TiloBox
Back to directory
Defguard project preview

Defguard

Enterprise WireGuard 2FA/MFA VPN gateway and OpenID Connect identity provider.

LicenseApache-2.0
GitHub stars2.8k
Last commit1 weeks ago
Tags6 topics
Oidc ProviderWebauthnRustEnterprise VpnWireguard 2faSecurity
Overview

Why consider Defguard?

Defguard is an enterprise-grade open-source WireGuard 2FA VPN gateway and OpenID Connect (OIDC) identity provider. Written in Rust, it delivers hardware token MFA (YubiKey), WebAuthn, LDAP synchronization, and multi-location WireGuard gateway clustering.

Guided learning

Learn Defguard by building

Practical setup notes, real use cases, and copy-ready examples in one focused guide.

1 min read 2 sections
In this guide2 sections

Overview of Defguard

Defguard enforces hardware key MFA authentication on WireGuard tunnels before granting access to corporate VPC infrastructure.

Running with Docker

bash
1# Deploy with Docker Compose
2curl -fsSL https://defguard.net/install.sh | bash

Defguard is licensed under the Apache License Version 2.0.

Related tools

More options with a similar category or technology profile.

Defguard FAQs

Defguard is listed as a Devops Infrastructure tool on TiloBox. Review the overview, features, and official documentation on this page to decide whether it solves your specific workflow.

Start with the project's GitHub repository and official website for supported installation and deployment instructions. Test the setup with representative data or a small project before rolling it out more widely.

Defguard is listed under the Apache-2.0 license. Read the complete license text and the project's notices before using, modifying, or distributing the software.

Production readiness depends on your requirements. Review maintenance activity, security practices, documentation, backup and upgrade procedures, and compatibility with your stack; then validate it in a non-production environment.

Defguard is listed as an alternative to Okta MFA VPN. Compare the core workflow, deployment model, integrations, and licensing against your must-have requirements before switching.