You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/content/blog/defguard-release.mdx
+2-2Lines changed: 2 additions & 2 deletions
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: "True Zero-Trust WireGuard® VPN with 2FA/MFA - defguard security paltform released by teonite"
2
+
title: "True Zero-Trust WireGuard® VPN with 2FA/MFA - Defguard security paltform released by teonite"
3
3
publishDate: 2023-05-12
4
4
description: "Defguard offers a unique combination of security-related functionalities from identity management (OpenID/OAuth2/LDAP) to VPN (Wireguard) to other features (Multi-Factor Authentication, Yubikey provisioning, Web3, Webhooks, etc.)."
"Today is my 42nd birthday and my present for everyone is our open-source security army knife platform", Robert Olejnik - defguard founder
12
+
"Today is my 42nd birthday and my present for everyone is our open-source security army knife platform", Robert Olejnik - Defguard founder
13
13
14
14
It doesn’t matter if you are looking for an on-premise security infrastructure for your home, a small office, or a large enterprise – most likely [Defguard](https://defguard.net/) has all the features you need and is very easy to set up. It also has a great and clean UI that business owners can and like to use (not only admins).
Copy file name to clipboardExpand all lines: src/content/blog/self-hosted-vpn-private-cloud-acquinox-defguard.mdx
+5-5Lines changed: 5 additions & 5 deletions
Original file line number
Diff line number
Diff line change
@@ -35,10 +35,10 @@ When Kacper, Venture Partner and Security lead joined Acquinox, he knew right aw
35
35
This applied across the board, including document storage, communication infrastructure, internal systems, and access control. Balancing modern usability with enterprise-grade security in a self-hosted setup presented a unique set of technical and operational challenges.
36
36
37
37
38
-
> “Trying to solve the remote access problem, I’ve looked into popular solutions like Tailscale, Netbird or Firezone offering VPN management with Wireguard, but their focus lies in the cloud/SaaS and does not fit our scenario perfectly. Then I’ve discovered defguard which is designed with private cloud use cases in mind and offers built in identity and SSO. With defguard documentation and support the evaluation was fast and easy.”
38
+
> “Trying to solve the remote access problem, I’ve looked into popular solutions like Tailscale, Netbird or Firezone offering VPN management with Wireguard, but their focus lies in the cloud/SaaS and does not fit our scenario perfectly. Then I’ve discovered Defguard which is designed with private cloud use cases in mind and offers built in identity and SSO. With Defguard documentation and support the evaluation was fast and easy.”
39
39
> — *says Kacper Wiśniewski*
40
40
41
-
Acqinox did a quick evaluation, with defguard support, and confirmed that the solution fits perfectly into their private cloud strategy.
41
+
Acqinox did a quick evaluation, with Defguard support, and confirmed that the solution fits perfectly into their private cloud strategy.
42
42
43
43
44
44
## Defguard provides the fundamental security layer for Acquinox
@@ -50,13 +50,13 @@ To meet internal security and operational requirements, the investment firm depl
50
50
51
51
Acquinox leveraged Defguard VPN enterprise features including full stack identity and SSO. This approach minimized the maintenance burden and deployment costs. It solved a lot of integration issues and external tools dependencies.
52
52
53
-
The aspect of vendor lock-in was not overlooked - because of the fact that defguard supports third party identity and SSO providers, Acquniox can switch easily to other options whenever there is a need.
53
+
The aspect of vendor lock-in was not overlooked - because of the fact that Defguard supports third party identity and SSO providers, Acquniox can switch easily to other options whenever there is a need.
54
54
55
-
Other decision factors in choosing Defguard were its support for **built-in** multi-factor authentication (MFA) that operates on WireGuard protocol level. The fact that it’s handled by defguard on-prem instance means, that unlike other VPN solutions, no data ever leave Acquinox infrastructure. Multifactor authentication soon will be mandatory and required from many (especially financial) organisations by **NIS2 and DORA regulations**.
55
+
Other decision factors in choosing Defguard were its support for **built-in** multi-factor authentication (MFA) that operates on WireGuard protocol level. The fact that it’s handled by Defguard on-prem instance means, that unlike other VPN solutions, no data ever leave Acquinox infrastructure. Multifactor authentication soon will be mandatory and required from many (especially financial) organisations by **NIS2 and DORA regulations**.
