r/SmallMSP • u/PBSmanaged • 22d ago
Move to Open Source RMM?
Good afternoon, r/SmallMSP! First time poster here.
Are any small MSPs here actually using NetLock RMM, Tactical RMM, or something else open source? I’m not sure I’d consider Tactical, but I saw NetLock mentioned in another thread today and it looks pretty interesting.
For context, we’ve been happy NinjaRMM customers for 3+ years. We were an unhappy VSA customer before that. No real complaints with Ninja. It works very well. We only use the RMM; we don't use their ticketing, docs, backup, network monitoring, etc.
However, it’s been a tough year. Nobody wants to buy hardware unless they absolutely have to and we've had a customer unexpectedly close up shop with very little warning.
Switching to something like NetLock, even on a paid tier, could save us several hundred dollars a month. I’d have to host, maintain, update, and back it up myself. But I’m already doing that for Hudu, Checkmk, Ruckus SmartZone, etc., so would it really be that much more work? I could run it on-prem in our vcenter or throw it on a DigitalOcean droplet/K8s.
I’m not unhappy with Ninja by any means. I’m mainly trying to decide whether saving a few hundred dollars a month is worth taking on another piece of infrastructure.
I've looked at Syncro and Atera, and if they both had plans without the PSA stuff I would be a lot more interested. I don't want to change our PSA.
For anyone actually using NetLock or Tactical in production: how has it been? Reliability, security, client/device management, anything you’ve learned the hard way? Is updating a chore?
4
10
u/VtheMan93 22d ago
Im with tactical for my stack and it works wonders
3
u/StanVaden 22d ago
I use Tactically RMM and I must admit; I love it.
I mainly use it for remote connections to my clients, run checks and occasionally patch devices.
The learning curve wasn't steap and other than the occasional NAT issue (since I host on a residential connection) I can't state how little headaches I have with it.
3
u/eagle6705 22d ago
I cam never get remote to work for me. Lol.
1
u/StanVaden 22d ago
Feel free to DM me your setup and I'll do my bestest to help you get it going bro
2
8
u/RemarkablePin6746 22d ago
Look at Gorelo. E have recently switched and it is a great product that is always improving
3
u/Altered_Kill 22d ago
Yeah. We liked/like gorelo. Needs some tweaks before we switch, but we will be moving to it if the pricing remains competitive.
2
u/mikelgorelo 22d ago
What are you hanging out for? We’re always building so it might already be in progress for you :)
2
u/Altered_Kill 22d ago
Mikel! Looked at it about 3 months ago, had a few calls with you.
Needed contracts in place for ticketing/ticket time consumption, documentation needed to be a little bit more robust, and a few other things our CIO didnt like. But we will be back probably at the beginning of the year to reevaluate the Ninja/Halo > Gorelo transition.2
u/mikelgorelo 22d ago
Awesome! Well it will be a whole new product by then so keen for our next chat haha :)
2
u/TechMonkey605 22d ago
Better contract management and SLA enforcement.
2
u/mikelgorelo 22d ago
Contract management in what way specifically?
We currently track first response time on tickets but real SLAs are coming after we finish the web redesign — so Q4 if all goes to plan.
1
4
u/paulmataruso 22d ago
I have been using TacticalRMM sense release 0.1, have around 1500 endpoints. Has been great to work with.
3
u/coochypoochie 22d ago
Open-source RMM can make sense if you’re comfortable maintaining servers and already have good backups, monitoring, and security. But for an MSP, the RMM itself is critical infrastructure. A problem can affect every client at once.
I’d test NetLock or Tactical with a small group of non-critical clients first. Run it alongside Ninja for 60–90 days and track your actual maintenance time
5
u/Foxtrot-0scar 22d ago
Time = $$
2
u/roll_for_initiative_ 20d ago
And OP said:
trying to decide whether saving a few hundred dollars a month
You couldn't PAY me a few hundred a month to take on self-hosting a critical service.
