Scantide Guard Guide

Host-Based Blocking vs Perimeter Firewalling

Perimeter firewalls reduce exposure; host-based protection sees the authentication evidence. The strongest design uses both rather than treating them as competitors.

Technical guideUpdated 25 September 2026Scantide Guard
Short answer: Perimeter firewalls reduce exposure; host-based protection sees the authentication evidence. The strongest design uses both rather than treating them as competitors.

Perimeter firewalls answer reachability questions

A network firewall is excellent at deciding which addresses and networks may reach a service. It should be used to reduce unnecessary exposure before traffic reaches the server.

The host sees application context

The server or application knows whether authentication failed, which username was used and which monitor observed the event. That makes host-level evidence useful for behavioral blocking that a perimeter device may not have.

Local blocking follows the protected workload

A Guard firewall rule is enforced on the server being attacked. This is useful in mixed estates and environments where changing the upstream firewall requires another team or service provider.

Central management can still coordinate host enforcement

Datacenter provides policy and visibility across the fleet while each Guard applies the relevant local firewall action on its own operating system.

Do not use Guard as an excuse for open exposure

If a management service can be restricted to VPN or trusted administrative networks, do that. Host-based blocking is defense in depth, not permission to expose everything.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Custom Security Log Monitoring & Automatic IP Blocking

Yes. A custom monitor can classify successful authentication evidence so Guard can use it for trusted-host or safe-list learning rather than blocking.

Current Scantide source: Scantide Guard Product & Server Security Guides

Host-level intrusion and abuse prevention for Windows and Linux using authentication logs, web evidence, reputation context and local firewall response.

Current Scantide source: Lightweight Server Intrusion Prevention for Windows & Linux

Yes. Guard is useful as a standalone host protector and can later be enrolled into Datacenter if centralized management is needed.

Current Scantide source: RDP Brute Force Protection for Windows Server

Scantide Guard can use successful authentication evidence from supported built-in collectors and Custom Monitors to recognize trusted administration sources, reset or contextualize active failure history where appropriate, and reduce unnecessary blocking without weakening the deterministic protection model.

Current Scantide source: Scantide Guard for Linux

Protect Linux servers with lightweight log-based detection, configurable thresholds and local nftables enforcement for SSH, web servers and application logs.

Field experience from the archive

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

In many environments, local firewalls are disabled out of pure laziness. "We can't be bothered troubleshooting why SQL traffic doesn't work .." Have local firewalls enabled , enable logging so you can easily find what's going on. If you're in a shared environment you'll also get alerted about noisy neighbors . Local firewalls also enables you to utilize a brute force prevention software and have those attacks mitigated, no matter where they come from. If you want, I'll happily help you out with getting a brute force prevention software in place.

Historical source · JufCorp: Using HTTP redirects for mitigating vulnerability scans and bruteforce attacks

I started thinking about how it actually works. If a vulnerability scan is performed (if you have the WAF, Wordfence Application Firewall, enabled that is) or a brute force attempt is made against your /wp-login-page, there are rules that determine things such as "how many invalid login attempts during how long". Based on those rules, the IP address is presented with a 503 error or 403 error. The client isn't allowed to access for instance the /wp-admin page for a specified period of time. All of this works fine from out of the box with Wordfence so they've done the hard work i.e writing the engine to detect the stuff. And while at it , you might also want to have a look at using Wordfence for blocking XMLRPC traffic ( here's an article about why you should btw) It's simply done by adding the line /xmlrcp.php into the blocking part of Wordfence)

This would imitate brute force protection such as Fail2Ban on SSH etc The sky's the limit, right? I'm sure one could do a lot of fun things if one's up for it but , as stated earlier, I'm lazy :-)

Historical source · JufCorp: Securing your servers, users and customers online

Just remember , the same thing goes for antivirus as for 0day attacks, if you antivirus provider hasn't released any protection against that virus you just got into your system , there's not that much you can do about it, more than start cleaning your server once you the antivirus updated or even restore your server to a state prior to the virus. These days there are also a few other approaches to finding viruses such as Sentinel One that's not signature based.. Very cool actually. Still, an antivirus is not the single point of protection.

Brute force attacks Another method of rendering you server useless is to use a brute force attack on the usernames (sometimes also known as a "dictionary attack" ) .

Use an automatic brute force prevention software ( I can recommend you some that can block attacks on RDWeb, RDP, Exchange Webmail, FTP, Citrix., basically anything that uses Windows Authentication or help you set it up if you like)

Practical review checklist

Frequently asked questions

Should I choose Guard or a network firewall?

They solve different parts of the problem and are normally complementary.

Why block locally if I have a firewall?

Because the host has authentication/application context and can respond without requiring upstream firewall changes.

Use the same principles with Scantide Guard

Scantide Guard combines preconfigured collectors, Custom Monitors, per-monitor policy, successful-login learning, explainable firewall enforcement and optional Datacenter management across Windows and Linux.

Explore Scantide Guard Custom Monitors Datacenter