defguard
⌘Ctrlk
defguard
  • Welcome
  • Getting help
    • About Defguard
    • Features overview
    • One-line install script
    • Overview
    • Zero-Trust VPN with 2FA/MFA
    • Remote user enrollment
    • Internal SSO (OpenID Connect Provider)
    • External SSO/OpenID providers
    • LDAP and Active Directory integration
    • Firewall
    • Network devices
    • Activity & Audit logs
    • Notifications
    • Integrations
    • OPNSense Configuration
    • SSH Authentication
    • Forward auth
    • User SNAT bindings
    • Service locations
    • Desktop client auto-provisioning
    • Static IP assignment
    • Certificate management
    • Overview
    • Deploying to Production
    • Migration guides
    • Hardware, OS, network and firewall recommendations
    • Standalone package based installation
    • Docker Compose
    • Kubernetes
    • Terraform
    • OVA
    • Amazon Machine Image (AMI)
    • Configuration
    • Running Gateway on OPNsense firewall
    • Running Gateway on VyOS
    • Reverse Proxy configuration using NGINX
    • High Availability and Failover
    • Updating and version compatibility
    • Using a userspace WireGuard implementation
    • Pre-production and development releases
    • Health check
    • Production deployment verification guide
    • Linux Kernel WireGuard tuning
    • Programmatic gateway adoption
    • Purchasing and using the license
    • Overview
    • Mobile Client
    • Desktop Client
    • CLI Client
    • Other WireGuard® Clients
    • Password change / Reset
    • Enrollment & Onboarding
    • Setting up 2FA/MFA
    • How to submit an issue
    • Sending support information
    • Troubleshooting Guides
      • Core
      • Desktop Client
      • Mobile Client
      • Edge Component
      • Gateway
      • TOTP / email codes for MFA do not work
      • WebAuthn security keys
      • Can access VPN but not local network or internet
      • How to verify the VPN is working
      • Testing VPN speed
    • Server migration and licence transfer
    • Initial Setup Wizard: setting up from scratch
    • Migrating from Defguard 1.6 to 2.0
    • Adding Edge component
    • Defguard Compliance
    • Secure by design
    • Architecture
    • Architecture Decision Records
    • Client application feature compatibility
    • Defguard Open Organisation
    • BoringTun
    • Contributing
    • Environment setup
Powered by GitBook
  1. Support

Troubleshooting Guides

Before contacting support, check whether your problem is covered here.

Before contacting support, please see if the answer cannot be found here.

Issues are grouped by component. Each linked page covers one specific problem.

Core

  • h2 protocol error from reverse proxy

  • Unable to sign in with correct credentials

  • User lost access to their 2FA methods

  • Enrollment URL Changed

Desktop Client

  • Failed to configure DNS (Linux)

  • Failed to parse IP address

  • Disconnecting shows "Connection failed" (Linux / NetworkManager)

  • resolvconf not found (Debian)

  • Unix socket does not exist (Linux)

  • Disconnected after MFA timeout

  • Client connects but cannot reach VPN servers (MTU)

  • Desktop client real-time / auto sync does not work

  • Windows client unable to connect

  • "All traffic" connection issues

  • Windows installer exit codes

  • High disk usage

  • MFA location disconnected after X-time

  • Unix socket permission error on connect (Linux)

Mobile Client

  • Android "Failed host lookup" error

Edge Component

  • There was a network error. Can't reach Edge

Gateway

  • No buffer space available

No category

  • TOTP / email codes for MFA do not work

  • WebAuthn security keys

  • Can access VPN but not local network or internet

  • How to verify the VPN is working

PreviousMobile clientNextCore

Was this helpful?

  • No category

Was this helpful?