For the complete documentation index, see llms.txt. This page is also available as Markdown.

Client behaviour customization

Navigate to Settings → General → Client behaviour.

Client configuration Permissions

Options that affect ability to interact with device management for users.

Device management

This option determines whether users can create and manage their own devices.

If disabled, only administrators can manage devices in user profiles. Users will retain the devices they already have but will not be able to add or manage new ones.

If disabled from the beginning, users will only be able to configure a single device during the enrolment process.

WireGuard configuration

This option disables ability to create native WireGuard configurations for users. This way users can only enroll new devices via Defguard client applications.

Client traffic rules

One of the unique features of Defguard desktop client is the ability for users to choose whether to route only predefined network traffic or all traffic from their device through a connected VPN location.

However, in some cases administrators may want to enforce a specific behaviour - allowing access only to predefined traffic or requiring all traffic to pass through the VPN.

The Client Traffic Policy setting enables administrators to control this behaviour as needed. The available options are:

  • None - Users can freely choose between routing predefined traffic or all traffic through the VPN.

  • Disable all traffic - Only predefined traffic is allowed, the "All traffic" option is disabled for users.

  • Force all traffic - All traffic is routed through the VPN, the "All traffic" option is enforced and cannot be changed by users.

Last updated

Was this helpful?