Stop RDP brute-force attacks by blocking entire countries
An exposed remote-desktop port is scanned thousands of times a day from networks across the world.
Geo Firewall blocks that traffic at the IP level — before it ever reaches the Windows login screen —
by allowing only the countries where legitimate administrators actually sign in.
brute-force attempts a day against a typical exposed RDP endpoint
100+
countries seen in recent campaigns targeting Windows remote desktop
250+
territories Geo Firewall can allow or block individually
An open RDP port is an open invitation
Remote Desktop is the fastest way to administer a Windows server and one of the most heavily attacked.
Automated botnets continuously scan the public Internet for port 3389, then hammer any server they find
with credential guesses around the clock. A single weak or reused password is all it takes for that
traffic to turn into a ransomware incident. The same pattern applies to other management surfaces such as
database, mail and file-transfer services exposed to the Internet.
The overwhelming majority of that traffic comes from places where an organization has no users, no offices
and no business. Allowing only the regions that matter is one of the simplest, highest-impact ways to shrink
a server's attack surface — and it is exactly what Geo Firewall is built to do.
How Geo Firewall protects a Windows server
Block by country at the IP level
A kernel-mode network driver inspects every connection against a geo-IP database of more than 250
territories and drops traffic from blocked regions before it reaches the remote-desktop service.
Rules apply to IPv4, IPv6, TCP and UDP.
Keep trusted access open
Administrator IP addresses and subnets go on the whitelist and are always allowed, regardless of
geographic rules. Port range exceptions can reopen a public service port worldwide while management
ports stay restricted to trusted regions.
See who is knocking
Live statistics and an activity log show exactly which territories were allowed or blocked and how much
traffic each one generated. New rules can be created directly from what the traffic reveals.
Adds a layer, not a conflict
Geo Firewall is compatible with the antivirus and security tools already running on the server. It adds
a distinct geographic layer of defense — and the more independent layers there are, the harder a
server is to breach.
From install to protection in four steps
Install on the server or VPS
Download and install on the Windows server or cloud VM. No additional hardware is required.
Whitelist the admin address first
Add the remote-desktop client IP to the whitelist right away so management access can never be cut off. See the RDP lockout recovery guide for cloud VMs.
Block the regions with no users
Select the territories where no legitimate administrators sign in and block them for inbound and outbound traffic.
Watch the noise drop, then refine
Use the statistics and log to confirm the blocked traffic and tighten or relax rules as the picture becomes clear.
Why not just use manual Windows Firewall rules?
Country IP ranges can be scripted into Windows Firewall by hand, but those lists go stale the moment
address blocks are reassigned, offer no visibility into what was blocked, and are awkward to maintain across
servers. Geo Firewall is purpose-built for the job.
Capability
Manual Windows Firewall lists
Geo Firewall
Geo-IP database kept current
Manual re-import of country lists
Automatic updates from the cloud
Inbound and outbound control
Limited and hard to manage
Separate actions per territory, both directions
Traffic visibility
None
Per-territory statistics and activity log
Open a port for a blocked country
Difficult to maintain
Built-in port range exceptions
Setup
PowerShell scripting
Point-and-click, with a free edition to start
Questions about RDP geo-blocking
Does blocking countries stop RDP brute-force attacks?
Most automated RDP brute-force traffic originates from networks in regions where an organization has
no legitimate administrators. Blocking those territories at the IP level removes the bulk of that
traffic before it reaches the login screen, sharply reducing failed sign-in noise and the chance of a
successful guess.
Will Geo Firewall lock administrators out of the server?
Trusted administrator IP addresses and subnets can be placed on the whitelist so they are always
allowed, regardless of geographic rules. On a cloud VM it is recommended to whitelist the
remote-desktop client address right after installation to avoid an accidental lockout.
Does Geo Firewall run on Windows Server?
Yes. Geo Firewall runs on Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, as well as
Windows 10 and 11. It uses a kernel-mode network driver and works alongside existing security software.
Can specific ports stay open for an otherwise blocked country?
Yes. Port range exceptions can reopen specific ports for territories that are otherwise blocked, so a
public web port can remain reachable worldwide while remote-desktop and management ports are
restricted to trusted regions.
Add a geographic layer to remote-desktop security
Start with the free Basic edition or compare the Pro and Ultimate editions for servers that need the
full rule set, statistics and logging.
Notes: * Windows® is a registered trademark of the Microsoft Corporation.
By clicking accept, you understand that we use cookies to improve your experience on our website.
For more details, please see our
Cookie Policy
and our
Terms of Use.