Windows Server · RDP · VPS

Stop RDP brute-force attacks by blocking entire countries

An exposed remote-desktop port is scanned thousands of times a day from networks across the world. Geo Firewall blocks that traffic at the IP level — before it ever reaches the Windows login screen — by allowing only the countries where legitimate administrators actually sign in.

37,000+
brute-force attempts a day against a typical exposed RDP endpoint
100+
countries seen in recent campaigns targeting Windows remote desktop
250+
territories Geo Firewall can allow or block individually

An open RDP port is an open invitation

Remote Desktop is the fastest way to administer a Windows server and one of the most heavily attacked. Automated botnets continuously scan the public Internet for port 3389, then hammer any server they find with credential guesses around the clock. A single weak or reused password is all it takes for that traffic to turn into a ransomware incident. The same pattern applies to other management surfaces such as database, mail and file-transfer services exposed to the Internet.

The overwhelming majority of that traffic comes from places where an organization has no users, no offices and no business. Allowing only the regions that matter is one of the simplest, highest-impact ways to shrink a server's attack surface — and it is exactly what Geo Firewall is built to do.

How Geo Firewall protects a Windows server

Block by country at the IP level

A kernel-mode network driver inspects every connection against a geo-IP database of more than 250 territories and drops traffic from blocked regions before it reaches the remote-desktop service. Rules apply to IPv4, IPv6, TCP and UDP.

Keep trusted access open

Administrator IP addresses and subnets go on the whitelist and are always allowed, regardless of geographic rules. Port range exceptions can reopen a public service port worldwide while management ports stay restricted to trusted regions.

See who is knocking

Live statistics and an activity log show exactly which territories were allowed or blocked and how much traffic each one generated. New rules can be created directly from what the traffic reveals.

Adds a layer, not a conflict

Geo Firewall is compatible with the antivirus and security tools already running on the server. It adds a distinct geographic layer of defense — and the more independent layers there are, the harder a server is to breach.

From install to protection in four steps

  1. Install on the server or VPS

    Download and install on the Windows server or cloud VM. No additional hardware is required.

  2. Whitelist the admin address first

    Add the remote-desktop client IP to the whitelist right away so management access can never be cut off. See the RDP lockout recovery guide for cloud VMs.

  3. Block the regions with no users

    Select the territories where no legitimate administrators sign in and block them for inbound and outbound traffic.

  4. Watch the noise drop, then refine

    Use the statistics and log to confirm the blocked traffic and tighten or relax rules as the picture becomes clear.

Why not just use manual Windows Firewall rules?

Country IP ranges can be scripted into Windows Firewall by hand, but those lists go stale the moment address blocks are reassigned, offer no visibility into what was blocked, and are awkward to maintain across servers. Geo Firewall is purpose-built for the job.

Capability Manual Windows Firewall lists Geo Firewall
Geo-IP database kept current Manual re-import of country lists Automatic updates from the cloud
Inbound and outbound control Limited and hard to manage Separate actions per territory, both directions
Traffic visibility None Per-territory statistics and activity log
Open a port for a blocked country Difficult to maintain Built-in port range exceptions
Setup PowerShell scripting Point-and-click, with a free edition to start

Questions about RDP geo-blocking

Does blocking countries stop RDP brute-force attacks?

Most automated RDP brute-force traffic originates from networks in regions where an organization has no legitimate administrators. Blocking those territories at the IP level removes the bulk of that traffic before it reaches the login screen, sharply reducing failed sign-in noise and the chance of a successful guess.

Will Geo Firewall lock administrators out of the server?

Trusted administrator IP addresses and subnets can be placed on the whitelist so they are always allowed, regardless of geographic rules. On a cloud VM it is recommended to whitelist the remote-desktop client address right after installation to avoid an accidental lockout.

Does Geo Firewall run on Windows Server?

Yes. Geo Firewall runs on Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, as well as Windows 10 and 11. It uses a kernel-mode network driver and works alongside existing security software.

Can specific ports stay open for an otherwise blocked country?

Yes. Port range exceptions can reopen specific ports for territories that are otherwise blocked, so a public web port can remain reachable worldwide while remote-desktop and management ports are restricted to trusted regions.

Add a geographic layer to remote-desktop security

Start with the free Basic edition or compare the Pro and Ultimate editions for servers that need the full rule set, statistics and logging.

Explore other ways to use Geo Firewall

Notes:
* Windows® is a registered trademark of the Microsoft Corporation.