./security/defguard, True Zero-Trust WireGuard VPN with 2FA/MFA

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 2.1.0nb2, Package name: defguard-2.1.0nb2, Maintainer: adam

Defguard provides Comprehensive Access Control (a complete security platform):
* WireGuard VPN with 2FA/MFA - not 2FA to "access application" like most
solutions
- The only solution with automatic and real-time synchronization for users'
desktop client settings (including all VPNs/locations).
- Control users ability to manage devices and VPN options
* ACLs/Firewall Management for Linux and FreeBSD/OPNSense
* Integrated SSO based on OpenID Connect:
- significant cost saving, simplifying deployment and maintenance
- enabling features unavailable to VPN platforms relying upon 3rd party SSO
integration
* Already using Google/Microsoft or other OpenID Provider? - external OpenID
provider support
* Two way Active Directory/LDAP synchronization
* Only solution with secure remote user Enrollment & Onboarding
* Yubico YubiKey Hardware security key management and provisioning
* Secure and robust architecture, featuring components and micro-services
seamlessly deployable in diverse network setups (eg. utilizing network
segments like Demilitarized Zones, Intranet with no external access, etc),
ensuring a secure environment.
* Enterprise ready (multiple Locations/Gateways/Kubernetes deployment, etc..)
* Built on WireGuard protocol which is faster than IPSec, and significantly
faster than OpenVPN
* Built with Rust for speed and security


Master sites:

Filesize: 6685.313 KB

Version history: (Expand)


CVS history: (Expand)


   2026-09-29 08:08:46 by Thomas Klausner | Files touched by this commit (3127)
Log message:
*: recursive bump for pcre2 10.49
   2026-09-27 13:39:47 by Tobias Nygren | Files touched by this commit (3126)
Log message:
*: revbump for pcre2 symbol versioning change
   2026-09-05 07:08:24 by Adam Ciarcinski | Files touched by this commit (12) | Package updated
Log message:
defguard*: updated to 2.1.0

2.1 makes the device itself part of the access decision - admins define the
security criteria a machine must meet, and non-compliant endpoints simply can't
establish a connection - and it ships a rebuilt Desktop Client whose tray mode
gets your users onto the VPN in two clicks.
   2026-09-02 21:05:38 by Thomas Klausner | Files touched by this commit (3127)
Log message:
*: recursive bump for pcre2 10.48
   2026-07-24 11:03:52 by Adam Ciarcinski | Files touched by this commit (7) | Package updated
Log message:
defguard-gateway: updated to 2.0.3

2.0.3
Fix memory access problem on BSD.
   2026-07-13 09:29:18 by Adam Ciarcinski | Files touched by this commit (12) | Package updated
Log message:
defguard, defguard-gateway, defguard-proxy: updated to 2.0.2

2.0.2:

SMTP OAuth configuration for Microsoft and Google
Bulk user actions
Synchronization of disabled Active Directory users
LDAP integration improvements
Synchronization of users only from specified groups in Microsoft directory \ 
synchronization
Security improvements to the Forward Auth functionality
Bug fixes and UX improvements
   2026-05-15 11:02:08 by Adam Ciarcinski | Files touched by this commit (7) | Package updated
Log message:
defguard defguard-proxy: updated to 2.0.1

2.0.1
Bug fixes
   2026-05-05 20:00:36 by Adam Ciarcinski | Files touched by this commit (12) | Package updated
Log message:
defguard: updated to 2.0.0

2.0.0

It’s a significant step up from version 1.x, featuring:

a completely redesigned UI,
a new and easy deployment approach (and component communication security),
and some other major architectural changes.