How to Enable and Configure VoIP/SIP Brute-Force Protection with WinPcap/Npcap or Raw Sockets
RdpGuard
Intrusion prevention system for your Windows Server
 

VoIP/SIP Brute-Force Protection Settings

SIP Protection Overview

RdpGuard's VoIP/SIP protection monitors SIP traffic on your Windows server and automatically blocks IP addresses when detected failures reach the configured limit.

Traffic monitoring supports unencrypted IPv4 SIP over TCP and UDP. SIP over TLS and IPv6 are not supported.

How to Enable and Configure SIP Protection

  1. Run RdpGuard Dashboard as administrator. Under Monitored protocols, click SIP to open its settings. SIP protection is disabled by default.

    Disabled SIP protection button in RdpGuard Dashboard
    Click SIP to open its protection settings.

    The SIP Settings dialog will open:

    SIP Settings with protection enabled, WinPcap/Npcap selected and default SIP ports
    SIP Settings dialog.
  2. Select Enable SIP protection.

  3. Select WinPcap/Npcap (recommended). If needed, install a compatible capture driver. Click Configure..., select the network adapter carrying SIP traffic, and click OK.

    Alternatively, select Raw Sockets, click Configure... and choose the local IP addresses to monitor. This method requires no additional driver but may not work with some firewalls or Windows editions. Click OK.

  4. Leave SIP ports empty to use 5060, or enter your server's SIP ports separated by commas, for example 5060, 5070.

  5. Click Save to apply the settings. RdpGuard restarts its service automatically.

To adjust the detection limit or block duration, open Tools, Options, General. Use the whitelist to exempt trusted IP addresses from blocking.

If SIP attempts are not detected, check the adapter and ports. Monitoring must see both client requests and server responses. Open View, Show event log in RdpGuard Dashboard to check for monitoring errors and SIP detections.

RdpGuard 10.4.1 Free Trial

RdpGuard protects:

Our customers say

"This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques

"Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson

"Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford

"Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch

"Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan

"It's a great product - really stopping those RDP attackers :-)" - Dave, UK

"First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes

Our Other Products
Copyright © 2012-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.