Connecting to Instance
In this guide, you will learn how to connect to location. If you haven't added an instance yet, follow this guide.
Connecting to location without MFA
Open Defguard
Click on Instance you want to connect to.

Click "Connect" next to location you want to use.

The first time you connect, app will ask whether you want to route predefined traffic or all traffic. You will see screen like this:

Predefined traffic will only route traffic specified by your administrator.
All traffic will route everything through VPN tunnel.
You can select Remember my choice if you don't want to be asked again.
If you want to change your traffic routing method after your first connection go to this article
Choose your routing method
Confirm
Your phone will need to add new VPN configuration, you will see popup like this:

Please click Allow, without this permission, Defguard cannot establish VPN connection.
If your location does not use MFA, your VPN connection should be established immediately after confirming your routing method.
Some VPN locations require extra security when connecting. This is called MFA (Multi-Factor Authentication). There are two types:
Internal MFA: You confirm your identity directly in the app, for example by entering a code from your Authenticator App or email.
External MFA: You are redirected to a secure login page (like Google or Microsoft) outside the app to confirm your identity.
If your location is using MFA please go to section 3.2 "Connecting to location with MFA
Connecting to location with MFA
Open Defguard
Go to Instances and click Connect next to location you want to use.

The first time you connect, app will ask whether you want to route predefined traffic or all traffic. You will see screen like this:

Predefined traffic will only route traffic specified by your administrator.
All traffic will route everything through VPN tunnel.
You can select Remember my choice if you don't want to be asked again.
If you want to change your traffic routing method after your first connection go to this article
Choose your routing method, and confirm.
Depending on your location settings you will need to authenticate with external or internal MFA.
External MFA
If the VPN location requires OpenID for authentication (external MFA) you will see screen like this:

Click Authenticate with OpenID and you will be redirected to a secure login page (for example Google/Microsoft). Follow the instructions on the screen to log in. After successful authentication please return to Defguard. In the app you will see screen like this:

After successful authentication, return to Defguard Mobile, your connection will be established automatically.
Internal MFA
When connecting with MFA for the first time, you will have the option to select Remember my choice. Select this option if you want to always use this method for this location.
If you are connecting for first time, or if you have not clicked Remember my choice during previous connection, you will need to choose your MFA method.

Choose method configured for your account, and click Connect.
If you're using "Email" method, please enter code sent to your email.
If you're using "Authenticator App", please enter code generated within your authenticator app.
If you don't know how to setup or use your Authenticator App please check this article for detailed information.
After this step, your connection will be established immediately.
Disconnecting from VPN
To disconnect from a VPN location in Defguard:
Open Defguard.
Go to the active instance
Click Disconnect button next to the location you are currently connected to.

After disconnecting, your device will stop sending traffic through the VPN and return to your regular internet connection.