This guide explains how to install and configure WireGuard with an MFA overlay using Defguard. The setup consists of three main steps, to be executed after requesting a token from ETRO_ICT@vub.be.
Once these steps are completed, your device will be ready to connect to the VPN using WireGuard with MFA authentication.
Go to:
Log in with your ETROVUB credentials. Use only your username, without @etrovub.be.

Click Edit profile in the top-right corner.
Enable TOTP — Time-Based One-Time Password — as your two-factor authentication method by clicking on the gear wheel next to TOTP. You may need to do this twice.

Use an authenticator app, or equivalent, to register Defguard by scanning the QR code. Once registered, enter the one-time password code to confirm.


Recovery codes are not strictly necessary, as ICT can intervene if needed. Click I have saved my codes.
Do not forget to save your changes.
If you are logged out, log back in using your authentication code.
Go to::
https://enroll.etrovub.be
Start the enrollment process.

Click Launch enrollment.
You will be asked to enter the token sent by your administrator.
Download and install the client for your operating system.

Once the client has been installed, open it
In the Defguard client, click Add instance in the left menu bar.

Enter the URL and token you received from your administrator.
For each supplementary device please request a new token at ETRO_ICT@vub.be

Choose a name for your device.

Once the instance has been created, click Connect for the Brussels location.

Use MFA to authenticate.

You are now successfully connected.

Good luck! You are virtually there!
Perhaps one of the remedies below helps