LogonShield 한국어

Frequently asked questions

Does Windows Firewall need to be on?

Yes. Blocks are Windows Firewall rules, so they have no effect on a network profile where the firewall is turned off.

I moved RDP off port 3389. Is that a problem?

No. Blocks apply to the IP, not to a port, so there is nothing to configure.

Does protection continue if I close the manager or sign out?

Yes. A Windows service does the blocking and starts automatically with the server. The manager is only for viewing status and changing settings.

Attacks keep coming, but nothing gets blocked.

First check on the Protocols screen that the service is being watched. RDP failures are only recorded when failed-logon auditing is on; the installer turns it on, but a domain Group Policy can turn it back off. If a router or firewall appliance hides the real address behind NAT, every connection looks like a private IP, and private ranges are whitelisted by default. In that case, configure the device to pass the original IP through.

My own IP got blocked. How do I undo it?

Connect from another IP or the server console, then unblock it in the Blocked IPs list or add it to the whitelist. Whitelisting lifts the block immediately and keeps it from happening again.

Where are history and settings stored?

In %ProgramData%\LogonShield. Block and failure history plus settings live in logonshield.db; service logs are in the logs folder.

Does uninstalling remove the firewall rules?

Yes. Uninstalling from Windows Settings > Apps removes the firewall rules LogonShield created and asks whether to delete history and settings.