Overview
True VPN-Level MFA: Unlike other solutions that only apply MFA at the app login, Defguard enforces Multi-Factor Authentication (MFA) directly on the WireGuard® protocol layer for every connection attempt. This unique feature creates a genuine Zero-Trust VPN experience.
Advanced Authentication: The platform supports a wide array of authentication methods, including TOTP, biometrics (FaceID/TouchID), and hardware keys like YubiKey. It also adds post-quantum protection through session-based Pre-Shared Keys (PSK), helping you meet rigorous compliance standards like the EU's NIS2 Directive.
High Performance & Efficiency: Defguard delivers connections that are 2-5 times faster than OpenVPN with significantly lower CPU usage than IPsec. A case study showed one gateway supporting over 150 concurrent users on just 0.5 CPU, proving its efficiency and scalability.
Uncompromising Security: Defguard's architecture allows its core components to run in your secure internal network, which significantly minimizes the attack surface. The entire platform is open-source and written in the memory-safe language Rust for maximum security.
Highlights
- True VPN-Level MFA: Unlike other solutions that only apply MFA at the app login, Defguard enforces Multi-Factor Authentication (MFA) directly on the WireGuard® protocol layer for every connection attempt. This unique feature creates a genuine Zero-Trust VPN experience.
- High Performance & Efficiency: Defguard delivers connections that are 2-5 times faster than OpenVPN with significantly lower CPU usage than IPsec. A case study showed one gateway supporting over 150 concurrent users on just 0.5 CPU, proving its efficiency and scalability.
- Uncompromising Security: Defguard's architecture allows its core components to run in your secure internal network, which significantly minimizes the attack surface. The entire platform is open-source and written in the memory-safe language Rust for maximum security.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
Defguard offers no refund policy at the moment,
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
- Mobile Clients
- External SSO/IdP MFA support on desktop (Microsoft, Google etc.)
- MultiFactor authentication for WireGuard on Desktop using mobile client
Additional details
Usage instructions
The guide on deployment can be found here : https://docs.defguard.net/deployment-strategies/amis-and-aws-cloudformationÂ
Support
Vendor support
Defguard offers community support via Matrix (like Discord) support channel and email/ticketing system on support@defguard.net . More info here: https://docs.defguard.net/supportÂ
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.