This is a patch release for v2.1 that includes the following fixes:
- Trigger firewall update from LDAP/AD sync by @wojcik91 in #3662
- Make DN comparison case insensitive where possible by @t-aleksander in #3709
- Handle escaped commas in LDAP when parsing DNs by @wojcik91 in #3703
- Disallow CIDR of /31 and fix address range handling by @jakub-tldr in #3749
- Add redirect to location wizard by @jakub-tldr in #3752
- Fix gateway trim logic on license expiry by @wojcik91 in #3787
- Include all users coming from LDAP in the synchronization by @t-aleksander in #3798
Full Changelog: v2.1.0...v2.1.1
2.1 makes the device itself part of the access decision - admins define the security criteria a machine must meet, and non-compliant endpoints simply can't establish a connection - and it ships a rebuilt Desktop Client whose tray mode gets your users onto the VPN in two clicks.
🛡️ Device Posture verification - client and OS version, security updates, AD membership, antivirus, disk encryption,
🖥️ a redesigned Desktop Client with tray mode,
⌨️ defguard-client - drive the client from a terminal, MFA included,
🔒 Allowed IPs generated from Firewall Rules - least-privilege configs, no network recon,
🐧 service locations on Linux - Always-on VPN from system boot,
🧩 official support for running Defguard Gateway on VyOS as a container.
More details with videos in this blogpost.
🔐 As always, this release was pentested by ISEC, together with Striga.AI - all major findings were fixed before release. The full report will be published on our pentesting page.
📖 Documentation for the new features:
- Device Posture verification
- CLI client
- Generate Allowed IPs from Firewall Rules
- Service locations
- Running Gateway on VyOS
🚅 If you would like to test Defguard, we offer a quick and easy One-line install script.
⚠️ Device Posture verification, Service locations and Generate Allowed IPs from Firewall Rules are Enterprise features.
Business features require free registration.
👉 https://defguard.net/get-free-business/
Once registered, simply apply your license to your instance.
We want to get as much feedback as possible, so we encourage you to:
💬 open a GitHub discussion
🪲 report any missing features or bugs as issues