Pangolin is the closest open-source cousin to ProxyLink — self-hosted WireGuard tunnels via its connector that expose private resources, with browser SSH/RDP/VNC and identity-aware access. If you want to host and run it yourself, it's a strong choice. ProxyLink is the managed, MSP-focused version: multi-client tenancy and isolation, EU-hosted, NIS2 built in, MikroTik auto-config, and nothing to self-host or patch.
| Feature | ProxyLink | Pangolin |
|---|---|---|
| WireGuard tunnel + browser access | ||
| Open source / self-hostable | No (managed) | |
| Fully managed — nothing to run, patch or scale | No — you self-host | |
| Reach entire LAN incl. NVR/PBX/switches agentless | Partial (per-resource config) | |
| MSP multi-tenant client management + isolation | Single-org focus | |
| One-click MikroTik router auto-config | ||
| One-line Windows PC deploy | ||
| Identity-aware access / SSO | Basic RBAC + 2FA | |
| NIS2 audit log + session recording | Basic logs | |
| EU-hosted, managed | Wherever you host it |
Comparison reflects public documentation as of 2026. Pangolin is a capable tool in its own category — this page focuses on the MSP / whole-site use case where the two differ.
Pangolin is open source and self-hosted — which means you run the server and connector, handle updates, TLS, scaling and your own uptime. Great if you want full control; real ops work if you don't.
ProxyLink runs on Hetzner Germany. We patch, scale and secure it. You onboard a client site in minutes and never touch a server.
Pangolin is built to expose your own resources behind one deployment — not to manage dozens of separate client networks with tenant isolation and per-client compliance.
Teams, client groups, tenant isolation, a per-client NIS2 portal, MikroTik auto-config and one-line Windows deploy — built for managing many client sites at once.
Free during early access. EU-hosted. No agent on network devices. No credit card.
Get free access →