56
56
57
57
## The Result
58
58
59
-
That design and architecture proposed by defguard allowed Acquinox to use it as a backbone of the entire private cloud infrastructure. Now Acquinox can securely connect to multiple online environments with the most secure VPN solution while maintaining full privacy.
59
+
That design and architecture proposed by Defguard allowed Acquinox to use it as a backbone of the entire private cloud infrastructure. Now Acquinox can securely connect to multiple online environments with the most secure VPN solution while maintaining full privacy.
When combining with [defguard](https://github.com/DefGuard/defguard) VPN & SSO you can have multiple defguard instances (sites/installations) and multiple Locations (VPN tunnels in that location/site) in <strong>one client</strong>! If you are an admin/devops - all your customers (instances) and all their tunnels (locations) can be in one place!
6
+
When combining with [defguard](https://github.com/DefGuard/defguard) VPN & SSO you can have multiple Defguard instances (sites/installations) and multiple Locations (VPN tunnels in that location/site) in <strong>one client</strong>! If you are an admin/devops - all your customers (instances) and all their tunnels (locations) can be in one place!
Copy file name to clipboardExpand all lines: src/content/core-features/desktop-client.mdx
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -10,4 +10,4 @@ defguard client is the only open source client to support **Multi-Factor Authent
10
10
- Secure and remote [user enrollment](https://docs.defguard.net/help/remote-user-enrollment) - setting up password, automatically configuring the client for all VPN Locations/Networks
11
11
-[Onboarding](https://docs.defguard.net/help/remote-user-enrollment/user-onboarding-after-enrollment) - displaying custom onboarding messages, with templates, links …
12
12
- Ability to route **predefined VPN traffic or ALL traffic through the VPN**
13
-
- Supports not only defguard instances, but any WireGuard® VPN sever (just import your config)
13
+
- Supports not only Defguard instances, but any WireGuard® VPN sever (just import your config)
Copy file name to clipboardExpand all lines: src/content/core-features/identity.mdx
+2-2Lines changed: 2 additions & 2 deletions
Original file line number
Diff line number
Diff line change
@@ -3,10 +3,10 @@ title: SSO & Identity Provider
3
3
order: 3
4
4
---
5
5
6
-
As a core principle, defguard is based and built on open standards with [OpenID Connect](https://openid.net/connect/) based Identity Provider with Multi-Factor Authentication to secure your apps and VPNs:
6
+
As a core principle, Defguard is based and built on open standards with [OpenID Connect](https://openid.net/connect/) based Identity Provider with Multi-Factor Authentication to secure your apps and VPNs:
7
7
8
8
-**Time-based One-Time Password** Algorithm (TOTP - e.g. Google Authenticator)
9
9
-**Email** tokens
10
10
-**WebAuthn / FIDO2** - for hardware key authentication support and **Passkeys**
11
11
12
-
Already using **Google/Microsoft or other OpenID Provider?**, defguard supports [external OpenID provider login & registration](https://docs.defguard.net/enterprise/external-openid-providers).
12
+
Already using **Google/Microsoft or other OpenID Provider?**, Defguard supports [external OpenID provider login & registration](https://docs.defguard.net/enterprise/external-openid-providers).
Copy file name to clipboardExpand all lines: src/content/core-features/integrations.mdx
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -6,4 +6,4 @@ order: 8
6
6
Automate processes that involve your organization's data using:
7
7
8
8
-**API** - all functionalities are exposed via REST API
9
-
-**Webhooks** - outgoing webhooks are a simple way for defguard to notify your systems of ongoing changes in identity management (user was added, deleted, modified) or hardware key provisioning (easily propagateGPG/PGP or SSH keys to your internal systems)
9
+
-**Webhooks** - outgoing webhooks are a simple way for Defguard to notify your systems of ongoing changes in identity management (user was added, deleted, modified) or hardware key provisioning (easily propagateGPG/PGP or SSH keys to your internal systems)
0 commit comments