↓Skip to main content
Alemasone

Self-Hosted VPN: Best Solutions for Your Private Network

Compare WireGuard, OpenVPN, and Tailscale to build your own VPN on a Raspberry Pi or server. Explore performance, setup difficulty, and limitations.

8 min read Updated on
Raspberry Pi connected to a router with network cables on a desk
On this page
A VPN installed at your home serves one specific purpose: reaching your network from the outside in an encrypted way, to access your file server, cameras, or office computer. It doesn’t hide your browsing, because traffic still leaves through your line with your IP address. If you install it on a rented server instead, everything changes: we will see that below.

This is the distinction that decides everything. If you want to hide from your ISP or bypass geo-blocks, a home VPN won’t do that job. If, however, you want to access your devices remotely and securely, managing it yourself is the best solution: free and without third parties involved.

Options #

SolutionDifficultyPerformanceNotes
WireGuardMediumExcellentThe current standard, extremely lightweight
OpenVPNHighGoodMature, better at traversing restrictive networks
TailscaleLowExcellentBased on WireGuard, automatic configuration
wg-easyLowSame as WireGuardWireGuard in Docker with a web panel
PiVPNLowSame as WireGuardGuided installation on Raspberry Pi, no longer developed
NetBird and HeadscaleMediumExcellentOpen source alternatives with self-managed coordination

WireGuard #

It is today’s standard. The code is stripped down to the essentials, the encryption is modern, it is much faster than OpenVPN, and it consumes less battery on your phone. It is integrated into the Linux kernel and many routers already support it. Authentication works like SSH: each device has a key pair and the server only accepts those it knows.

WireGuard logo, the lightweight VPN protocol integrated into the Linux kernel and recent routers
WireGuard is currently the benchmark for a self-hosted VPN

Configuration isn’t difficult but it is all manual: you generate keys, write a configuration file for the server and one for each device, and open a port on your router. If you prefer a web panel, wg-easy runs WireGuard in a Docker container and lets you add devices with a single click by scanning a QR code.

OpenVPN #

It is older, heavier, and slower, but it has two real advantages: it can run over TCP on port 443—allowing it to pass through corporate or hotel networks that block everything else—and it is supported practically everywhere.

OpenVPN logo, the mature protocol capable of passing through port 443 from restrictive networks
OpenVPN remains useful where everything else gets blocked

If you need to connect from highly restricted networks, it remains the most reliable choice among classic VPNs.

Tailscale #

Here the approach changes: it uses WireGuard as its engine but manages the connection between devices itself. You don’t have to open ports on your router or have a public IP: devices find each other through a coordination service and, when possible, connect directly.

The Personal plan is free, with unlimited devices for up to six users, but only for non-commercial use. It is by far the simplest path: install the app on every device, log in with your account, and it just works. With an exit node, you can also route all traffic through your home PC, just like a classic VPN.

Tailscale administration panel showing the list of connected devices and their respective addresses
Every device that connects appears here with a fixed address

The trade-off is that coordination relies on an external service, even though traffic remains encrypted between your devices. If you want to remove that step as well, Headscale is an open-source version of the coordination server that you can install yourself, which is compatible with Tailscale apps. NetBird does something similar and is entirely open source, including its panel.

PiVPN #

It isn’t a protocol but an installation program: on a Raspberry Pi or a Debian server, it configures WireGuard or OpenVPN using a guided setup and creates client profiles as QR codes to be scanned with your phone.

Terminal showing the PiVPN wizard generating a client profile QR code
PiVPN delivers the profile as a QR code to be scanned with your phone

For years, it was the fastest way to get a VPN without writing configurations by hand, but in April 2024, the developers closed the project with version 4.6.0. Existing installations still work because WireGuard updates with the system, but for a new installation, I recommend wg-easy or Tailscale.

WireGuard or OpenVPN on Raspberry Pi #

On a Raspberry Pi, you can really see the difference because of the limited hardware.

WireGuard easily handles your home line speed even on older models because its encryption is much more efficient. The processor stays cool and the connection reconnects automatically when your phone switches from Wi-Fi to mobile data: this is the difference you’ll notice most in daily use.

OpenVPN on the same hardware becomes a bottleneck: on a Raspberry Pi from a few years ago, it struggles to exceed a few dozen megabits per second because its encryption requires much more processing power.

In short: use WireGuard, unless you need to connect from networks that block it. In that case, use OpenVPN on port 443.

