Ross ROSS = Recommend OSS · open-source software intelligence for agents

DefGuard/defguard

Zero-Trust access management with true WireGuard® 2FA/MFA observed · 2026-08-28

github.com/DefGuard/defguard · homepage · Rust · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 96
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 14
  • age_days: 1414
  • days_rel: 29
  • days_push: 8
  • n_releases_24m: 30

Full methodology

Adoption not part of the score

2809 stars · 110 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Defguard is a self-hosted zero-trust access management platform combining WireGuard VPN with built-in MFA/2FA, identity and access management (OIDC SSO, LDAP/AD sync), and firewall access control. It is written in Rust and ships with desktop, mobile, and CLI clients plus webhooks and a REST API.

Use cases

  • self-host wireguard vpn with mandatory mfa on every connection
  • run an internal openid connect provider for sso
  • enforce two-factor authentication for vpn logins with yubikey or totp
  • manage vpn users and groups synced from ldap or active directory
  • apply per-user firewall rules across multiple vpn gateways
  • onboard remote employees with self-service device enrollment
  • stream audit logs to a siem

When to choose

  • you want a unified, fully self-hosted alternative to Tailscale/Pritunl/Keycloak+VPN stacks
  • you need connection-level MFA for WireGuard, not just portal login MFA
  • you require zero-trust network access with per-location ACLs and audit trails
  • you want open-source core with published SBOMs and pentest reports

When to avoid

  • you need only a simple point-to-point WireGuard tunnel without identity management
  • you require cloud-managed VPN with no self-hosting overhead
  • you need features like HA, LDAP sync, or SIEM streaming but cannot use the paid tiers
  • your infrastructure is not Linux/BSD-based for gateways

Facets

service · maturity active

auth authorization vpn security self-hosted api-gateway webhook security networking self-hosted privacy developer-tools windows self-hosted rust cross-platform wireguard zero-trust mfa oidc-provider sso iam network-access-control openid-connect ldap firewall-management yubikey webauthn linux macos android ios docker kubernetes

4 sources

Member repositories

RepositoryRoleHealth v2
DefGuard/defguardmain98

For agents

markdown · JSON · MCP: product_card(name="DefGuard/defguard")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem