# DefGuard/defguard

Zero-Trust access management with true WireGuard® 2FA/MFA

Repository: https://github.com/DefGuard/defguard
Canonical: https://ross.abutalabs.com/products/defguard
Homepage: https://defguard.net
Language: Rust
License: NOASSERTION
License Family: other
Topics: multifactor-authentication, openid, openid-connect, vpn, wireguard, yubikey, authentication, forwardauth, oauth, oauth-provider, oauth2-server, oidc, oidc-provider, openid-connect-provider, openvpn, security, keycloak, pritunl, vpn-server, wireguard-ui
Last push: 2026-08-25T11:35:50+00:00

## Health v2 (maintenance only)
Score: 98/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 96, longevity 100
- inputs: {"age_days": 1414, "days_push": 8, "days_rel": 29, "gap_med": 14, "n_releases_24m": 30}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2809, forks 110 (observed 2026-08-28T04:07:23.616056+00:00)

## What it is
Defguard is a self-hosted zero-trust access management platform combining WireGuard VPN with built-in MFA/2FA, identity and access management (OIDC SSO, LDAP/AD sync), and firewall access control. It is written in Rust and ships with desktop, mobile, and CLI clients plus webhooks and a REST API.

## Use cases
- self-host wireguard vpn with mandatory mfa on every connection
- run an internal openid connect provider for sso
- enforce two-factor authentication for vpn logins with yubikey or totp
- manage vpn users and groups synced from ldap or active directory
- apply per-user firewall rules across multiple vpn gateways
- onboard remote employees with self-service device enrollment
- stream audit logs to a siem

## When to choose
- you want a unified, fully self-hosted alternative to Tailscale/Pritunl/Keycloak+VPN stacks
- you need connection-level MFA for WireGuard, not just portal login MFA
- you require zero-trust network access with per-location ACLs and audit trails
- you want open-source core with published SBOMs and pentest reports

## When to avoid
- you need only a simple point-to-point WireGuard tunnel without identity management
- you require cloud-managed VPN with no self-hosting overhead
- you need features like HA, LDAP sync, or SIEM streaming but cannot use the paid tiers
- your infrastructure is not Linux/BSD-based for gateways

## Facets
- artifact type: service
- maturity: active
- function: auth, authorization, vpn, security, self-hosted, api-gateway, webhook
- domain: security, networking, self-hosted, privacy, developer-tools
- platform: windows, self-hosted, rust, cross-platform
- tags: wireguard, zero-trust, mfa, oidc-provider, sso, iam, network-access-control, openid-connect, ldap, firewall-management, yubikey, webauthn, linux, macos, android, ios, docker, kubernetes

## Member repositories
- DefGuard/defguard (main) score 98

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:23.616056+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T08:14:24.220972+00:00, confidence not recorded.
  - readme: https://github.com/DefGuard/defguard (fetched 2026-08-28T04:07:23.616056+00:00, sha 8806be0989b4)
  - homepage: https://defguard.net (fetched 2026-08-29T09:54:12.576562+00:00, sha 3aa1024cb137)
  - site_page: https://docs.defguard.net/ (fetched 2026-08-29T09:54:12.581827+00:00, sha eee50735eb93)
  - site_page: https://defguard.net/pricing (fetched 2026-08-29T09:54:12.579828+00:00, sha 57788ed1d67b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
