Scantide Guard Guide

How to Deploy Guard Safely Without Locking Yourself Out

Verify logging, firewall state, source attribution and normal authentication behavior before enabling aggressive automatic blocking.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Verify logging, firewall state, source attribution and normal authentication behavior before enabling aggressive automatic blocking.

Confirm the prerequisites

Before enforcement, make sure the relevant event or application logging is enabled and that the local firewall can accept and remove Guard rules. Confirm the collector you intend to use is actually receiving events.

Generate controlled failures

Use a test account or controlled authentication attempt from a known source. Verify that Guard records the expected source IP, username and monitor. Do not assume that because an event exists it contains safe blocking evidence.

Start with monitor-only when uncertain

For custom applications or unusual authentication paths, monitor first. Learn normal failure patterns, validate parsing and confirm that proxies/gateways are attributed correctly.

Define emergency access

Administrators should know how to disable Guard enforcement or remove a firewall block locally if access is lost. Remote security controls are safer when the recovery path is documented before rollout.

Add trusted sources deliberately

Do not whitelist an entire LAN merely to avoid mistakes. Use explicit management sources where needed and allow successful-login learning to provide context where supported.

Roll out gradually

Protect one or a small number of representative servers first, review events and policy, then expand through Datacenter. A controlled deployment reveals application-specific behavior before it affects the entire estate.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Scantide Guard for Linux

A custom Linux monitor can inherit the normal Guard thresholds or use an explicit override for alerts, blocking, windows, durations and other monitor-specific behavior.

Current Scantide source: Custom Security Log Monitoring & Automatic IP Blocking

Yes. A custom monitor can classify successful authentication evidence so Guard can use it for trusted-host or safe-list learning rather than blocking.

Current Scantide source: SSH Brute Force Protection for Linux

Guard turns normal SSH authentication evidence into a controlled defense loop: observe failures, correlate the source, apply policy, and enforce the block using the local Linux firewall.

Current Scantide source: Custom Security Log Monitoring & Automatic IP Blocking

Yes. The design supports per-monitor overrides so applications with different authentication behavior do not have to share one global threshold.

Current Scantide source: Scantide Guard for Windows Server

Each monitor can inherit the global Guard policy or use its own alert threshold, block threshold, time window, block duration, immediate-block behavior and notification settings.

Field experience from the archive

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

Enable logging of login failures, access failures to operating system events etc. In short, log everything. It'll impact performance and use up disk but it's useful for troubleshooting when the time comes.

Historical source · JufCorp: Securing your servers, users and customers online

Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)

Practical review checklist

Frequently asked questions

Should I enable blocking immediately after installation?

For well-understood built-in collectors you can, but monitor-first deployment is safer for unusual applications and custom monitors.

What if Guard blocks my own IP?

Have a documented local recovery/unblock procedure and explicit management trust where appropriate.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter