Defguard Edge

Defguard Edge is the public-facing proxy component of Defguard, a self-hosted Zero-Trust WireGuard VPN platform.

  • Network Services
  • Other
  • Productivity
  • Tools & Utilities
Defguard Edge is the public-facing proxy component of Defguard, a self-hosted Zero-Trust WireGuard VPN platform. It exposes a public REST API for identity verification, multi-factor authentication, and network access control, serving as the remote-access gateway for self-hosted infrastructure.

Platform availability

Available on 1 of 6 install platforms

  • Unraid
  • TrueNAS (not listed)
  • Umbrel (not listed)
  • ZimaOS (not listed)
  • Proxmox (not listed)
  • Helm (not listed)

Also on GitHub

Health score

62/100 Good

Maintained
100last commit 33 days ago
Popular
2211 GitHub stars
Easy to install
351 install platform, install notes, Docker image
Light to run
No data

Based on 3 of 4 factors.

How is this calculated?

A 0-100 score computed nightly from four factors: maintained (40%: recent commits and steady activity), popular (25%: GitHub stars, log scale), easy to install (20%: platforms, install notes, setup guides, Docker image) and light to run (15%: minimum RAM, ARM support). Factors without data are left out and the rest are rescaled.

Availability: platform listings confirmed today

GitHub stars
11
Open issues
17
Last commit
2026-09-03
Latest release
v2.1.0
Activity
stale

Checked 7 days ago - source: GitHub (DefGuard/proxy)

Resources & Compatibility

Requirements not published yet.

Checked 7 days ago - source: Docker Hub image tags and published docs

First-install notes

  • Install the Defguard proxy package Run 'sudo apt install defguard-proxy' (sudo asks for admin permission) to add the Defguard package you need. If the package you need is missing, that Defguard component won’t be installed and its service won’t be available. source
  • Check Defguard containers and ports If you run Defguard with Docker (a tool that runs apps in isolated containers), use 'docker ps' to confirm defguard-db-1 and defguard-core-1 are up. Those containers show ports 5432 (database), 8000 (Defguard core), and 50055 (proxy), so allow those ports if other devices need to connect. source
  • Set up NGINX if using a reverse proxy If you plan to put Defguard behind NGINX (a reverse proxy that forwards web requests), run 'apt install nginx certbot', then enable and start NGINX. Without NGINX running, web requests to your Defguard address won’t be forwarded and HTTPS (secure web) certificate setup can fail. source

Fetched 7 days ago - each note links to its source

Alternatives (10)

  • Fossorial Pangolin - Open-source identity-based remote access platform using WireGuard, offering unified management, tunneled connections, granular access contr…
  • LogMeIn Hamachi - Seamlessly connects devices and networks, extending LAN-like connectivity to mobile users and teams with a secure, hosted VPN service.
  • NetBird - NetBird is an open-source Zero Trust networking platform that makes it easy for engineers to create fast, secure, and private networks with…
  • OpenVPN Connect - OpenVPN Connect provides flexible VPN solutions to secure your data communications, whether it's for Internet privacy, remote access for em…
  • Outline VPN - Journalists need safe access to information to research issues, communicate with sources, and report the news.
  • Rayfish - A peer-to-peer mesh VPN with zero infrastructure.
  • SoftEther VPN - SoftEther VPN ("SoftEther" means "Software Ethernet") is one of the world's most powerful and easy-to-use multi-protoco…
  • Tailscale - Private networks made easy.
  • WireGuard - WireGuard®(https://www.wireguard.com/) is an extremely simple yet fast and modern VPN that utilizes state-of-the-art cryptography.
  • ZeroTier - Zerotier is an open source, cross-platform virtual LAN / VPN

Checked 7 days ago - source: AlternativeTo

Common questions

How do I install the Defguard proxy package?

Run sudo apt install defguard-proxy. If the package is missing, that Defguard component will not be installed and its service will not be available.

Which ports should I open when running Defguard in Docker?

Check that defguard-db-1 and defguard-core-1 are up, then allow ports 5432 for the database, 8000 for Defguard core, and 50055 for proxy if other devices need to connect.

What should I do before putting Defguard behind a reverse proxy?

Install NGINX and certbot, then enable and start NGINX. Without NGINX running, web requests to Defguard will not be forwarded and HTTPS certificate setup can fail.

Answers sourced from docs.defguard.net, docs.defguard.net, docs.defguard.net

Community

Collected yesterday - public community threads