Enterprise WireGuard

Self-hosted. Real MFA. Full control. No cloud dependency.

WireGuard® VPN, built-in SSO/Identity Provider, granular firewall access control, and zero-touch device enrollment—all running on your infrastructure. Your encryption keys and metadata stay entirely under your control and never leave your environment.

Who gets the most value from Defguard

Enterprise IT and security teams achieve maximum efficiency while meeting the highest standards of security and reliability.

CISO / CTO

True Zero-Trust, provable: MFA enforced on every WireGuard® connection, a fully isolated control plane with no Internet exposure, and complete data residency on your own hardware - aligned with NIS2, GDPR, HIPAA, and ISO 27001.

IT / DevOps

Replace Legacy and CVE prone SSL-VPN with one open platform: VPN, SSO, LDAP/AD sync, firewall ACLs, and zero-touch enrollment - deployed with a one-line script/VM, scaled with active-active HA.

Trusted by businesses across the globe

Security you can verify, not just trust

World's only connection-level MFA on WireGuard®

MFA method list offering authenticator app, email, biometry, OpenID, hardware key and mobile client

MFA on the tunnel itself

TOTP/email + per-session pre-shared keys; every connection requires MFA, not just the app login

Two-factor authentication prompt asking the user to scan a QR code with the Defguard mobile app

Biometric approval

Touch ID / Face ID via Mobile Client to authorize desktop connections

Two-factor authentication prompt requiring Google sign-in before the VPN connects

SSO-enforced 2FA

Works with Google Workspace, Microsoft Entra ID, Okta, JumpCloud, and any OIDC provider

Secure by Design architecture

Architecture diagram showing internet and WireGuard traffic reaching Defguard and the VPN gateway through DMZ and internal firewalls over HTTPS and gRPC with TLS

Secure by Design architecture

  • Fully isolated control plane — Core, database, and identity integrations are never exposed to the Internet
  • Minimal attack surface — only the Edge (HTTPS) and Gateway (single UDP port) are public
  • mTLS everywhere — mutual TLS secures every internal component connection end-to-end
  • Resilient by default — gateways keep operating even if the Core goes down

Radical transparency

Defguard GitHub organisation page showing pinned public repositories including defguard, client, wireguard-rs and gateway

Open source

Inspect, audit, and contribute to the code running your infrastructure

Penetration test report listing issues by severity, with a completed cross-site scripting finding linked to its GitHub issue

Public pentests

Independent security audits published openly

SBOM report for the Core component showing CVE vulnerability details, severity badges and patch status

Daily SBOM/CVE reports

Signed images and binaries, supply-chain best practices

Public GitHub project board showing the Defguard backlog and roadmap with numbered issues

Open roadmap

Architecture decisions and development plans shared publicly

One platform, complete stack

Built-in identity, or bring your own

Defguard login screen offering Continue with Google alongside username and password fields

Internal SSO

Full OpenID Connect provider out of the box

Enrollment activation screen offering sign-in with an external SSO provider such as Google or Microsoft

External IdP integration

Google, Entra ID, Okta, JumpCloud, any OIDC-compliant provider

Two-way LDAP synchronisation settings with either Defguard or LDAP selectable as the source of truth

Two-way LDAP & Active Directory sync

Bi-directional, with automatic enrollment of synced users

Firewall & access control

Select allowed users dialog with a searchable checkbox list of users to grant access to

Identity-based ACL

Firewall rules driven by SSO users and groups (RBAC)

Firewall rules screen with a Pending tab listing three rules awaiting deployment

Zero-downtime rules deployment

Aliases, pre-defined locations, no service interruption

Logos of supported gateway platforms: NetBSD, FreeBSD, Debian, Rocky Linux, OPNsense and Ubuntu

Multi-platform gateways

Linux, FreeBSD, NetBSD, and a native OPNsense plugin

Zero-touch enrollment at scale

Desktop client automatic configuration step with a One-Click Configuration button

Remote onboarding

Users go from install to connected without hand-editing configs

Defguard client connected to Dublin showing a WireGuard has been updated confirmation and a live throughput graph

Real-time config sync

Every change propagates to all clients in ~30 seconds (Enterprise)

Clients for everything

Windows, Apple and Linux platform icons

Native apps

Windows, macOS, Linux, iOS, Android, plus a CLI client

WireGuard logo with the tagline fast, modern, secure VPN tunnel

Any WireGuard® server

The client isn’t locked to Defguard

Defguard VPN Client listing instances for Poland, UK and France with the Warsaw location online

Multiple instances & locations

All sites and customers in one client; ideal for MSPs

Global traffic policy settings offering no limitation, disable all traffic or force all traffic through the VPN, plus group-based policies

Traffic policies

Full-tunnel or split routing, user-selectable or admin-enforced

Enterprise-grade operations

High Availability & always-on access

Enterprise
Locations management table listing London HQ, Warsaw Office, Tokyo and Berlin with gateway connection status and firewall state

Active-active HA

Multiple gateways and edges per location, no single point of failure

Service location settings with Pre-logon connection selected, disconnecting the VPN once the user logs in

Pre-logon VPN

Tunnel up before user login; domain auth and policy from boot

Service location settings with Always on connection selected, keeping the VPN connected from system boot

Always-on VPN

Persistent, auto-reconnecting connections for managed devices

Client configuration permission toggles restricting device management, WireGuard configuration and tunnel creation to administrators

Admin-only device management

Block non-Defguard clients, lock down self-service

Audit & compliance

Enterprise
Activity log listing events such as device attestation failed, webhook state changed and user added, with date, user, IP, location and module columns

Activity & audit logs

Every admin action and connection traceable

Log destination picker offering Logstash and Vector as streaming targets

SIEM log streaming

Feed your existing security stack

NIS2 Directive and GDPR Compliant badges

Regulatory alignment

Supports ISO 27001, NIS2, GDPR, and HIPAA compliance; full data residency on your hardware

ISO 27001 certification badge

ISO 27001 certified

Developed in the EU (Poland)