On-Premises Windows Servers

Geo-block the Windows servers that run the business

File shares, databases and line-of-business applications are often exposed with little more than the built-in firewall. Geo Firewall confines each server to the countries that matter — inbound and outbound — right on the host, with no new hardware to buy or rack.

No
additional hardware — protection runs on the server itself
250+
territories to allow or block individually, by region or one at a time
2-way
inbound and outbound control for every territory

Servers exposed with only the basics

Plenty of Windows servers face the Internet protected by nothing more than the built-in firewall and an antivirus agent. They answer connection attempts from anywhere on earth, and — just as importantly — they are free to reach out to anywhere, which is exactly how compromised machines call home and move data out. For an organization that only does business in a handful of regions, that is far more exposure than the work requires.

Geo Firewall closes that gap by partitioning connectivity by geography. Traffic to and from regions the organization never deals with is simply dropped, on the server, before it reaches a service or leaves the host.

What a host-based geo-firewall does for a server

Confine the server to approved regions

A kernel-mode driver checks every connection against a geo-IP database of more than 250 territories and drops traffic from blocked regions across IPv4, IPv6, TCP and UDP — shrinking the attack surface to the places that matter.

Control outbound, not just inbound

Each territory carries separate actions for inbound and outbound traffic, so a server can be stopped from reaching out to regions it has no reason to contact — cutting off a common path for data leaving a compromised host.

Protects more than remote desktop

File sharing, database, mail and custom line-of-business ports all sit behind the same geographic rules. Port range exceptions keep the services that genuinely need a global audience reachable.

No appliance, no new hardware

Geo Firewall installs as software on the server and works behind whatever router or firewall is already in place. It adds a geographic layer without a forklift upgrade, and a free edition makes it easy to start.

Set up on a server in four steps

  1. Install on each server

    Install on the Windows server; the kernel-mode driver begins inspecting traffic immediately.

  2. Protect internal access

    Reserved and local networks stay reachable, and trusted management addresses go on the whitelist so internal work is never interrupted.

  3. Block the regions with no business

    Select the territories the organization never deals with and block them for inbound and outbound traffic.

  4. Review and add exceptions

    Use the statistics and log to verify the result, then add port range exceptions for any service that needs broader reach.

On the host vs. at the edge

A perimeter appliance guards the network boundary, but many smaller sites do not have one — and even where one exists, it rarely controls what an individual server is allowed to reach. Geo Firewall puts the geographic policy on the server itself.

Consideration Network edge appliance Geo Firewall on the host
Where the policy runs At the network perimeter On each Windows server
Protects a single exposed server Requires appliance configuration Built in, per server
Outbound control by country Varies by device Inbound and outbound per territory
Visibility into what hit the server Aggregated at the edge Per-territory statistics on the host
Cost to start New hardware and licensing Software only, free Basic edition

Questions about server geo-blocking

Does Geo Firewall need a separate appliance or new hardware?

No. Geo Firewall is software that installs directly on the Windows server and filters traffic with a kernel-mode network driver. It protects the server itself and needs no additional hardware or network appliance.

Can it block outbound traffic as well as inbound?

Yes. Each territory has separate actions for inbound and outbound traffic, so a server can both refuse connections from a region and be prevented from initiating connections to it.

Will geographic blocking break internal or essential services?

Geo Firewall recognizes reserved and local networks so internal communication keeps working, and trusted addresses and subnets can be placed on the whitelist. Port range exceptions keep specific public services reachable while the rest of the surface is restricted.

Which Windows Server versions are supported?

Geo Firewall supports Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, as well as Windows 10 and 11.

Shrink a server's attack surface to the regions that matter

Start with the free Basic edition, or compare the Pro and Ultimate editions for servers that need the full rule set, statistics and logging.

Explore other ways to use Geo Firewall

Notes:
* Windows® is a registered trademark of the Microsoft Corporation.