Link to home
Start Free TrialLog in
Avatar of icecom4
icecom4Flag for United States of America

asked on

Block failed RDP attempts

I am looking for a simple RDP monitor/security tool for a windows server environment.  I connect remotely from various addresses.  I have a remote VPN but the IP changes also., otherwise I would lock RDP down to one IP.  I tried RDPguard and tested it, does not seem to block ban my many failed login attempts.  Any free tools out there?  

Is there a way to do this in Windows?

Environment:
Server 2012 R2 64bit
Avatar of Paul MacDonald
Paul MacDonald
Flag of United States of America image

You shouldn't allow RDP through your firewall to begin with - all the more so if you can VPN in to your network.  Locking down your firewall will fix your problem, because all connection attempts will be coming from a trusted network.
Use a dynamic dns service for your VPN. That way the ip changing isn't an issue, and as Paul stated, you want to VPN into your network and then access RDP if needed.
RDPguard works fine, I guess you might not have configured it correctly
Avatar of icecom4

ASKER

@Shaun,

There is not much to the config according to the developer, I enabled login auditing, thats about it.  

However, maybe it is working and I just can't test it.  So All I am doing is just logging in RDP and deliberately putting the wrong password.  I will do this about 10 times, which takes about 1-15 seconds naturally.  However, maybe RDPguard knows that I am not a hack tool.  I do see that it only makes one failed login regardless of how many times I try, however in the Windows audit logs I see all of them.  

Thoughts?
Do you have Windows Firewall enabled?
Avatar of icecom4

ASKER

Yes, I do have windows firewall enabled.
ASKER CERTIFIED SOLUTION
Avatar of Soulja
Soulja
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Changing the port will not prevent these attacks. It is trivial to scan and find open RDP ports
@Shaun Agreed. My suggestion wasn't a supplement for RDP Guard just another measure to slow down/deter/hinder these attacks in combination with RDP Guard.
Avatar of icecom4

ASKER

I contacted the dev but they could not really answer my question.  Perhaps it is working but I am not able to trigger the RDP locks because I am testing it manually?  Maybe that is not a fast enough way to trigger the black list.
Avatar of icecom4

ASKER

Thanks much