...