business

Verdict

Submitted 6/18/2026, 5:27:51 PM · Completed 6/18/2026, 5:56:28 PM

5.5
pivot
The idea

Suggestions for modern VPN solution

Pain point
The user needs a modern, self-hosted, IPv6-compatible VPN solution that supports SSO and split-tunneling for remote access to internal services.
Who has this problem
Sysadmins managing small to medium-sized networks with specific security and network requirements.
Contradiction (TRIZ)
Wants a solution that is both fully self-hosted and vendor-agnostic, but also offers advanced features like SSO and split-tunneling.
Ideal final result
A seamless, self-hosted, multi-platform VPN solution that integrates smoothly with existing infrastructure, supports IPv6 natively, and provides robust user management and security features without vendor lock-in.
Suggested solution
Consider using OpenVPN with a custom client that supports split-tunneling and integrates with an existing Identity Provider for SSO. This solution can be self-hosted, fully customizable, and leverages the strengths of open-source tools like OpenLDAP or Keycloak for user management while providing advanced security features.
Show original source text →
Hello everyone, I am currently exploring some solutions for our company (10-15 users, mostly developpers) in order to implement remote access for specific services. We use Fortigate as firewall and historically had the free version of Forticlient with Entra ID as IDP. However 2 years back our internal network was modernised and legacy VPN solutions no longer cut it. For context, we have the following network setup internally : * About 50 VLANs each with a /64 * SLAAC and RDNSS are used to advertise prefixes and DNS servers (Cloudflare/Google and a local Unbound cache server acting as failover) * No dependencies on Active Directory, no DHCP server or any local DNS server * Most internal services run on Linux VMs (through Docker with IPVLAN on Alma Linux or Debian with Caddy, Nginx or Treafik) while few run on standalone Windows Server instances * Some services include Gitlab, Bitwarden, MQTT, an S3 instance, Grafana, InfluxDB, NodeJS alongside an internal wiki * Web services are exposed internally through public AAAA DNS records, most with SSO enabled through and IDP with conditional access whever possible, SSL is enabled everywhere with ACME clients (DNS-01) or a reverse proxy and only a select few AAAA web services are exposed externally with strict filtering activated (geo blocking, anti-bot). For that we use the Crowdsec Fortigate integration and some public IP blacklists plus Techaro Anubis on some critical services * NAT64 is used where needed but servers have no internal IPv4 connectivity * We already use Apache Guacamole as remote access gateway (SSH, RDP only) What I need is something acting as a centrale node which allows me to handle user access before terminating to my proxy / IP adresse of the servers (Exemple Gitlab) through the internal network. I am having a hard time find a solution which ticks all of my requirements, notably : * Ideally self hosted and doesn't have a vendor 'lock in' * Installable on Docker or Linux * Fully supports IPv6 without fallbacks like NAT or legacy IPv4 * Can allocate client devices on a routed /64 (from Firewall to VM) and then manage access rights and supports IDP integration for SSO/OIDC * Has a lighweightclient (GUI and CLI for servers) * Has native split-tunneling allowing only traffic to the IP ranges to be routed though the tunnel * Uses Wireguard or IPSec * Does not require maintaining a split DNS server / zones I have been researching / testing several solutions since past weeks but none fit my needs : * Zscaler, Pangolin, Netbird and Twingate : Eliminated due to lack of IPv6 support * Teleport : Features locked out in free version, incomplete IPv6 support * Defguard : Seemed promising but the VPN client fails to install on Alma Linux * Netmaker : SSO tax, features locked out in free version * Fortigate ZTNA : We do not use ZTNA or EMS and the pricing isn't attractive * Tailscale / Headscale : Supposedly has IPv6 support but only using ULAs which is not what I want * A basebone Wireguard server on a Linux VM : Network-side would work but user management would be a PITA Does anyone have some good recommendations / experiences ? Thanks !
TRIZ inventive level: 3/5· Principles: parameter changes, mechanical interaction
Synthesis verdict
**Pivot**. The idea has a strong market potential with a hidden, paying market of IPv6-native, AD-free engineering teams. However, the proposed solution requires significant development and integration efforts, and the team's capabilities and resources may be insufficient to deliver a seamless IPv6 routing and robust policy controls. The venture is highly unlikely to succeed within 6-12 months due to regulatory/compliance overhead, platform risk, and churn due to user experience.

Strengths

  • Highly specific, technically sophisticated problem from a niche but valuable audience
  • No existing tool meets the exact stack requirements
  • Potential for high-margin, freemium model with unique IPv6-only zero-trust capabilities

Weaknesses

  • Overly restrictive requirements for a small team's capabilities and resources
  • Regulatory/compliance overhead may trigger unforeseen compliance burdens
  • Platform risk due to DIY approach may lead to significant internal resource expenditure
  • Lack of lightweight, user-friendly client may lead to high churn rates among users

Best angle

Focus on building a lightweight, Dockerized WireGuard + Keycloak + CIDR-based policy engine, and monetize via enterprise support to address the niche market's needs.

