129 Followers
0 Following
37 Posts

๐Ÿš€ Defguard 2.0 Alpha 2 is out โ€” nearly feature-complete!

๐Ÿ†• What's new:
- Quick Setup Wizard & OVA images
- High Availability (multi-gateway + Envoy LB)
- Firewall management
- Static IP assignment
- Easier Edge & Gateway deployment

Not for production yet โ€” but great for PoCs and early testing. Beta with 1.6 migration wizard coming soon.

๐Ÿ‘‰ https://defguard.net/blog/defguard-2-0-release-alpha-2/

#WireGuard #OpenSource #SelfHosted #VPN #Defguard

Defguard 2.0 Release Alpha 2: Feature-Complete Preview for Early Testing | Defguard Blog

Defguard 2.0 Alpha 2 is now nearly feature-complete. This release introduces faster setup, high-availability improvements, firewall management updates, and static IP assignment for users and devices.

defguard

Weโ€™re opening early user testing for Defguard 2.0 Alpha!

Some of the major improvements include:

๐Ÿ— Reversed core โ†” gateway communication model

๐Ÿ–ฅ Fully redesigned control plane UI

๐Ÿ” Built-in internal certificate authority (mTLS)

๐Ÿ“Š Full system state visibility in the UI

โš™๏ธ Guided deployment & component provisioning

๐Ÿ” Active-active gateway high availability

โฑ Explicit WireGuard session management

Release notes & details: https://defguard.net/blog/defguard-20-alpha-technical-overview

Video guide: https://www.youtube.com/watch?v=DWQlyHmqMlo

Defguard 2.0 Alpha now available for early user testing | Defguard Blog

Defguard 2.0 is a major step forward, featuring a redesigned interface, stronger security and simpler deployment. This post covers why the changes were made, what was rebuilt and how the new architecture enables high availability and future growth.

defguard

Defguard v1.6.0 released -
Scale WireGuard Enterprise VPN.

๐Ÿ–ฅ๏ธ Windows Pre-logon & Always-on WireGuard with Service Locations

๐Ÿš€ Zero-touch Enrollment & Provisioning โ€“ MSI, macOS App Store, and file-based tokens.

โš™๏ธ Enterprise-ready clients - WireGuardNT on Windows & native Swift on macOS

๐ŸŒ Improved network reliability โ€“ Manual MTU configuration for LTE/5G.

Release notes & details: https://defguard.net/blog/defguard-16-release-notes/

#WireGuard #VPN #SelfHosted #ZeroTrust #CyberSecurity #EnterpriseIT

Defguard 1.6 brings Zero-touch Enrollment at Enterprise Scale for WireGuard | Defguard Blog

Zero-touch WireGuard VPN enrollment, Pre-logon VPN for Active Directory, Always-On VPN, native macOS/Windows clients, and enterprise-scale device provisioning. The most complete open-source WireGuard VPN solution.

defguard

Is your enterprise VPN stuck in the SSL era? ๐Ÿฆ–

We unpacked the mechanics behind common issues like TCP meltdown, DTLS fallback, and mobility struggles in our new guide.

See why the transport protocol matters and what a modern, WireGuard-based alternative looks like in practice:

https://defguard.net/blog/ssl-vpn-performance-protocol-problem/

#SSLVPN #WireGuard #OpenSource #NetworkEngineering

Why is Your Fortinet VPN Slow? The SSL VPN Protocol Problem | Defguard Blog

Tired of users complaining your Fortinet VPN is slow? You're not alone. The problem is the SSL VPN protocol itself. See the facts & why even Fortinet is deprecating it.

defguard

Defguard listed in Dealroom's "Tough Tech" report!

Mapping NATO Eastern Flank innovations, it defines "Tough Tech" as tech that "can't fail."

The only infrastructure that never fails is one you fully control.

We were recognized for:
๐Ÿ”น European Data Sovereignty
๐Ÿ”น Privacy & Control (Self-hosted)
๐Ÿ”น Trust through Open Source

If you build critical infrastructure, don't rent your security. Own it.

More: https://dealroom.co/uploaded/2025/11/Tough-Tech.pdf

#OpenSource #SelfHosted #CyberSecurity #DataSovereignty #ToughTech

The NIS2 Directive is no longer a future problem. It's on your desk now, and your remote access stack is under scrutiny.

But be warned: most "VPN MFA" solutions have a critical compliance gap that auditors will find.

We wrote an engineering guide (no fluff) on how to fix it:
๐Ÿ”น Real security vs. "checkboxes"
๐Ÿ”น Implementing connection-level MFA
๐Ÿ”น Making your setup compliant

Read the deep dive: https://defguard.net/blog/mfa-wireguard-nis2-compliance/

#NIS2 #WireGuard #InfoSec #MFA #SysAdmin

๐Ÿ’ก Not all โ€œVPN MFAโ€ means the same thing.

Setup-level 2FA: checked once during device enrollment.

Connection-level MFA: required every time a session starts.

If someone steals the VPN key (the static config with the private key), setup-level 2FA wonโ€™t block the connection, because itโ€™s not involved in the handshake.

Connection-level MFA is.

In Defguard, MFA is built into the WireGuardยฎ session flow.

More: https://defguard.net/vpn_mfa/

#Cybersecurity #VPN #Enterprise

Our founder Robert joined the Hard2Beat podcast with Maciej Zawadziล„ski to talk about something simple, yet often forgotten in enterprise security.

People build systems and people make mistakes. Thatโ€™s normal.

The real problem starts when systems are designed to hide those mistakes.

We build Defguard to be seen, tested, and trusted โ€” by everyone.

๐ŸŽง Watch the episode and tell us what you think: https://www.youtube.com/watch?v=qnkOtnTAheQ

#Defguard #OpenSource #Security

๐ŸŽ™๏ธ Hard2beat Podcast #4 - Defguard and the future of security

YouTube

๐Ÿ”’ Is your enterprise VPN a "Black Box"?

When security relies on "trust" in closed code, you're exposed to hidden risks, vendor lock-in, and outdated protocols.

We compared the traditional "all-in-one" model with an open, enterprise-ready stack built on WireGuardยฎ.

๐Ÿ‘‰ Swipe for 2 key differences
๐Ÿ“Š Full 8-point analysis: https://defguard.net/defguard-vs-fortinet/

#CyberSec #VPN #OpenSource #WireGuard #InfoSec #EnterpriseSecurity

Whatโ€™s your Enterprise VPN built on?

Biggest release yet: 11 major features and nearly 100 bugfixes!

๐Ÿ“ฒ Mobile Clients with Internal MFA (TOTP/Biometry) and External SSOs.

๐Ÿ’ซ Desktop Client adds External SSO/IdP MFA.

๐Ÿซ† New: MFA on Desktop via Mobile Biometry ๐Ÿ”

๐Ÿค As an open company, weโ€™ve launched public processes like the Architecture Decision Record and a page with pentesting findings & fixes (unique in VPNs, as far as we know).

Release notes: https://defguard.net/blog/defguard-15-release-notes/

#WireGuard #vpn #security #privacy #release #selfHosted

Release 1.5 with Mobile apps, External SSO MFA, MFA with Biometry | Defguard Blog

This is the biggest, most feature packed release we have ever done! Weโ€™ve introduced 11 major features and nearly 100 bugfixes.

defguard