Protect Windows Server VPN (RRAS) from Brute-Force Attacks with Automatic IP Blocking
RdpGuard
Intrusion prevention system for your Windows Server
 

Microsoft VPN (RRAS) Brute-Force Protection

Microsoft's Routing and Remote Access Service (RRAS) lets remote users connect to a private network through a Windows Server VPN. An Internet-facing VPN server also receives connections from people who have no business on that network. Automated tools can cycle through usernames and passwords, retry continuously and fill your Windows event logs with failed authentication attempts.

A VPN encrypts the connection, but password guessing still reaches the login process. Repeated failures create authentication traffic and log noise that administrators would otherwise have to investigate and block manually.

In Event Viewer, Windows Logs, System, rejected RRAS authentication attempts can appear as Event ID 20271 from RemoteAccess. During repeated connection attempts, these warnings can arrive one after another:

Date and time             Event ID       Source             Level
2024-01-19 16:48:45       20271          RemoteAccess       Warning
2024-01-19 16:48:44       20271          RemoteAccess       Warning
2024-01-19 16:48:42       20271          RemoteAccess       Warning
Selected System log entries: repeated VPN authentication failures (event ID 20271).

The selected event includes the attempted username, source IP address and failure reason:

Log Name:  System
Source:    RemoteAccess
Event ID:  20271
Level:     Warning
Logged:    1/19/2024 4:48:45 PM

Description:
The user admin connected from 34.237.68.111 but failed an authentication attempt due to the following reason:

The connection was prevented because of a policy configured on your RAS/VPN server. Specifically, the authentication method used by the server to verify your username and password may not match the authentication method configured in your connection profile. Please contact the Administrator of the RAS server and notify them of this error.
RemoteAccess event 20271: VPN authentication rejected by the server's policy.

Another common message reports an unrecognized username/password combination or a disallowed protocol:

The user vpn connected from 68.69.184.82 but failed an authentication attempt due to the following reason: The remote connection was denied because the user name and password combination you provided is not recognized, or the selected authentication protocol is not permitted on the remote access server.

An isolated warning can result from a typing mistake or an incorrectly configured VPN client. Repeated failures across many usernames are a common sign of automated password guessing. Sustained attempts also consume authentication resources and can make useful events harder to find among thousands of failed connections.

RdpGuard monitors RemoteAccess event 20271 in the System log and IPsec event 4652 in the Security log. It reads the source IP address from each supported failure event and counts detections against that address. When detections reach the configured limit, RdpGuard blocks the address for the configured period and automatically unblocks it when that period expires.

You control the failed-login limit and block duration. You can also whitelist trusted IP addresses, exclude narrowly defined VPN events, and receive email or Telegram notifications when an IP is blocked. Automatic blocking reduces repeated attempts from the same sources while you keep control over the server's access policy.

For 64-bit Windows and Windows Server. Supported Windows versions.

See Also

See How to Enable and Configure Microsoft VPN (RRAS) Protection for setup instructions, event log requirements and exclusion rules with examples.

RdpGuard 10.4.5 Free Trial

RdpGuard protects:

Our customers say

"This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques

"Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson

"Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford

"Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch

"Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan

"It's a great product - really stopping those RDP attackers :-)" - Dave, UK

"First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes

Our Other Products
Copyright © 2012-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.