Panel verdicts

Viability

meta/llama-4-maverick-17b-128e-instruct

6.0

A custom solution using a combination of existing open-source tools like Wireguard and a user management system could be feasible, but would require significant development and integration efforts.

The proposed solution requires a complex setup with multiple specific requirements such as IPv6 support, IDP integration, and split-tunneling. While some existing solutions like Wireguard or Headscale have some of the required features, they lack others, such as proper IPv6 support or user management. A custom solution using a combination of existing open-source tools could be feasible, but it would likely require significant development and integration efforts. A solo or 2-person team might be able to build a basic version in 4-12 weeks, but it would likely be a simplified solution that doesn't fully meet all the requirements. The team would need to prioritize features, focus on the most critical ones, and potentially sacrifice some of the nice-to-have features.

Competition

no model

This agent failed to return a verdict (executor exception: 'NoneType' object has no attribute 'strip'). The synthesis ran with the remaining agents.

Risk

nvidia/llama-3.3-nemotron-super-49b-v1

2.0

Overly restrictive requirements for a small team's capabilities and resources doom the project to failure.

The proposed venture is highly unlikely to succeed within 6-12 months due to three critical failure modes: **1. Regulatory/Compliance Overhead**: The custom, self-hosted, IPv6-only requirement may trigger unforeseen compliance burdens (e.g., GDPR for EU users, CCPA for US) without a clear, audited, and compliant solution, leading to potential legal liabilities. **2. Platform Risk (Vendor Lock-in Avoidance Backfiring)**: The stringent avoidance of vendor lock-in leads to a DIY approach (e.g., basebone Wireguard server) that significantly increases internal resource expenditure for maintenance, support, and user management, potentially overwhelming the small team. **3. Churn due to User Experience**: The lack of a lightweight, user-friendly client (especially for non-developer users, if the team grows beyond its current developer-heavy profile) and the complexity of the setup may lead to high churn rates among users, undermining the solution's adoption and effectiveness.

Market

qwen/qwen3-next-80b-a3b-instruct

7.0

There's a hidden, paying market of IPv6-native, AD-free engineering teams who will pay for a self-hosted, SSO-integrated, routed-IPv6 zero-trust gateway - but no existing tool meets their exact stack requirements.

This is a highly specific, technically sophisticated problem from a niche but valuable audience: small-to-mid-sized engineering teams running modern, IPv6-native, AD-free infrastructures. The user is not asking for a generic VPN - they need a zero-trust, SSO-integrated, IPv6-routed, self-hosted access gateway that respects their architectural constraints. This is a real, unmet need. While solutions like Tailscale and Teleport are popular, they fail on IPv6 routing (using ULA instead of global addresses) or lock critical features behind paywalls. The fact that this team has already invested in Guacamole, Crowdsec, ACME, and IPv6-only services signals they are early adopters with budget and technical capacity to pay for a tailored solution. The market size is small but high-value: likely under 10,000 organizations globally with similar setups (cloud-native, IPv6-first, no legacy AD). These are DevOps teams at startups, SaaS companies, or research labs who prioritize security, autonomy, and infrastructure integrity. They will pay for a self-hosted, open-source, WireGuard-based solution with OIDC/SSO and native /64 allocation - and would likely contribute to or sponsor such a project. The absence of existing tools meeting this exact combo of requirements creates a white space. However, the score is not higher because building this requires deep networking expertise, and the market is too small to justify a commercial product without open-source community traction first. A viable path would be to build a lightweight, Dockerized WireGuard + Keycloak + CIDR-based policy engine - and monetize via enterprise support, not licenses.

Monetization

openai/gpt-oss-120b(fallback #2)

6.0

A high‑margin, freemium model can work if the product offers unique, production‑ready IPv6‑only zero‑trust capabilities that current competitors lack.

The venture targets a niche but growing segment: enterprises that have fully transitioned to IPv6 and need a self‑hosted zero‑trust remote access platform. The value proposition is clear - full IPv6 support, split tunnelling, SSO/OIDC integration, and lightweight clients without vendor lock‑in. However, the market is crowded with established players (Tailscale, Netbird, Zscaler) and open‑source projects that already address many of these needs, albeit with partial IPv6 support. Monetisation would likely rely on a freemium model: an open‑source core for community adoption, with paid enterprise add‑ons (advanced policy engine, centralized management UI, premium support, and compliance reporting). Pricing could be tiered per‑user per‑month ($8‑$15) or per‑node for on‑prem licences, plus optional support contracts ($2,000‑$10,000 annually). Channels would include direct sales to mid‑size tech firms, partnerships with managed service providers, and listings on cloud marketplaces. Gross margins would be high (70‑80%) given low COGS for software, but support and continuous development costs could erode profitability if adoption is limited. The biggest risk is the difficulty of convincing customers to switch from existing solutions, especially when the core feature set overlaps. Success hinges on delivering truly seamless IPv6 routing and robust policy controls that competitors lack, and on building a strong ecosystem of integrations and support services.

Synthesized by meta/llama-3.3-70b-instruct · 4.5s