In-tunnel MFA #2175
Replies: 2 comments
-
|
Hello, I think that the flow that you are describing could be achieved by setting up two VPN locations in Defguard as follows:
This of course would be not so user friendly since it would require establishing two connections at once in a correct order and updates of Client's configuration wouldn't work without a VPN tunnel/access to Edge (since the Edge would be hidden), but meets your requirement of exposing only Wireguard. |
Beta Was this translation helpful? Give feedback.
-
|
Hi, |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
I was trying to determine to what extent I could use defguard to provide VPN access where:
As far as I was able to tell from the code in defguard_core, there doesn't seem to be a provision for routing the MFA flows in-tunnel. Am I completely mistaken, or is there some other approach that achieves the "only wireguard is exposed to the Internet" criterion?
Thanks for your insights!
Beta Was this translation helpful? Give feedback.
All reactions