Geo-block the Windows servers that run the business
File shares, databases and line-of-business applications are often exposed with little more than the
built-in firewall. Geo Firewall confines each server to the countries that matter — inbound and
outbound — right on the host, with no new hardware to buy or rack.
additional hardware — protection runs on the server itself
250+
territories to allow or block individually, by region or one at a time
2-way
inbound and outbound control for every territory
Servers exposed with only the basics
Plenty of Windows servers face the Internet protected by nothing more than the built-in firewall and an
antivirus agent. They answer connection attempts from anywhere on earth, and — just as importantly —
they are free to reach out to anywhere, which is exactly how compromised machines call home and move data out.
For an organization that only does business in a handful of regions, that is far more exposure than the work
requires.
Geo Firewall closes that gap by partitioning connectivity by geography. Traffic to and from regions the
organization never deals with is simply dropped, on the server, before it reaches a service or leaves the host.
What a host-based geo-firewall does for a server
Confine the server to approved regions
A kernel-mode driver checks every connection against a geo-IP database of more than 250 territories and
drops traffic from blocked regions across IPv4, IPv6, TCP and UDP — shrinking the attack surface to
the places that matter.
Control outbound, not just inbound
Each territory carries separate actions for inbound and outbound traffic, so a server can be stopped from
reaching out to regions it has no reason to contact — cutting off a common path for data leaving a
compromised host.
Protects more than remote desktop
File sharing, database, mail and custom line-of-business ports all sit behind the same geographic rules.
Port range exceptions keep the services that genuinely need a global audience reachable.
No appliance, no new hardware
Geo Firewall installs as software on the server and works behind whatever router or firewall is already
in place. It adds a geographic layer without a forklift upgrade, and a free edition makes it easy to start.
Set up on a server in four steps
Install on each server
Install on the Windows server; the kernel-mode driver begins inspecting traffic immediately.
Protect internal access
Reserved and local networks stay reachable, and trusted management addresses go on the whitelist so internal work is never interrupted.
Block the regions with no business
Select the territories the organization never deals with and block them for inbound and outbound traffic.
Review and add exceptions
Use the statistics and log to verify the result, then add port range exceptions for any service that needs broader reach.
On the host vs. at the edge
A perimeter appliance guards the network boundary, but many smaller sites do not have one — and even
where one exists, it rarely controls what an individual server is allowed to reach. Geo Firewall puts the
geographic policy on the server itself.
Consideration
Network edge appliance
Geo Firewall on the host
Where the policy runs
At the network perimeter
On each Windows server
Protects a single exposed server
Requires appliance configuration
Built in, per server
Outbound control by country
Varies by device
Inbound and outbound per territory
Visibility into what hit the server
Aggregated at the edge
Per-territory statistics on the host
Cost to start
New hardware and licensing
Software only, free Basic edition
Questions about server geo-blocking
Does Geo Firewall need a separate appliance or new hardware?
No. Geo Firewall is software that installs directly on the Windows server and filters traffic with a
kernel-mode network driver. It protects the server itself and needs no additional hardware or network
appliance.
Can it block outbound traffic as well as inbound?
Yes. Each territory has separate actions for inbound and outbound traffic, so a server can both refuse
connections from a region and be prevented from initiating connections to it.
Will geographic blocking break internal or essential services?
Geo Firewall recognizes reserved and local networks so internal communication keeps working, and
trusted addresses and subnets can be placed on the whitelist. Port range exceptions keep specific
public services reachable while the rest of the surface is restricted.
Which Windows Server versions are supported?
Geo Firewall supports Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, as well as Windows 10
and 11.
Shrink a server's attack surface to the regions that matter
Start with the free Basic edition, or compare the Pro and Ultimate editions for servers that need the full
rule set, statistics and logging.
Notes: * Windows® is a registered trademark of the Microsoft Corporation.
By clicking accept, you understand that we use cookies to improve your experience on our website.
For more details, please see our
Cookie Policy
and our
Terms of Use.