로그인을 계속 틀리는 IP는
방화벽이 대신 막습니다
IPs that keep failing to log in get blocked at the firewall
LogonShield는 Windows 서버의 로그인 실패 기록을 지켜보다가, 비밀번호를 무작위로 대입하는 IP를 찾아 Windows 방화벽 규칙으로 차단합니다. 차단 시간이 지나면 저절로 풀립니다. LogonShield watches your Windows server's failed-login records, finds IPs guessing passwords, and blocks them with Windows Firewall rules. Blocks lift on their own when the time runs out.
- 09:14:02RDP4625203.0.113.451/5
- 09:14:03RDP4625203.0.113.452/5
- 09:14:03MS-SQL18456198.51.100.231/5
- 09:14:04RDP4625203.0.113.453/5
- 09:14:05RDP4625192.168.0.12 (화이트리스트)(whitelisted)–
- 09:14:05RDP4625203.0.113.454/5
- 09:14:06RDP4625203.0.113.455/5
-
09:14:08 203.0.113.45 차단, 24시간 뒤 해제
방화벽 규칙 “LogonShield Local #1”에 추가됨 09:14:08 203.0.113.45 blocked for 24 hours
Added to firewall rule “LogonShield Local #1”
작동 방식How it works
Windows 서비스로 백그라운드에서 돌아가므로, 아무도 로그인하지 않은 서버도 계속 보호됩니다. It runs in the background as a Windows service, so the server stays protected even when nobody is signed in.
-
기록을 읽습니다Reads the records
Windows 이벤트 로그와 IIS, 메일 서버, MySQL, SIP 로그 파일에서 로그인 실패를 실시간으로 찾습니다.Picks up failed logins in real time from Windows event logs and from IIS, mail server, MySQL and SIP log files.
-
횟수를 셉니다Counts attempts
IP와 서비스별로 정해진 시간 안의 실패 횟수를 셉니다. 화이트리스트 IP는 세지 않습니다.Counts failures per IP and service within a time window. Whitelisted IPs are never counted.
-
방화벽에서 막습니다Blocks at the firewall
기준을 넘은 IP를 Windows 방화벽 인바운드 차단 규칙에 넣습니다. 포트와 관계없이 그 IP의 모든 접속이 막힙니다.Adds the IP to an inbound Windows Firewall block rule. Every port is closed to it, whatever port your services use.
-
때가 되면 풉니다Lifts the block
차단 시간이 지나면 규칙에서 저절로 뺍니다. 영구 차단도 고를 수 있고, 관리 화면에서 언제든 직접 풀 수 있습니다.Removes the IP when the block expires. You can also block permanently, or unblock by hand at any time.
보호하는 서비스Services it protects
13개 서비스를 지원합니다. 서버에 없는 서비스는 “로그 없음”으로 표시되고, 나머지는 그대로 동작합니다. 13 services are supported. Anything not installed on the server shows as “no log”, and the rest keep working.
| 서비스Service | 읽는 곳Source | 실패로 보는 기록Counted as a failure |
|---|---|---|
| RDP | 보안 이벤트 로그Security event log | 4625 |
| MS-SQL | 응용 프로그램 이벤트 로그Application event log | 18456 |
| MySQL / MariaDB | 이벤트 로그, 에러 로그 파일Event log, error log file | Access denied for user |
| OpenSSH | OpenSSH/Operational | Failed password, Invalid user |
| FTP | IIS FTP 로그IIS FTP log | PASS → 530 |
| HTTP | IIS 웹 로그IIS web log | 401.1 |
| RD Web Access | IIS 웹 로그IIS web log | 로그인 페이지 실패Rejected sign-in page |
| ASP.NET Web Forms | 응용 프로그램 이벤트 로그Application event log | 1315 |
| IMAP, POP3, SMTP | hMailServer 로그hMailServer log | 인증 실패 응답Authentication failure replies |
| SIP | Asterisk 로그 (chan_sip, PJSIP)Asterisk log (chan_sip, PJSIP) | 등록 실패Failed registration |
| MS-VPN | 시스템 이벤트 로그 (RRAS)System event log (RRAS) | 20271 |
기능Features
설치하면 기본 설정으로 바로 보호를 시작합니다. 필요한 것만 바꾸면 됩니다. Protection starts with sensible defaults the moment it is installed. Change only what you need.
서비스별 차단 기준Per-service rules
실패 횟수, 세는 시간, 차단 시간을 서비스마다 따로 정합니다. 차단 시간을 0으로 두면 영구 차단입니다.Set the attempt limit, time window and block length for each service. A block length of 0 means permanent.
국가 기준 차단Country rules
허용한 국가 밖에서 로그인에 실패한 IP는 첫 실패에 바로 차단합니다. 국가 데이터베이스는 매달 자동으로 갱신됩니다.An IP from outside your allowed countries is blocked on its first failure. The country database updates itself monthly.
외부 차단 목록 구독Blocklist subscriptions
공개된 공격 IP 목록 주소를 넣으면 6시간마다 받아 와서 미리 막아 둡니다.Add the URL of a public attacker list and it is fetched every 6 hours and blocked in advance.
