π Welcome to Defguard Desktop Client 2.1 π
With this release of the Defguard Desktop Client, we introduce a brand-new interface, redesigned from scratch. It brings two separate views: a minimalistic βtrayβ version for day-to-day activities and a full βwindowβ version for advanced tasks.
|
|
The new client is also designed to work with the latest Defguard 2.1 server capabilities. The version makes the device itself part of the access decision - admins define the security criteria a machine must meet, and non-compliant endpoints simply can't establish a connection - and it ships a rebuilt Desktop Client whose tray mode gets your users onto the VPN in two clicks.
π‘οΈ Device Posture verification - client and OS version, security updates, AD membership, antivirus, disk encryption,
β¨οΈ defguard-client - drive the client from a terminal, MFA included,
π Allowed IPs generated from Firewall Rules - least-privilege configs, no network recon,
π§ service locations on Linux - Always-on VPN from system boot,
π§© official support for running Defguard Gateway on VyOS as a container.
More details with videos in this blogpost.
π Installation packages for the new client are available in the release assets. For macOS users, it is also available in the App Store.
π As always, this release was pentested by ISEC, together with Striga.AI - all major findings were fixed before release. The full report will be published on our pentesting page.
π Documentation for the new features:
- Device Posture verification
- CLI client
- Generate Allowed IPs from Firewall Rules
- Service locations
- Running Gateway on VyOS
π If you would like to test Defguard, we offer a quick and easy One-line install script.
β οΈ Device Posture verification and service locations are Enterprise features.
Business features require free registration.
π https://defguard.net/get-free-business/
Once registered, simply apply your license to your instance.
We want to get as much feedback as possible, so we encourage you to:
π¬ open a GitHub discussion
πͺ² report any missing features or bugs as issues
What's Changed
- Preserve old package versions on APT repository by @jakub-tldr in #821
- Fix blocking windows syscalls by @t-aleksander in #825
- Windows: always register the deep-link by @moubctez in #827
- Clear TOTP code input on MFA failure by @jakub-tldr in #857
- Handle error on session end & regenerate QR on session end by @jakub-tldr in #863
- Bump version to 1.6.9 and disable Windows workflow by @moubctez in #864
- Report pre-release version by @t-aleksander in #862
- Device posture by @moubctez in #865
- fix(nix): handle various DNS setups in nix package by @wojcik91 in #867
- alpha client v2 by @filipslezaklab in #866
- add mfa connect via oidc provider by @filipslezaklab in #875
- connect mfa via mobile confirmation in tray ui by @filipslezaklab in #877
- Implement posture checks by @j-chmielewski in #871
- Better windows positioning by @moubctez in #879
- Report number of days since last security update by @t-aleksander in #880
- tray update - windows 11 window management by @filipslezaklab in #881
- Optimise VPNExtension by @moubctez in #883
- Chocolatey update workflow by @jakub-tldr in #873
- fix window spawning behaviour by @filipslezaklab in #894
- Handle posture checks in new UI by @j-chmielewski in #882
- rounded corners for tray window on macos by @filipslezaklab in #895
- Sync code with mobile client by @moubctez in #896
- remove extra window decorations from macos tray window by @filipslezaklab in #897
- migrate nix package build process to crane by @wojcik91 in #876
- Fix posture checks on windows by @j-chmielewski in #898
- Fix macos new UI window by @moubctez in #900
- Fix deep link handling by @filipslezaklab in #903
- fix single instance plugin deep link handling by @filipslezaklab in #904
- macOS: handle app re-open by @moubctez in #905
- Ready for 1.6.9 by @moubctez in #906
- Fix anti-virus posture report by @j-chmielewski in #907
- Posture errors layout by @j-chmielewski in #909
- update app icon and tray icon by @filipslezaklab in #908
- macOS: new UI window should not be resizeable by @moubctez in #929
- Mfa loader by @j-chmielewski in #928
- update wireguard_rs dependency by @wojcik91 in #930
- Fix posture errors icon and spacing by @j-chmielewski in #931
- split the Rust code into smaller, Tauri-independent crates in preparation for adding CLI by @wojcik91 in #933
- Posture checks CI by @j-chmielewski in #945
- replace full view with new ui by @filipslezaklab in #948
- Fix new UI by @moubctez in #951
- Add --version command to all binaries by @wojcik91 in #952
- Full view connect by @filipslezaklab in #956
- [New UI] Updates view by @t-aleksander in #957
- [New UI] Log view by @t-aleksander in #953
- fix compact view spacing by @filipslezaklab in #960
- [New UI] App settings by @t-aleksander in #954
- implement base CLI for Linux & Windows by @wojcik91 in #949
- add external OIDC MFA for the CLI client by @wojcik91 in #966
- Optional summary field by @t-aleksander in #969
- NixOS module fix by @wojcik91 in #972
- Build defguard-cli tar archive by @j-chmielewski in #973
- add workflow for building dg packages for Alma Linux 9 by @wojcik91 in #976
- Sharing state between active windows by @filipslezaklab in #975
- update dev by @filipslezaklab in #978
