RdpGuard GeoIP Blocking - control access to your Windows server by country.
RdpGuard
Intrusion prevention system for your Windows Server
 

RdpGuard GeoIP Blocking

GeoIP blocking overview

RdpGuard GeoIP blocking lets you deny access from selected countries or allow access only from selected countries. Country IP ranges are updated automatically.

Use Advanced GeoIP settings to apply country restrictions to all ports or selected ports on your Windows server.

Enable GeoIP blocking

  1. Click Tools, Options:

    RdpGuard Tools menu with Options highlighted
    Open Tools, Options.
  2. In the Options dialog, select the GeoIP tab and check Enable GeoIP:

    RdpGuard Options with Enable GeoIP checked
    Enable GeoIP on the GeoIP tab.
  3. Choose whether to block selected countries or allow selected countries, then follow the steps below for that mode.

Block selected countries

In Deny mode, GeoIP blocks the countries you select. It does not restrict other countries.

  1. Select Deny connections from selected countries:

    GeoIP in Deny mode with selected countries in the list
    Deny connections from selected countries.
  2. Click Add.

    The Add countries dialog will open:

    Add countries dialog with multiple countries selected
    Select one or more countries, then click Add.
  3. Select the countries you want to block and click Add.

  4. Click Save in the Options dialog to apply your changes.

Allow selected countries

In Allow mode, GeoIP allows the countries you select and blocks other countries. You can also add specific IP addresses and ranges as exceptions.

  1. Select Allow connections only from selected countries:

    GeoIP in Allow mode with selected countries in the list
    Allow connections only from selected countries.
  2. Click Add, Allowed country.

    The Add countries dialog will open:

    Add countries dialog with multiple countries selected
    Select one or more countries, then click Add.
  3. Select the countries you want to allow and click Add.

  4. Click Save in the Options dialog to apply your changes.

Test mode enforces country restrictions until the next system restart. Restarting the computer removes these temporary GeoIP restrictions. Other firewall and RdpGuard rules still apply.

Allow specific IP addresses and ranges

In Allow mode, add IP addresses, ranges or CIDRs that should be allowed regardless of the selected countries. These entries bypass GeoIP country restrictions, but can still be blocked by RdpGuard's failed-login protection or blacklist.

To exclude a trusted address from RdpGuard blocking, use the whitelist.

  1. Click Add, Allowed address or range:

    GeoIP Add menu with Allowed address or range highlighted
    Add an allowed address or range.
  2. The Add IP addresses dialog will open:

    Add IP addresses dialog with an IP address and a CIDR range
    Enter one IP address, range or CIDR per line.

    Enter one or more addresses or ranges, one per line, and click Add.

  3. The entries will appear as Custom allow list:

    GeoIP country list with a Custom allow list entry
    Custom addresses appear as a separate list entry.

    Click Save to apply your changes.

Advanced GeoIP settings

On the GeoIP tab, click Settings:

Settings button on the GeoIP tab
Open Advanced GeoIP settings.

The Advanced GeoIP settings dialog has three tabs: Deny mode, Allow mode and Miscellaneous.

Deny mode

The Deny mode tab controls which ports are blocked for countries listed in Deny mode.

Advanced GeoIP settings, Deny mode tab
Advanced GeoIP settings, Deny mode.

Blocking scope - choose which ports are denied for blocked countries:

  • Block all ports - deny access from blocked countries to all ports on the server.
  • Block all ports except selected - deny access from blocked countries to all ports except those listed.
  • Block selected ports only - deny access from blocked countries only to the ports listed.

Separate multiple ports with commas, for example: 3389,443.

Allow mode

The Allow mode tab controls which ports are available to allowed countries and which ports are blocked for other countries in Allow mode.

Advanced GeoIP settings, Allow mode tab
Advanced GeoIP settings, Allow mode.

Allow rules - choose which ports are available for allowed countries:

  • Allow access to all ports - allow connections from allowed countries to all ports.
  • Allow access to selected ports only - allow connections from allowed countries only to the ports listed.

Other connections - choose which ports are denied for countries outside the allowed list:

  • Block all ports - deny all access from disallowed countries.
  • Block all ports except selected - deny access from disallowed countries to all ports except those listed.

Separate multiple ports with commas, for example: 3389,443.

Exceptions and special networks - additional Allow mode options:

  • Allow loopback connections (recommended) - allow connections within this computer. Disabling this option can disrupt applications.
  • Allow local network connections - allow access to the server over the local network.
  • Exclude VPN networks and Tor exit nodes from allowed connections - exclude known VPN networks and Tor exit nodes from the allowed IP ranges.
  • Exclude data center networks from allowed connections - exclude known data center networks from the allowed IP ranges.

Miscellaneous

The Miscellaneous tab contains GeoIP database settings:

Advanced GeoIP settings, Miscellaneous tab
Choose the GeoIP database version.

Two versions of the GeoIP database are available:

  • Lite - fewer IP ranges, lower system load, less precise.
  • Max - more IP ranges, higher system load, more precise.

Click OK, then Save in the Options dialog to apply your changes.

Known restrictions and limitations

GeoIP filtering adds country IP ranges to Windows Filtering Platform (WFP). A country can contain thousands of ranges. Large configurations can increase memory and CPU usage, slow down rule updates and affect network performance.

Avoid filtering individual ports with large country lists.

When country rules apply to selected ports, RdpGuard creates separate TCP and UDP filters for each port. The same country IP list is repeated in each set:

Port settingCopies of the country IP list in WFP
All ports1
1 selected port2
5 selected ports10
10 selected ports20

Filtering fewer ports does not mean fewer firewall rules. This multiplication applies both when blocking countries and when allowing them. "All ports except selected" also creates additional filters for the remaining port ranges.

To keep the configuration manageable:

  • Consider the Lite database as a performance trade-off. It uses fewer IP ranges, but country detection is less accurate. This can cause addresses to be blocked or allowed incorrectly. Use it only if lower resource usage is more important than accurate country filtering.
  • Prefer All ports when it matches your access requirements.
  • If access is needed from only a few countries, consider Allow mode instead of blocking a long list of countries.

Test large configurations under representative traffic before using them in production. If performance deteriorates after enabling GeoIP or adding port restrictions, reduce the configuration and retest before expanding it.

RdpGuard 10.3.9 Free Trial

RdpGuard protects:

Our customers say

"This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques

"Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson

"Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford

"Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch

"Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan

"It's a great product - really stopping those RDP attackers :-)" - Dave, UK

"First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes

Our Other Products
Copyright © 2012-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.