Your exposed ports, handled. Automatically.
PortGuardian reads the logs your rejected logins land in, decides which addresses are attacking, and bans them in Windows Firewall. It runs on your server, and your log data stays there.
In private testing on three Windows Server VPSs. The free version launches first.
Watch, decide, write the rule.
Three steps, running unattended on the server you already have. Nothing sits in front of your traffic and no DNS changes.
Read the logs already being written
The agent reads the Windows Security log, MariaDB's error log, IIS and Web Deploy logs, hMailServer and the dashboard's own sign-in attempts. Each rejected login becomes one event with an address, a username, a port and where it came from.
Apply the thresholds you set
Rejections are counted per address across every source, so an attacker spreading attempts over MariaDB and RDP is still one decision. Events that cannot be traced to an address are recorded and skipped, never guessed at.
Ban it in Windows Firewall
Bans are ordinary Windows Firewall rules in a PortGuardian rule group. There is no extra packet filter and no kernel driver, and uninstalling removes the group and every rule in it.
It will not lock you out of your own server.
A lockout on a remote VPS means a support ticket and an hour of downtime, so the safety guard is the default path, not a setting.
Every address is checked twice
Before a rule is written, the address is checked against the one you are connected from, the local subnets, the allowlist and every other protection source. A match stops the ban and records why.
New installs start in Monitoring
Decisions are recorded as would-bans and shown in the dashboard. Nothing is banned until you switch the server to Protecting, and you can stay in Monitoring as long as you like.
Every change asks for your code
Unbanning, changing the mode and editing the allowlist all ask for the 6-digit code from your authenticator app, so a stolen password alone changes nothing.
| Address | Origin | Rejections | Decision |
|---|---|---|---|
| 203.0.113.44 | RDP · 3389 | 412 | Would-ban |
| 198.51.100.17 | MariaDB · 3306 | 5,217 | Would-ban |
| 192.0.2.230 | Web Deploy · 8172 | 88 | Would-ban |
| 203.0.113.9 | Dashboard · 8443 | 31 | Protected |
| — | MariaDB · hostname | 1,904 | Not attributable |
Monitoring: decisions recorded, nothing in the firewall changed. Addresses are from documentation ranges.
The six places rejected logins land.
Each source is read into the same event shape, so counts are per address across the whole server rather than per service.
And a hardening score for what a ban cannot fix.
Banning addresses does not close an open port or turn off an old TLS version. The hardening scan checks the server against a fixed list and tells you how to fix what fails.
| Check | Verdict |
|---|---|
| RDP reachable from any address | Fail |
| TLS 1.0 and 1.1 disabled | Fail |
| Local accounts with non-expiring passwords | Partial |
| Account lockout threshold set | Pass |
| SMBv1 removed | Pass |
A fix, not just a finding
Each failed check explains why it failed on this server and gives you the PowerShell command or Group Policy path that resolves it. Run the scan again and the score updates.
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\ Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server' ` -Name Enabled -Value 0
The fix shown under “TLS 1.0 and 1.1 disabled”.
Planned after launch
Not built yet. These are next on the list once the free version ships.
Admin ports that open only for you Planned
Remote Desktop and Web Deploy stay closed to the internet. When you need in, enter the code from your authenticator app and the port opens for your current address, for as long as you choose. No VPN required.
Several servers, one dashboard Planned
A fleet dashboard you host yourself. An address banned on one server can be banned on all of them.
Questions people ask before installing it
Can it lock me out of my own server?
The address you are connected from is checked before every rule is written, along with local subnets, connected Remote Desktop clients, recent accepted logins and your allowlist. If you need a break, Stand down lifts every ban for 15 minutes, an hour or eight hours, then restores them by itself.
What happens if the wrong address is banned?
Unban it from the Bans page with your code. The firewall rule is rewritten immediately. The decision stays in history with the events that caused it, and you can add the address to the protected list so it cannot happen again.
Does my log data leave my server?
No. Addresses, usernames and event text are kept in a local database on your server.
How is this different from RdpGuard or IPBan?
Counting is per address across every log source rather than per service, bans are ordinary Windows Firewall rules, and the safety guard, Monitoring and the code on every change are on by default rather than settings you have to find.
Which Windows Server versions does it run on?
It is running now on Windows Server 2012 R2 and 2019. The full list will be published at launch.
When does it launch?
When the free version is ready. Join the waitlist and you will get one email that day.
Start in Monitoring. Switch to Protecting when you trust it.
The free version launches first. Get one email when it does.