RDP Brute-Force Protection ConfigurationProtection OverviewRdpGuard protects Remote Desktop servers from brute-force attacks by detecting failed login attempts and automatically blocking IP addresses that reach the configured limit. You can adjust the failed-attempt limit and block duration to suit your server. Use the RDP Settings dialog to enable protection and configure detection exclusions. To receive notifications when an address is blocked, configure a custom action. To enable and configure RDP protectionBefore you begin, check the recommended audit policy settings. RdpGuard uses failed logon events from the Windows Security log to detect login attempts.
To change the failed-attempt limit or block duration, open Tools, Options, General. These are shared blocking settings, not separate limits for RDP. On Windows Server 2012 and later, RdpGuard also uses the Remote Desktop Services RdpCoreTS log to help identify the source IP when it is missing from a failed logon event. The traffic-monitoring controls below are shown only on Windows Server 2008 and 2008 R2. Traffic monitoring on Windows Server 2008 and 2008 R2On these older systems, failed RDP connections over TLS can leave the source IP missing from the Security log. Enable traffic monitoring to detect these attempts from RDP network traffic. ![]()
Click Save to apply the settings. Exclusions for RDP detectionWindows Security log event 4625 can describe failed logons from RDP and other sources. If legitimate activity is being counted as failed attempts, you can exclude specific events based on their fields. Open RDP Settings and click Exclusions.... See how to exclude Security log events (Event ID 4625) for rule syntax and examples. To keep a trusted IP address from being blocked regardless of event details, add it to the whitelist instead. | RdpGuard 10.4.5 Free Trial RdpGuard protects:
Our customers say "This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques "Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson "Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford "Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch "Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan "It's a great product - really stopping those RDP attackers :-)" - Dave, UK "First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes Our Other Products |