Before installing anything, check your router. Many recent models, such as FRITZ!Box and many mid-range routers, already have WireGuard or OpenVPN in their administration panel: you can activate it in five minutes without extra hardware and without extra power consumption.

What you need to make it work #

An address reachable from the outside. This is the most common stumbling block: many home connections, especially on FWA (Fixed Wireless Access) and mobile networks, use shared addresses among multiple customers (known as CGNAT), which blocks incoming connections. To check this, compare the IP you see in your router’s panel with the one shown by a site like whatismyipaddress.com: if they are different, you need to ask your provider for a public IP (sometimes for a fee) or use a solution like Tailscale that doesn’t require one.

A name that follows the address. If your IP changes, a dynamic DNS service like DuckDNS can associate it with a fixed hostname. Many routers already support this.

An open port on the router pointing to the device hosting the VPN, except for solutions that don’t require one.

A copy of your configurations. Keep your client keys in a safe place: if you lose them, you will have to recreate the profiles one by one.

What a personal VPN does NOT do #

It doesn’t make you anonymous. When you connect to your home VPN and browse, traffic leaves through your line with your IP address: to the websites you visit, it looks like you are at home. This is convenient when you want to use services linked to your local network, but it is exactly the opposite of what you need for privacy.

For the same reason, it won’t bypass geo-blocks from other countries: you will always appear to be in Italy.

What it does well is protecting your traffic on networks you don’t trust—like hotel, airport, or cafe Wi-Fi—and allowing you to access your devices no matter where you are.

And what about a rented server? #

If you install the VPN on a VPS—a small server rented for a few euros a month in a data center—the situation changes. The traffic exits from the server’s address, not your home: you get a dedicated static IP, which is useful for whitelisting corporate services, and you can choose the data center’s country. You control the logs yourself instead of trusting a provider’s “no log” promise. However, the IP remains registered to you: your privacy from your ISP increases, but you are not anonymous.

On a VPS, people often also use tools designed to bypass where standard VPNs are blocked:

OpenConnect is the open-source version of Cisco AnyConnect’s protocol. It uses port 443 and its traffic looks like normal HTTPS website traffic, so it bypasses many corporate firewalls. It has clients for all operating systems.

Logo di OpenConnect VPN
OpenConnect: blends in with HTTPS traffic on port 443

SoftEther VPN is a multi-protocol server born at the University of Tsukuba: within a single program, it manages OpenVPN, L2TP/IPsec, SSTP, and its own protocol, and can even bypass restrictions by encapsulating traffic in ICMP or DNS.

Logo di SoftEther VPN
SoftEther: more protocols in a single server

V2Ray and its fork Xray are not VPNs but proxies designed to bypass censorship: they hide traffic inside a TLS connection that looks like normal browsing. They are meant for people located in countries with heavy filtering.

Logo di V2Ray
V2Ray: a proxy designed to bypass censorship

If you install more than one on the same server, watch your ports: both OpenConnect and SoftEther use TCP 443 and cannot run together without changing one of them. To get up and running quickly on a VPS, the Algo script configures WireGuard and IPsec automatically.

FAQ #

Does a self-hosted VPN replace a paid service? #

No, they do different things. A home VPN is used to access your network from the outside securely; a commercial service is used to hide your browsing from your ISP and make it look like you are in another country by mixing you with thousands of other users. A VPN on a VPS sits in the middle: it changes your location, but the IP is yours alone. If you need both, use both.

How much power does a Raspberry Pi consume when running as a VPN server? #

Just a few watts: a few euros of electricity per year. It is one of the most sensible uses for those boards, because the load is minimal and it can stay on without noise or heat.

Is it safe to open a port on your router? #

If there is an updated VPN behind that port, yes: WireGuard doesn’t even respond to unauthenticated packets, so from the outside, the port appears closed. The risk arises if you don’t update the software or if you open other ports toward less secure services.

Is Tailscale free? #

The Personal plan is, with unlimited devices for up to six users, but only for non-commercial use. For larger groups or businesses, there are paid plans. If you want to move away from external services entirely, you can install Headscale.

Can I use a VPN to watch Italian streaming services from abroad? #

Technically yes, because the traffic exits from your home line and therefore appears to be in Italy: it is one of the most common uses for a personal VPN while traveling. However, check the terms of service of your streaming provider, as some limit usage outside the subscription country. In the European Union, however, subscriptions can also be used in another EU country during a temporary stay.

Read next