Both put a client on the device. The difference is where traffic goes: peer-to-peer over AmneziaWG, or through Cloudflare's edge.
| OpenVLAN | Cloudflare WARP / ZT mesh | |
|---|---|---|
| Traffic path | Direct peer-to-peer when possible | Through Cloudflare edge |
| Protocol | AmneziaWG (open standard) | Proprietary BoringTun-derived |
| Any-protocol access | SSH, RDP, DB, k8s native | Best for HTTP; tunnels otherwise |
| Self-hosted resources | Join directly as nodes | cloudflared tunnel per network |
| Device-to-device (Taildrop-style) | Built in | Not the model |
| Independence from vendor edge | Direct paths degrade gracefully | Edge outage = access outage |
| Free tier | Personal, up to 100 devices | Zero Trust free tier |
You want SASE-style web filtering, DLP on HTTP, and Gateway policies — a full edge security stack in one client.
You want fast private access to your own infrastructure — any protocol, direct paths, no edge dependency for P2P traffic.