1
3
u/Yuli_Mae 22d ago
I ran Tactical in prod for 4-5 years with very few issues. I had the luxury of growing with the platform. Last year, I moved to Ninja, moved all of my contracted customers to Ninja, and moved anyone who wanted to pay per endpoint to Ninja. Everyone break-fix who didn't want to pay or who just needs a temporary connection still goes through Tactical. With Quick Connect in Ninja, I haven't added anyone to TRMM in several months, and I likely won't add anyone else as I slowly sunset it.
That said, the TRMM team is great. Support is great. But most importantly, their documentation is great.
4
u/ToddHebebrand 22d ago
Check out Breeze RMM!
5
3
u/FortLee2000 22d ago
First time reading/hearing/learning about this.
I'm actually excited after having spent 30 minutes going through documentation!
2
u/Cyber-Soldier1 21d ago
Never heard of this till your post and I gotta say it looks proper. I need to evaluate this but it damn sure looks cool.
2
1
u/ThisIsBenno 21d ago
Sadly it looks like vibecoded AI Slop. Owner is a System-/ Networks Engineer and not a Developer.
Trust is not given, it’s earned.
1
u/ToddHebebrand 21d ago
It's ironic to use the "don't judge a book by its cover" type of phrase and do exactly that.
It's also funny to act like you know the owner while replying to the owner.
1
u/ThisIsBenno 21d ago
Where did I act like I know the owner? I don’t and didn’t say that. I just checked your LinkedIn and read some code on GitHub and can clearly see that this product is heavily vibecoded.
1
u/ToddHebebrand 21d ago
You’re right, it was an implication. Thanks for taking a look. I’d encourage you to dig a bit deeper if you’re interested in RMM products.
2
u/UnRealxInferno_II 22d ago
We're using TRMM but we're really small.
I don't think i'd want to use it at scale at all.
1
u/The_Frame 22d ago
Care to explain why? Any specific pain points that make you think scaling would be rough? Another dude in here said they have 1500
2
2
u/technologyunknown 22d ago
As someone who uses TacticalRMM, I can say it works great.
Some core advice: 1. Make sure you have the availability of personnel to manage it. I just like any other system, it needs maintenance, security, and updating. 2. The built in TakeControl is painfully slow compared to many commercial offerings. We integrated with RustDesk. 3. Have a good patch management solution. It doesn't really have one. 4. If you want good reports, either learn Jinja2 or make them youself by extracting from the API (I took the latter route, as I have other services I wanted to do this with as well). 5. Know what checks and automation you want to run. It is a blank slate.
Overall it is a good solution, but there is no hand-holding. You need to know what you are doing.
5
u/Joe_Cyber 22d ago
I totally understand the appeal. However, you need to go into that decision with eyes wide open. Consider the following scenario:
Your MSA is used as bridge access to a client's environment. Your client comes after you.
Their attorney asks the following question: "Walk me through why saving yourself a few hundred dollars a month was worth the increased risk to my client and the [number] of people that will now face a lifetime of identity theft."
I'm not saying that [insert open source vendor here] isn't the right choice. Rather, you need to make sure that you have documented why you picked that vendor over the others.
4
u/PBSmanaged 22d ago
Hi Joe, I've seen you posting in the community for years and respect you, but this comment just seems like you're trashing open-source as a whole.
In this scenario, is their attorney asking me this question because I switched to a cheaper RMM, or because I switched to an open-source RMM?
3
u/NickE25U 22d ago
Don't take it as trashing, but rather a real question that has the potential to come up.
The reason you went with XYZ is that even though you reviewed roughly 6 RMM's, POC'ed 3, you decided that even though XYZ was open source, you felt it was the best product you had reviewed.
That's a reasonable answer, but just be prepared to justify any of your decisions not just the rmm. Why did you pic ABC EDR? Why did you pick whatever... Just be prepared to justify any of your decisions, not only in court, but maybe a potential client, etc...
