Microsoft VPN (RRAS) Brute-Force ProtectionMicrosoft's Routing and Remote Access Service (RRAS) lets remote users connect to a private network through a Windows Server VPN. An Internet-facing VPN server also receives connections from people who have no business on that network. Automated tools can cycle through usernames and passwords, retry continuously and fill your Windows event logs with failed authentication attempts. A VPN encrypts the connection, but password guessing still reaches the login process. Repeated failures create authentication traffic and log noise that administrators would otherwise have to investigate and block manually. In Event Viewer, Windows Logs, System, rejected RRAS authentication attempts can appear as Event ID 20271 from RemoteAccess. During repeated connection attempts, these warnings can arrive one after another: The selected event includes the attempted username, source IP address and failure reason: Another common message reports an unrecognized username/password combination or a disallowed protocol: An isolated warning can result from a typing mistake or an incorrectly configured VPN client. Repeated failures across many usernames are a common sign of automated password guessing. Sustained attempts also consume authentication resources and can make useful events harder to find among thousands of failed connections. RdpGuard monitors RemoteAccess event 20271 in the System log and IPsec event 4652 in the Security log. It reads the source IP address from each supported failure event and counts detections against that address. When detections reach the configured limit, RdpGuard blocks the address for the configured period and automatically unblocks it when that period expires. You control the failed-login limit and block duration. You can also whitelist trusted IP addresses, exclude narrowly defined VPN events, and receive email or Telegram notifications when an IP is blocked. Automatic blocking reduces repeated attempts from the same sources while you keep control over the server's access policy. For 64-bit Windows and Windows Server. Supported Windows versions. See AlsoSee How to Enable and Configure Microsoft VPN (RRAS) Protection for setup instructions, event log requirements and exclusion rules with examples. | RdpGuard 10.4.5 Free Trial RdpGuard protects:
Our customers say "This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques "Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson "Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford "Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch "Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan "It's a great product - really stopping those RDP attackers :-)" - Dave, UK "First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes Our Other Products |