PortGuardianYour exposed ports, handled. Automatically.

Your exposed ports, handled. Automatically.

PortGuardian reads the logs your rejected logins land in, decides which addresses are attacking, and bans them in Windows Firewall. It runs on your server, and your log data stays there.

One email at launch, plus the occasional progress note. Unsubscribe anytime.

In private testing on three Windows Server VPSs. The free version launches first.

Watch, decide, write the rule.

Three steps, running unattended on the server you already have. Nothing sits in front of your traffic and no DNS changes.

01 / WATCH

Read the logs already being written

The agent reads the Windows Security log, MariaDB's error log, IIS and Web Deploy logs, hMailServer and the dashboard's own sign-in attempts. Each rejected login becomes one event with an address, a username, a port and where it came from.

02 / DECIDE

Apply the thresholds you set

Rejections are counted per address across every source, so an attacker spreading attempts over MariaDB and RDP is still one decision. Events that cannot be traced to an address are recorded and skipped, never guessed at.

03 / WRITE

Ban it in Windows Firewall

Bans are ordinary Windows Firewall rules in a PortGuardian rule group. There is no extra packet filter and no kernel driver, and uninstalling removes the group and every rule in it.

It will not lock you out of your own server.

A lockout on a remote VPS means a support ticket and an hour of downtime, so the safety guard is the default path, not a setting.

Every address is checked twice

Before a rule is written, the address is checked against the one you are connected from, the local subnets, the allowlist and every other protection source. A match stops the ban and records why.

New installs start in Monitoring

Decisions are recorded as would-bans and shown in the dashboard. Nothing is banned until you switch the server to Protecting, and you can stay in Monitoring as long as you like.

Every change asks for your code

Unbanning, changing the mode and editing the allowlist all ask for the 6-digit code from your authenticator app, so a stolen password alone changes nothing.

WIN-VPS-01 · EventsMonitoring
Decisions are recorded and shown here. Nothing is blocked until you switch this server to Protecting.
AddressOriginRejectionsDecision
203.0.113.44RDP · 3389412Would-ban
198.51.100.17MariaDB · 33065,217Would-ban
192.0.2.230Web Deploy · 817288Would-ban
203.0.113.9Dashboard · 844331Protected
—MariaDB · hostname1,904Not attributable
Last 24 h · sample datapolling 5s

Monitoring: decisions recorded, nothing in the firewall changed. Addresses are from documentation ranges.

The six places rejected logins land.

Each source is read into the same event shape, so counts are per address across the whole server rather than per service.

Remote Desktop
Security 4625 · 3389
Rejected logins over the network and Remote Desktop, with the username the attacker tried.
MariaDB / MySQL
mysql_error.log · 3306
Access-denied lines. Rows that carry a hostname instead of an address are marked not attributable.
IIS
W3C logs · 80, 443
Bursts of rejected sign-ins against your sites, counted per address rather than per URL.
Web Deploy
W3C logs · 8172
Rejected publish sign-ins, a common target on servers that host ASP.NET applications.
hMailServer
hmailserver_*.log · 25, 587, 993
SMTP, POP3 and IMAP sign-in rejections.
The dashboard
PortGuardian · 8443
Its own sign-in attempts, so a brute force against the dashboard counts like any other source.

And a hardening score for what a ban cannot fix.

Banning addresses does not close an open port or turn off an old TLS version. The hardening scan checks the server against a fixed list and tells you how to fix what fails.

WIN-VPS-01 · Hardening scanran 14 min ago
74/ 10031 checks · 21 pass · 6 fail · 3 partial · 1 n/a
CheckVerdict
RDP reachable from any addressFail
TLS 1.0 and 1.1 disabledFail
Local accounts with non-expiring passwordsPartial
Account lockout threshold setPass
SMBv1 removedPass
Sample data31 checks

A fix, not just a finding

Each failed check explains why it failed on this server and gives you the PowerShell command or Group Policy path that resolves it. Run the scan again and the score updates.

Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\
  Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server' `
  -Name Enabled -Value 0

The fix shown under “TLS 1.0 and 1.1 disabled”.

Planned after launch

Not built yet. These are next on the list once the free version ships.

Admin ports that open only for you Planned

Remote Desktop and Web Deploy stay closed to the internet. When you need in, enter the code from your authenticator app and the port opens for your current address, for as long as you choose. No VPN required.

Several servers, one dashboard Planned

A fleet dashboard you host yourself. An address banned on one server can be banned on all of them.

Questions people ask before installing it

Can it lock me out of my own server?

The address you are connected from is checked before every rule is written, along with local subnets, connected Remote Desktop clients, recent accepted logins and your allowlist. If you need a break, Stand down lifts every ban for 15 minutes, an hour or eight hours, then restores them by itself.

What happens if the wrong address is banned?

Unban it from the Bans page with your code. The firewall rule is rewritten immediately. The decision stays in history with the events that caused it, and you can add the address to the protected list so it cannot happen again.

Does my log data leave my server?

No. Addresses, usernames and event text are kept in a local database on your server.

How is this different from RdpGuard or IPBan?

Counting is per address across every log source rather than per service, bans are ordinary Windows Firewall rules, and the safety guard, Monitoring and the code on every change are on by default rather than settings you have to find.

Which Windows Server versions does it run on?

It is running now on Windows Server 2012 R2 and 2019. The full list will be published at launch.

When does it launch?

When the free version is ready. Join the waitlist and you will get one email that day.

Start in Monitoring. Switch to Protecting when you trust it.

The free version launches first. Get one email when it does.

Unsubscribe anytime.