Overview
True VPN-Level MFA: Unlike other solutions that only apply MFA at the app login, Defguard enforces Multi-Factor Authentication (MFA) directly on the WireGuard® protocol layer for every connection attempt. This unique feature creates a genuine Zero-Trust VPN experience.
Advanced Authentication: The platform supports a wide array of authentication methods, including TOTP, biometrics (FaceID/TouchID), and hardware keys like YubiKey. It also adds post-quantum protection through session-based Pre-Shared Keys (PSK), helping you meet rigorous compliance standards like the EU's NIS2 Directive.
High Performance & Efficiency: Defguard delivers connections that are 2-5 times faster than OpenVPN with significantly lower CPU usage than IPsec. A case study showed one gateway supporting over 150 concurrent users on just 0.5 CPU, proving its efficiency and scalability.
Uncompromising Security: Defguard's architecture allows its core components to run in your secure internal network, which significantly minimizes the attack surface. The entire platform is open-source and written in the memory-safe language Rust for maximum security.
Highlights
- True VPN-Level MFA: Unlike other solutions that only apply MFA at the app login, Defguard enforces Multi-Factor Authentication (MFA) directly on the WireGuard® protocol layer for every connection attempt. This unique feature creates a genuine Zero-Trust VPN experience.
- High Performance & Efficiency: Defguard delivers connections that are 2-5 times faster than OpenVPN with significantly lower CPU usage than IPsec. A case study showed one gateway supporting over 150 concurrent users on just 0.5 CPU, proving its efficiency and scalability.
- Uncompromising Security: Defguard's architecture allows its core components to run in your secure internal network, which significantly minimizes the attack surface. The entire platform is open-source and written in the memory-safe language Rust for maximum security.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Defguard offers no refund policy at the moment,
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This release focuses on easy installation and automatic configuration of Desktop clients (for large environments/rollouts), including:
- Introducing service locations on Windows Desktop clients allowing users to connect to a location that, for example, provides access to a remote Active Directory before the computer's login screen, enabling authentication against AD.
- Introducing Desktop Client Auto Provisioning - on all platforms, additionally for Windows Client we introduced automated enrolment for Active Directory as well as EntraID enrolment.
- Windows Desktop Client has finally an MSI package - with native Wireguard networking based on WireguardNT. Please read the migration docs.
- MacOS Desktop Client introduces native Swift/macOS VPN implementation and is published in Apple macOS Store officially. Migration is required to connect to the currently configured VPN locations. Please read the migration blog post.
- All desktop Clients now have a new MTU setting available.
- Introducing Client Traffic Policy Selection. This lets administrators define whether VPN clients can choose their routing mode or are forced to use a specific traffic policy, such as routing all traffic through the VPN or only predefined traffic.
Additional details
Usage instructions
The guide on deployment can be found here : https://docs.defguard.net/deployment-strategies/amis-and-aws-cloudformation
Support
Vendor support
Defguard offers community support via Matrix (like Discord) support channel and email/ticketing system on support@defguard.net . More info here: https://docs.defguard.net/support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.