VyOS and Defguard Pair Remote Access Controls to Give Teams More VPN OwnershipEditorial image generated for IT Automation Week.

VyOS Networks and Defguard have announced a technology partnership that makes VyOS an officially supported platform for Defguard gateways, combining network operations with identity-aware management for WireGuard-based remote access.

The pairing is aimed at organizations that want to operate remote-access infrastructure with more direct control over where it runs and how it is managed. VyOS supplies routing, firewalling, VPN connectivity, network address translation, high availability and network-operations functions across bare-metal, virtualized, cloud and edge environments. Defguard adds identity and user-access capabilities around the WireGuard protocol.

According to the companies, Defguard provides single sign-on-based access, multifactor authentication at the VPN connection level, device-posture policies and centralized control for remote-access workflows. The partnership makes that stack a supported deployment option for teams using VyOS as the network foundation.

The announcement is a meaningful, though focused, integration rather than a new remote-access product. Its value is architectural: the network layer and the identity layer remain distinct but can be operated together. That can be relevant for organizations trying to avoid combining critical access policy with a closed appliance or a vendor-operated access service.

Remote access has become a more complex operational responsibility as employees, administrators, contractors and automated systems connect from outside traditional network boundaries. A VPN provides encrypted connectivity, but it does not by itself answer which identity should connect, what device requirements apply, or whether the connection should be allowed for a particular role. Identity-aware controls are intended to add those decisions to the access workflow.

VyOS and Defguard said their combination gives customers a way to build remote-access infrastructure that they can operate, verify and own. That is a company position rather than an independently tested result, and the release does not provide performance data, deployment benchmarks or a detailed integration architecture.

Even so, the source gives a useful outline of the responsibilities. VyOS handles the production network functions, including routing, firewalling, VPN connectivity and high availability. Defguard handles SSO, MFA, device posture and centralized access management. For a network team, that separation may make it easier to assign ownership and review changes without treating remote access as a single opaque service.

The approach may also appeal to organizations with requirements around infrastructure sovereignty or strict control of network access. Running gateways on supported platforms can offer greater deployment flexibility across on-premises, cloud and edge environments. But it also means the organization remains responsible for operating the underlying systems, maintaining software, configuring identity providers and defining its own policies.

The partnership does not eliminate the normal work of remote-access security. Administrators still need to decide which users and devices are eligible, keep identity and MFA settings current, monitor VPN and network logs, and plan for availability and incident response. The release makes no claims about automated remediation or managed operations.

For end users, the potential benefit is a remote-access experience governed by centralized identity controls rather than a separate manual process. For IT teams, the more important benefit is the ability to join network and identity controls in an open, supported architecture while retaining operational ownership of the infrastructure. Whether that is preferable to a managed alternative will depend on an organization’s internal expertise, compliance needs and tolerance for running the service itself.

Leave a Reply

Your email address will not be published. Required fields are marked *

Latest News