Scantide Guard Guide

From One Server to Datacenter-Wide Response

Local enforcement is valuable, but fleets need central policy, shared monitors, license visibility, reputation caching and cross-server context.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Local enforcement is valuable, but fleets need central policy, shared monitors, license visibility, reputation caching and cross-server context.

Keep enforcement close to the workload

Each Guard server observes its local evidence and can enforce through the local Windows or Linux firewall. That keeps protection autonomous even if the central service is temporarily unavailable.

Centralize policy and visibility

Datacenter provides a common place for policy, enrollment, configuration, security-event visibility and licensing across managed servers.

Share intelligence without duplicating it

Managed Guards can use Datacenter as the central path for external reputation caching and Global Reputation publishing, avoiding duplicate outbound queries and duplicate submissions.

Distribute Custom Monitors centrally

Organization-approved monitor definitions can be managed in Datacenter and distributed to enrolled servers while keeping locally authored monitors distinct.

Design for offline segments

Highly secured networks may allow a Guard server to reach Datacenter but not the Internet. Central services should therefore be able to broker licensing, policy and intelligence where practical rather than assuming every server has direct outbound access.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: RdpGuard Alternative for Windows & Linux Server Protection

A single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.

Current Scantide source: SSH Brute Force Protection for Linux

Scantide Guard does not need to attack, exploit or brute-force a service to decide that repeated hostile activity deserves action. Collectors observe evidence already generated by the server, normalize it into a common event model, then apply explicit thresholds, allowlists, exceptions and enforcement policy.

Current Scantide source: Scantide Guard for Windows Server

Monitor definitions can be packaged, reviewed and distributed. Datacenter can centrally distribute managed monitors while locally authored monitors remain distinct.

Current Scantide source: Scantide Guard for Linux

Events from Custom Monitors feed the same deterministic Guard decision model and local firewall enforcement used by the built-in SSH and web collectors.

Current Scantide source: Scantide Guard for Linux

Scantide Guard can use successful authentication evidence from supported built-in collectors and Custom Monitors to recognize trusted administration sources, reset or contextualize active failure history where appropriate, and reduce unnecessary blocking without weakening the deterministic protection model.

Field experience from the archive

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

In many environments, local firewalls are disabled out of pure laziness. "We can't be bothered troubleshooting why SQL traffic doesn't work .." Have local firewalls enabled , enable logging so you can easily find what's going on. If you're in a shared environment you'll also get alerted about noisy neighbors . Local firewalls also enables you to utilize a brute force prevention software and have those attacks mitigated, no matter where they come from. If you want, I'll happily help you out with getting a brute force prevention software in place.

Historical source · JufCorp: Securing your servers, users and customers online

Enforce an Account Lockout Policy and enforce complex password. Yes, people will hate you but they will hate you even more if someone actually succeeds in hacking your users data. Have a look at the link above about Account Lockout Policies though. Do not have local users more than necessary on the Exchange Server itself.

Practical review checklist

Frequently asked questions

Does Guard stop working if Datacenter is unavailable?

The architecture is intended to keep local enforcement autonomous; Datacenter adds central management and shared services.

Why centralize reputation queries?

It reduces duplicated outbound traffic, API usage and inconsistent cache state across servers.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter