LogonShield 한국어

IPs that keep failing to log in get blocked at the firewall

LogonShield watches your Windows server's failed-login records, finds IPs guessing passwords, and blocks them with Windows Firewall rules. Blocks lift on their own when the time runs out.

Download for Windows Version 1.1.0, 64-bit, Windows 10 / Server 2016 or later
Failed logins
  1. 09:14:02RDP4625203.0.113.451/5
  2. 09:14:03RDP4625203.0.113.452/5
  3. 09:14:03MS-SQL18456198.51.100.231/5
  4. 09:14:04RDP4625203.0.113.453/5
  5. 09:14:05RDP4625192.168.0.12 (whitelisted)–
  6. 09:14:05RDP4625203.0.113.454/5
  7. 09:14:06RDP4625203.0.113.455/5
  8. 09:14:08 203.0.113.45 blocked for 24 hours
    Added to firewall rule “LogonShield Local #1”
Default rule: 5 failures within 10 minutes means a 24-hour block. Adjustable per service.

How it works

It runs in the background as a Windows service, so the server stays protected even when nobody is signed in.

  1. Reads the records

    Picks up failed logins in real time from Windows event logs and from IIS, mail server, MySQL and SIP log files.

  2. Counts attempts

    Counts failures per IP and service within a time window. Whitelisted IPs are never counted.

  3. Blocks at the firewall

    Adds the IP to an inbound Windows Firewall block rule. Every port is closed to it, whatever port your services use.

  4. Lifts the block

    Removes the IP when the block expires. You can also block permanently, or unblock by hand at any time.

A look inside

The manager you get on your server, shown with sample data.

LogonShield dashboard
Current blocks, recent activity and the watch status of every service on one screen.

Services it protects

13 services are supported. Anything not installed on the server shows as “no log”, and the rest keep working.

Service Source Counted as a failure
RDPSecurity event log4625
MS-SQLApplication event log18456
MySQL / MariaDBEvent log, error log fileAccess denied for user
OpenSSHOpenSSH/OperationalFailed password, Invalid user
FTPIIS FTP logPASS → 530
HTTPIIS web log401.1
RD Web AccessIIS web logRejected sign-in page
ASP.NET Web FormsApplication event log1315
IMAP, POP3, SMTPhMailServer logAuthentication failure replies
SIPAsterisk log (chan_sip, PJSIP)Failed registration
MS-VPNSystem event log (RRAS)20271

Features

Protection starts with sensible defaults the moment it is installed. Change only what you need.

Per-service rules

Set the attempt limit, time window and block length for each service. A block length of 0 means permanent.

Country rules

An IP from outside your allowed countries is blocked on its first failure. The country database updates itself monthly.

Blocklist subscriptions

Add the URL of a public attacker list and it is fetched every 6 hours and blocked in advance.

Whitelist

Accepts IPs and CIDR ranges, with private networks and localhost included by default. Adding an IP also lifts any block on it.

Manager and tray icon

Dashboard, blocked-IP search with CSV export, per-IP history, manual block and unblock. The tray icon color shows protection status, and new blocks pop up a notice.

Korean, English, Japanese, Chinese

Follows the Windows display language at first, and can be changed in Settings.

Protection starts the moment it's installed

One license per server: ₩12,000 a year or ₩59,000 for life.