화이트리스트Whitelist
IP와 CIDR 대역을 넣을 수 있고, 내부망과 localhost가 기본으로 들어 있습니다. 화이트리스트에 넣으면 이미 걸린 차단도 풀립니다.Accepts IPs and CIDR ranges, with private networks and localhost included by default. Adding an IP also lifts any block on it.
관리 화면과 트레이 아이콘Manager and tray icon
대시보드, 차단 IP 검색과 CSV 내보내기, IP별 실패 기록, 수동 차단과 해제. 트레이 아이콘 색으로 보호 상태를 보여 주고, 새로 차단하면 알려 줍니다.Dashboard, blocked-IP search with CSV export, per-IP history, manual block and unblock. The tray icon color shows protection status, and new blocks pop up a notice.
한국어, English, 日本語, 简体中文Korean, English, Japanese, Chinese
처음에는 Windows 표시 언어를 따르고, 설정에서 바꿀 수 있습니다.Follows the Windows display language at first, and can be changed in Settings.
다운로드와 설치Download and install
설치 파일 하나로 서비스 등록, 로그온 실패 감사 켜기, 시작 메뉴 바로가기까지 끝납니다. 서버에 .NET을 따로 설치할 필요는 없습니다. One installer registers the service, turns on failed-logon auditing and adds a Start menu shortcut. No separate .NET install is needed.
LogonShield
설치 파일 다운로드Download installer- 서버에서 설치 파일을 실행하고 안내를 따릅니다. 끝나면 보호 서비스가 바로 시작됩니다.Run the installer on the server and follow the prompts. The protection service starts right away.
- 관리 화면에서 보호 상태와 서비스별 감시 상태를 확인합니다.Open the manager to check protection status and which services are being watched.
- 새 버전이 나오면 새 설치 파일을 실행하면 됩니다. 설정과 차단 기록은 그대로 남습니다.To update, run the newer installer. Settings and block history are kept.
여러 서버에 조용히 설치하려면For silent installs across many servers
자주 묻는 질문Frequently asked questions
Windows 방화벽이 켜져 있어야 하나요?Does Windows Firewall need to be on?
네. LogonShield는 Windows 방화벽 규칙으로 차단하므로, 방화벽이 꺼진 네트워크 프로필에서는 차단이 적용되지 않습니다.Yes. Blocks are Windows Firewall rules, so they have no effect on a network profile where the firewall is turned off.
RDP 포트를 3389가 아닌 번호로 바꿨는데 괜찮나요?I moved RDP off port 3389. Is that a problem?
괜찮습니다. 포트가 아니라 IP 단위로 막기 때문에 따로 설정할 것이 없습니다.No. Blocks apply to the IP, not to a port, so there is nothing to configure.
관리 화면을 닫거나 로그아웃해도 보호되나요?Does protection continue if I close the manager or sign out?
네. 차단은 Windows 서비스가 맡고, 서버가 켜질 때 자동으로 시작됩니다. 관리 화면은 상태를 보고 설정을 바꾸는 용도입니다.Yes. A Windows service does the blocking and starts automatically with the server. The manager is only for viewing status and changing settings.
공격이 계속되는데 아무 IP도 차단되지 않아요.Attacks keep coming, but nothing gets blocked.
먼저 관리 화면의 프로토콜 화면에서 해당 서비스가 감시 중인지 확인하세요. RDP는 로그온 실패 감사가 켜져 있어야 기록이 남는데, 설치할 때 켜지지만 도메인 그룹 정책이 다시 끌 수 있습니다. 공유기나 방화벽 장비가 NAT로 원래 IP를 가리면 모든 접속이 내부 IP로 보이고, 내부망은 기본 화이트리스트라 차단되지 않습니다. 이 경우 장비에서 원래 IP가 전달되도록 설정해야 합니다.First check on the Protocols screen that the service is being watched. RDP failures are only recorded when failed-logon auditing is on; the installer turns it on, but a domain Group Policy can turn it back off. If a router or firewall appliance hides the real address behind NAT, every connection looks like a private IP, and private ranges are whitelisted by default. In that case, configure the device to pass the original IP through.
제 IP가 차단됐어요. 어떻게 푸나요?My own IP got blocked. How do I undo it?
다른 IP나 서버 콘솔로 접속해 관리 화면의 차단 IP 목록에서 해제하거나, 화이트리스트에 추가하세요. 화이트리스트에 넣으면 차단이 바로 풀리고 다시 막히지 않습니다.Connect from another IP or the server console, then unblock it in the Blocked IPs list or add it to the whitelist. Whitelisting lifts the block immediately and keeps it from happening again.
기록과 설정은 어디에 저장되나요?Where are history and settings stored?
%ProgramData%\LogonShield 폴더에 있습니다. 차단·실패 기록과 설정은 logonshield.db, 서비스 로그는 logs 폴더입니다.In %ProgramData%\LogonShield. Block and failure history plus settings live in logonshield.db; service logs are in the logs folder.
제거하면 방화벽 규칙도 지워지나요?Does uninstalling remove the firewall rules?
네. Windows 설정 > 앱에서 제거하면 LogonShield가 만든 방화벽 규칙을 함께 지우고, 기록과 설정을 지울지 물어봅니다.Yes. Uninstalling from Windows Settings > Apps removes the firewall rules LogonShield created and asks whether to delete history and settings.