Follow | ASP.NET Web Forms Protection SettingsEnable ASP.NET Web Forms protection on the Windows server hosting your classic ASP.NET application. RdpGuard monitors the Application event log and uses detection rules to identify potentially dangerous requests.
Each matching event with a valid IP address counts as one detection. RdpGuard blocks the address when detections reach the shared limit. To change that limit or the block duration, open Tools, Options, General. The whitelist also applies. Check that events contain the client IPIn Event Viewer, Windows Logs, Application, look for events from ASP.NET with Event ID 1309. Check the event code, exception details and User host address. RdpGuard needs the client's IP address in the event to attribute the request to that client. If the expected events are absent, check your application's ASP.NET health monitoring configuration. This module reads new Application log events, not IIS access logs. For monitoring website access logs, see HTTP protection settings. Behind a reverse proxy, the recorded address may belong to the proxy. This module does not read X-Forwarded-For headers, and the HTTP module's X-Forwarded-For option does not change ASP.NET event processing. Check the recorded address before relying on automatic blocking. By default, blocked addresses lose access to all server ports. If you have configured blocking for selected ports, make sure it includes your website's HTTP or HTTPS ports. Custom Rules for ASP.NET Web Forms ProtectionThe standard rules match these two types of event 1309: event code 3003 with HttpRequestValidationException, or event code 3005 with HttpException and ValidateInputIfRequiredByConfig in the exception details. To edit the rules, select Override standard detection rules in ASP.NET Web Forms Protection Settings, edit Custom detection rules and click Save. Custom rules replace the standard rules. To extend the defaults, keep the two lines above and add your rules on separate lines. Clear the override checkbox to return to the standard rules. ![]() EventData fields Open an event's Details tab and select XML View. Rules refer to the The example below shows the beginning of an event 1309 EventData section. Values are illustrative; comments identify the fields used by the rules. Additional fields after the client IP are omitted.
Rule syntax
For example, this rule counts validation errors only for Use this instead of the broader 3003 rule when you want that restriction. Adding it as another line while retaining the broader rule will not narrow detection, because a match against either line is sufficient. The engine also watches Event ID 1316 for custom-rule scenarios. Its field positions differ from event 1309; the client IP is read from EventData20. Inspect the actual event XML before writing rules for it. The standard rules shown above target the validation errors in event 1309. Choose rules that distinguish suspicious requests from expected application errors. Matching events need a valid client IP, and an event contributes one detection even if it matches more than one rule. | RdpGuard 10.3.7 Free Trial RdpGuard protects:
Our customers say "This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques "Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson "Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford "Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch "Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan "It's a great product - really stopping those RDP attackers :-)" - Dave, UK "First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes Our Other Products |