Have you looked at authpf? It requires opening an ssh connection (with a 
separate account) to authorize passage through pf. That, combined with pf 
controlling access to wg might just do what you need. It isn’t exactly what 
you’re looking for, but you might be able to make something that would work for 
their requirements.

https://man.openbsd.org/authpf.8

-DaveP

On Tue, Sep 29, 2026, at 12:39, Ronny Machado wrote:
> Yes, that's exactly my problem...
>
>
> --
> Ronny Machado C.
>
> IT Consultant
> HP-UX Certified Systems Administrator
> Oracle Linux Certified Implementation Specialist
> Oracle MySQL Enterprise Certified Implementation Specialist
>
> https://sysops.cl
> +56 9 7519 9262
>
> Sent with Proton Mail <https://proton.me/mail/home> secure email. 
>
> On Tuesday, September 29th, 2026 at 3:37 PM, Janne Johansson 
> <[email protected]> wrote:
>> Den tis 29 sep. 2026 kl 19:30 skrev Ronny Machado <[email protected]>:
>>> Yeah...I know WG doesn't support 2FA...so maybe some kind of "wrapper"? 
>>> I'll look IKEv2 tho
>> 
>> One way is to treat it like cheap hotel wifi, where the wg tunnel is the 
>> wifi, then you put a captive portal behind it, only reachable after you auth 
>> to wg, and the portal auth becomes your second-factor.
>> 
>> Now your "problem" is not wedging in 2FA in wg, but only "how to make a 
>> captive portal" as a standalone issue.
>> 
>> -- 
>> May the most significant bit of your life be positive.

Reply via email to