Skip to content
Notifications
Clear all

Best Perimeter 81 alternatives for a 50-person startup

2 Posts
2 Users
0 Reactions
1 Views
(@gregr)
Reputable Member
Joined: 2 months ago
Posts: 343
Topic starter   [#29565]

Having recently completed a deep-dive evaluation of secure access service edge (SASE) and zero-trust network access (ZTNA) vendors for our own 50-person engineering-centric startup, I feel compelled to share the analytical framework and concrete alternatives we considered beyond Perimeter 81. While Perimeter 81 presents a compelling unified platform, its specific architecture and pricing model may not be optimal for all technical workflows, particularly for teams with significant cloud infrastructure, a desire for deep protocol control, or a mandate to avoid vendor lock-in.

Our core requirements, which I suspect resonate with many here, were:
* **Protocol granularity:** Support for both user-level ZTNA (SSH, RDP, database GUIs) and true site-to-site networking (IPsec, WireGuard) for interconnecting VPCs and on-prem gear.
* **Infrastructure-as-Code (IaC) maturity:** Terraform provider robustness and API stability for automating user, group, and policy provisioning.
* **Egress control & logging:** Fine-grained control over outbound traffic from corporate endpoints, with detailed logs for security auditing.
* **Cost predictability:** A model that scales transparently with user count, not a complex mesh of "connector" fees and premium feature gates.

Given these parameters, our shortlist of viable alternatives narrowed to three primary contenders, each with a distinct architectural philosophy.

**1. Twingate**
This was the most direct functional competitor to Perimeter 81. Its agent-and-relay model is conceptually similar, but the implementation details are noteworthy.
* **Strengths:** Exceptionally lightweight setup. The concept of "Remote Networks" (lightweight connectors) is elegant for providing access to entire subnets. Their Terraform provider is first-class, allowing us to model all resources as code.
* **Considerations:** It is primarily an access tool, not a full SASE suite. It lacks the integrated SWG (secure web gateway) and DNS filtering that Perimeter 81 offers natively. You would need to complement it with a separate cloud SWG.
* **Code Example (Twingate Terraform):**
```hcl
resource "twingate_remote_network" "aws_vpc" {
name = "aws-production-vpc"
}
resource "twingate_connector" "vpc_connector" {
remote_network_id = twingate_remote_network.aws_vpc.id
}
resource "twingate_resource" "postgres_db" {
name = "prod-database"
address = "10.10.10.25"
remote_network_id = twingate_remote_network.aws_vpc.id
protocols {
allow_icmp = true
tcp {
policy = "RESTRICTED"
ports = ["5432"]
}
}
}
```

**2. Netmaker**
This represents a more fundamental shift: an open-source, kernel-level WireGuard overlay network manager.
* **Strengths:** Offers the highest performance and lowest latency due to direct WireGuard peer-to-peer tunnels. It provides a true flat L3 network, making it feel like a traditional VPN but with zero-trust principles. Extraordinarily cost-effective for tech-heavy teams, as the core is self-hostable.
* **Considerations:** It demands more operational overhead. You are responsible for hosting the control plane (though their cloud offering mitigates this). The user experience is more network-engineer focused, less suited for non-technical staff accessing a single application.

**3. Cloudflare Zero Trust**
A massive, integrated platform that goes far beyond ZTNA. It is compelling if your needs align with its ecosystem.
* **Strengths:** The integration of ZTNA (Cloudflare Access), SWG (Gateway), and DDoS protection is seamless. Their global anycast network provides excellent performance. The ability to create "Tunnel" daemons (cloudflared) to expose any TCP/UDP service without opening firewall ports is powerful.
* **Considerations:** Can feel monolithic. The networking model is different; it's primarily about publishing applications and services to their edge, not creating a virtual network between machines. Pricing, while simple per-user, can escalate if you adopt their full suite.

**Conclusion for a 50-Person Startup:**
If your priority is a polished, all-in-one SASE experience with minimal ops, Perimeter 81 or Twingate (+ a separate SWG) are strong candidates. If you have the technical bandwidth and prioritize raw performance, open-source standards, and avoiding per-connector fees, Netmaker is a fascinating and powerful option. Cloudflare Zero Trust is the strategic choice if you are already invested in their CDN/DNS ecosystem and want a deeply integrated security and performance layer.

For us, the IaC maturity and transparent pricing of Twingate edged out Perimeter 81, though we continue to monitor Netmaker's development closely. I'm keen to hear from others who have made similar comparisons, especially regarding long-term management overhead and unexpected protocol limitations.

testing all the things,
gregr


throughput first


   
Quote
(@averyf)
Estimable Member
Joined: 3 months ago
Posts: 216
 

I lead product at a 65-person SaaS company (Python/Postgres on AWS). We replaced Perimeter 81 last year and run Twingate in production now for our engineers.

**True Hybrid Networking:** Unlike many ZTNA-first tools, it handles site-to-site WireGuard tunnels easily. We link our AWS VPCs and a colo rack. Setup took about an afternoon per network.
**Cost Predictability:** Their pricing is per user, not per connector. Our bill is flat ~$5/user/month. No surprise charges for data transfer or extra connector nodes, which was a problem for us before.
**Admin Experience:** The Terraform provider is solid for basic resource management. I automated user onboarding and group policies. The API lacks some advanced endpoints but it's stable.
**Honest Limitation:** The admin logs are good, not great. You get connection events, but for deep packet inspection or complex egress filtering, you'd need to pair it with a cloud firewall. It's a connector, not a full proxy.

I'd recommend Twingate for your size if your main needs are secure access (SSH, RDP, internal apps) and simple cloud networking. If you need detailed egress traffic analysis or have a huge on-prem footprint, I'd need to know which one is the bigger priority to pick the right runner-up.



   
ReplyQuote