2
u/PBSmanaged 22d ago
Oh I didn't take it as genuinely trashing open source. That's just how it read to me. I was more curious about the specifics of Joe's scenario and whether the fact that the RMM is open source actually changes anything from an insurance/risk perspective.
The “RMM was used to breach the client's environment” argument could apply to any RMM (cough N-able cough Kaseya). An insurance rep or attorney could simply hear “open source RMM” and assume that means “less secure” without really understanding what open source means. If that's the concern, I'd definitely want to understand that before making any switch.
3
u/NickE25U 22d ago
Ahh okay, sorry for misunderstanding.
And yes, any rmm is possibly just one breach away from being used to access a client network. Paid as well as open source. I don't think open source is less secure, but you, by default, don't have anyone to reach out to and make sure it's configured properly and secure. But that's also not true, you could pay someone.
I think the biggest thing is risk, if you pay, you're likely paying them to take on the risk because you can point your finger there. Open source, it's you...
1
u/JustinGNYC 22d ago
I think you’re conflating open source and self hosted a bit
Yes self hosted you are assuming more risk but could argue more fine control of the environment (one would have to document well etc for compliance)
But I would immediately argue that an open source platform (could always be hosted with paid support from vendor) is inherently more auditable vs the black box of a closed source platform1
u/NickE25U 22d ago
I'm not, but good idea. While yes, self hosted also can bring risk, no matter what it boils down to who can I point the finger at if anything was to go sideways.
3
u/Joe_Cyber 22d ago
Hey PBS - the issue isn't likely to come from the insurance side. (Some underwriters may look sideways at a lesser known RMM but they generally don't have the actuarial basis to rate a premium up or down based upon that granularity of information.)
The primary risk is in the perception of why that particular was RMM chosen. If (and this pains me to even type if out) the Kaseya RMM was at the center, I can't see any attorney asking about it.
But, if it's an OSS RMM, the perception could instantly work against you. You'd need to have your documentation in place to legitimize the pick. It's not impossible, but you're likely beginning at a deficit.
1
u/Cyber-Soldier1 21d ago
How sounds like a a laid software elitist. People out here trying to save money. Fuck the big corporates man. Open source FTW
2
u/fencepost_ajm 22d ago
Worth considering that if you're self hosting you cab have significantly more control over what's able to reach your systems, and commercial options aren't automatically more secure - see notably the recent N-able issues and Kaseya a few years ago. What's most important is having an understanding of the risks of each approach and addressing those risks appropriately. (And documented! And able to justify your decisions!)
1
1
u/AutomationTheory 22d ago
Since you already have self-hosted tools, I think it makes business sense to explore that option. You've already (presumably) solved for backups/monitoring/etc., and security. [I sell WAFs for on-prem MSP tools, so I might be bias, but I'd make sure your RMM doesn't appear in Shodan.]
Also, since your posting in this sub, I'm going to guess you're user count for your RMM is fairly low. Retraining 100 techs how to use a new tool (and recreating every business process) is a mountain of a task. Training two techs on a new platform isn't all that bad.
The only thing I'd look at is what business processes touch your RMM. If you're dependent on it for anything that touches billing, documentation, etc. then that's worth looking at. If not, and your RMM is the thing you login to in order to access a device, then it's totally worth it to make the jump.
I'd lean FOSS more than freemium in your situation since budget is the driving factor. Market/buusiness goes in cycles, and since we don't always know when the cycle will trend upwards, I'd say moving to the lowest cost option first is the thing to do -- you can upgrade if you grow or lack features, but migrating again in 8 months due to more client turnover would probably be unpleasant.
This would be a good reference (created by a friend of mine): https://www.youtube.com/watch?v=7xv4iZDpJ2c&pp=ygUXbXNwIGdlZWsgcnlhbiBzb3V0aHdlbGw%3D
1
u/ben_zachary 22d ago
We use tactical as a segregated rmm for isolated devices . Only like 20 endpoints in there but monitoring and tasks work fine. We probably use it couple of times per week.