- implement mobile auth for CLI by @wojcik91 in #974
- [New UI] Location details by @t-aleksander in #980
- Update client tray icon by @filipslezaklab in #979
- Add tunnel wizard by @filipslezaklab in #981
- change mfa factor in connect process by @filipslezaklab in #982
- add auto start openid mfa preference to app config by @filipslezaklab in #983
- display app version via tauri api by @filipslezaklab in #984
- Dev update by @filipslezaklab in #986
- macOS CLI by @moubctez in #988
- Check response status before version verification by @j-chmielewski in #989
- Fix window close on macOS by @moubctez in #992
- Build and sign windows bundle by @j-chmielewski in #991
- CLI config polling by @j-chmielewski in #993
- add menu and snackbars by @filipslezaklab in #996
- fix Nix hash update workflow by @wojcik91 in #997
- Cli connection monitoring by @j-chmielewski in #994
- Custom window decoration for windows / macos by @filipslezaklab in #1000
- fix windows window decoractions by @filipslezaklab in #1002
- macOS installer by @moubctez in #1001
- attempt to fix macos inconsistent buttons positioning by @filipslezaklab in #1004
- merge main to dev by @wojcik91 in #1005
- Always on service locations on linux by @j-chmielewski in #999
- merge dev to release by @filipslezaklab in #1013
- add actions menu to overview page by @filipslezaklab in #1011
- Better errors by @filipslezaklab in #1015
- fix confirm modal close after submit success by @filipslezaklab in #1019
- Match linux interfaces by pubkey by @j-chmielewski in #1014
- fix linux height by @filipslezaklab in #1023
- Pin runner on macOS by @moubctez in #1026
- fix tray view opening with no locations by @wojcik91 in #1024
- Posture checks for macOS by @moubctez in #1027
- E2E tests by @jakub-tldr in #1012
- Run Linux posture checks by @moubctez in #1028
- make password step in enrollment optional by @wojcik91 in #1018
- fix creating a new wireguard tunnel & other tunnel related issues by @wojcik91 in #1030
- Separate keychain for builds by @moubctez in #1031
- Fix split DNS on macOS by @moubctez in #1033
- fix delete last selectable by @filipslezaklab in #1034
- add enrollment markdown message from core by @filipslezaklab in #1036
- Edge communication error by @jakub-tldr in #1045
- Welcome window by @filipslezaklab in #1043
- Change way of displaying edge error in tray view by @jakub-tldr in #1048
- Connect from tray by @moubctez in #1047
- Service log rotation by @j-chmielewski in #1049
- Update wireguard-rs by @moubctez in #1050
- migrate connection-related logic to backend by @wojcik91 in #1040
- style fixes by @filipslezaklab in #1057
- Workaround for nvidia and wayland webkitgtk issues by @j-chmielewski in #1060
- Integrate command line with main app by @moubctez in #1058
- Implement hardened linux disk encryption posture signal by @j-chmielewski in #1061
- show errors during enrollment wizard by @wojcik91 in #1063
- Fix service logs file extension by @j-chmielewski in #1065
- old ui project removed by @filipslezaklab in #1068
- Linux posture ci by @j-chmielewski in #1067
- Fix stats query by @j-chmielewski in #1072
- handle WireGuard tunnels being disabled in core settings by @wojcik91 in #1070
- show Edge communication errors for posture-check-only locations by @wojcik91 in #1074
- Change component in APT by @jakub-tldr in #1076
- Posture check authenticates the device with polling token by @j-chmielewski in #1075
- Fix macOS pipeline by @jakub-tldr in #1077
- fix tunnel events by @filipslezaklab in #1082
- Nightly builds by @jakub-tldr in #1083
- Service location posture checks by @j-chmielewski in #1078
- disconnect connected service-location tunnels after posture rejection by @j-chmielewski in #1086
- SBOM ignore policy by @jakub-tldr in #1085
- fix posture tests and compile-checks by @j-chmielewski in #1087
- Fix release ci by @j-chmielewski in #1088
- Fix wireguard tunnels config/labels & E2E tests by @jakub-tldr in #1093
- Fix persistent keep alive (sec) field by @jakub-tldr in #1095
- Update dependencies and fix build on macOS and Windows by @moubctez in #1096
- Fix nightly by @moubctez in #1097
- ignore-version-mismatches by @moubctez in #1100
- fix compact-view connection race by @j-chmielewski in #1106
- Show correct "active mfa" label by @jakub-tldr in #1114
- Display correct routing labels in CLI/UI by @jakub-tldr in #1116
- Block connect button by @moubctez in #1115
- Add nightly for dev by @jakub-tldr in #1118
- Enable "What's new" screen by @jakub-tldr in #1120
- Adjust "What's new" window by @jakub-tldr in #1122
- DG2608-11: [desktop] Malformed peer request terminates the privileged service by @jakub-tldr in #1124
- DG2608-10: [desktop] Unvalidated instance identifier enables privileged file operations by @jakub-tldr in #1126
- Allow only one all-traffic connection by @moubctez in #1107
- fix Allowed IPs validation & normalize Allowed IPs for routing configuration by @wojcik91 in #1123
- Merge main to 2.1 by @t-aleksander in #1128
- Fix opening a deep-link by @moubctez in #1132
- fix handshake formatting by @filipslezaklab in #1134
- merge release branch into stable branch (2.1) by @t-aleksander in #1136
- Add spaces to match design by @jakub-tldr in #1137
- Trigger pipelines on stable branch by @t-aleksander in #1138
- Fix stats refresh by @t-aleksander in #1139
Full Changelog: v1.6.8...v2.1.0

