Defguard releases

New Desktop Client, Device Posture Checks, dynamic Allowed IPs and Gateway on VyOS - meet Defguard 2.1

blog post cover

Defguard 2.1 brings a redesigned Desktop Client with tray mode, Device Posture verification before a WireGuard® connection is allowed, Allowed IPs generated from Firewall Rules for true least-privilege access, and official support for running Defguard Gateway on VyOS.

September 4, 2026

Update
Core

Device Posture Verification

Define the security criteria a machine must meet before it can establish a WireGuard® connection. Posture Checks validate client version, OS version, security updates, Active Directory membership, antivirus status and disk encryption, and can be assigned per VPN location.

Update
Core

New Desktop Client UX

The Desktop Client has been redesigned with live configuration sync, multiple instance and location support, and flexible MFA including biometrics via the mobile app. The new tray mode adds a minimalistic layout and an instance picker, so users connect in two clicks.

Update
Core

Allowed IPs generated from Firewall Rules

Allowed IPs in the WireGuard® config can now be derived from the Firewall Rules that apply to a specific user, so configs never expose subnets that user cannot reach. Disabled by default, enabled per location, and combined with any manually defined entries.

Update
Deployment

Defguard Gateway on VyOS

Defguard Gateway is now officially supported as a container on VyOS, with no native package install required. It runs with full host networking, manages WireGuard® interfaces and nftables ACL rules natively, and keeps persistent state in a mounted VyOS volume.

Update
Core

Full control of Client from command-line - including MFA

Drive the desktop client from the terminal: connect and disconnect locations, check live connection status, and inspect your configuration. It shares instances, locations and the background service with the desktop app, supports MFA, and can emit JSON - useful for headless machines, SSH sessions and scripting.

Update
Enterprise

Service locations on Linux with Always-on VPN

Service locations are now supported by the Linux client, enabling Always-on VPN mode. The connection is established on system boot by a background service that runs independently of the Desktop Client, so it stays up across logins and logoffs and even when the Client has never been opened. Pre-logon mode remains Windows-only.

Update
Security

Security audit before release

This release was tested by our security team, ISEC, together with Striga.AI, and all major findings were fixed before shipping. A full pentesting report will be published on the pentesting page.