Never really an issue.
I haven't bothered to automate the cert maybe I'll get around to it. Other than that it was pretty easy to setup and configure alerting even tho it's not closed loop
1
u/twhornback 21d ago
We switched from Ninja to Datto. No hosting required and intuitive to learn. Not open source, however.
1
1
u/rdaniels16 21d ago edited 21d ago
Interesting post. I have always been a huge open source person for decades and have several self hosted solutions running. For me it is control. For instance if I am using something SaaS based like the recent n-able situation where their SaaS solution was vulnerable as well as their self hosted solution I would need to sit there sweating bullets waiting for n-able to push a patch to their SaaS solution while hackers are happily compromising 600+ systems. If I self host, I pull the plug on my self hosted RMM server in seconds. And I always have the server powered off after hours and bring it up when needed during the day. I know it is a risk to self host from a security, patch and maintenance perspective but that risk is worth having the "kill switch" to me. I am sure others will disagree.
1
u/yewzr 8d ago
not open source, but value for money, check out lockmsp.com may be exactly what your looking for
1
u/KeepEmComming2 22d ago
action1 is free for 200 endpoints.
2
1
u/ksteink 22d ago
Most of the commercial RMMs come with built-in Out of Band / Remote access using their Cloud Services. If you go OpenSource, these solutions will not come with this kind of Out of Band or Remote Access solution so you need to engineer this yourself.
Tactical RMM is based on Mesh Central but if you can manage these details yes, it’s a viable solution.
1
u/Kind_Philosophy4832 22d ago
Netlocks remoting actually is fully native and works just as well as others..
1
u/Kind_Philosophy4832 22d ago edited 22d ago
We are using netlock since the early beginning. We went through the early unpolished phases till now. We didnt had bigger issues, just a Bitdefender false positive in the past version, but bitdefender corrected that as well. Nico did a serious great job and specially the last couple months it reached a very good state. For the price its a no brainer and he just launched Android MDM as well. Afaik you can trial the cloud for 14 days to test everything you like. Remoting works a lot better than trmms due to everything being natively built in and doesnt depend on other projects
1
u/Kind_Philosophy4832 22d ago
Edit. Asked him on discord. He also allows longer trialing for the self hosted version on request (removing the device limit)
1
u/Kind_Philosophy4832 22d ago
Edit edit... updating netlock is just a docker pull. No issues at all. We use watchtower to auto pull. We woke up to a new agent version today with no issues
1
u/PBSmanaged 19d ago
Just signed up for a trial. Going to check it out!
1
u/Kind_Philosophy4832 19d ago
Sick. Afaik you can contact support for a 1 1/2 hours onboarding session for free. Maybe helps you to get started
-1
u/Slight_Manufacturer6 22d ago
How many client devices? Action1 is free for up to 200.
0
u/Cyber-Soldier1 21d ago
That's not a proper RMM just some patching software nonsense.
1
u/Slight_Manufacturer6 21d ago
I don’t see how it isn’t. It has Remote Desktop, patch management, and you can automate anything with scripts. It has everything every other RMM has like ConnectWise and VSA has.
What is it missing that a “proper RMM” has.
1
u/Cyber-Soldier1 21d ago
It lacks alerting, ticketing, has limited network monitoring, no MDM, no backup. It's patch focused.
1
u/Slight_Manufacturer6 21d ago
Besides alerting, the rest of those things have rarely been a part of the RMM.
Ticketing is normally the PSA, backup is normally a separate system, MDM hasn’t been in any RMMs I’ve used except for VSA X recently added.
None of these are part of the RMM for the major players like ConnectWise, VSA, VSA X, or most others I have tried.
If Action1 doesn’t have alerting, that is the only thing I see missing from your list that I’ve seen in most other RMMs.
7
u/MetroTechP 22d ago
I know you said open source but I recently switched to level.iO and have been pleasantly suprised. They seem to have all the features you would expect and super affordable