Both overlay networks — but one emulates an Ethernet switch and one builds identity into the network itself. Here's the split.
| OpenVLAN | ZeroTier | |
|---|---|---|
| Abstraction | Layer 3, identity-based IP network | Layer 2 virtual Ethernet (bridging, multicast) |
| Encryption | AmneziaWG end-to-end | Custom protocol, end-to-end |
| Controller | SaaS coordination layer | Hosted controllers or self-hosted |
| Access control | Central ACLs per user/tag/port | Rules per network, flow-based |
| Identity provider / SSO | Native, with SCIM | Controller-dependent |
| Audit and session recording | Built in | Not included |
| Layer-2 needs (broadcast domains) | Bridging via subnet routers | Native strength |
| Open source client | Yes | Yes |
You genuinely need layer-2 semantics — broadcast traffic, non-IP protocols, or Ethernet-bridging across sites.
Your access is IP-based and you want SSO, SCIM, ACLs, and audit as first-class citizens rather than controller add-ons.
Gaming labs and IoT clusters keep ZeroTier for L2; production infrastructure moves to OpenVLAN for identity and policy.