Local evidence comes first
A reputation entry should have provenance: which server saw the activity, which collector produced the evidence, when it occurred and why policy decided it was significant. Shared intelligence without origin context becomes difficult to trust.
Do not publish every temporary block
NAT, shared hosting, proxies and compromised legitimate systems make IP reputation imperfect. Guard distinguishes local enforcement from deliberately published permanent/public reputation observations.
Managed environments need one publisher
When a Guard server is enrolled in Datacenter, Datacenter is the natural central publisher. This prevents every managed server from independently reporting the same event and preserves a cleaner audit trail.
Cache external intelligence
Reputation lookup should not turn every authentication event into an external API call. Guard can cache locally, while Datacenter can provide shared caching/proxy behavior for managed servers.
Reputation is context, not proof
An address appearing in AbuseIPDB, Scantide Global Reputation or another provider is useful evidence. It should not erase local policy, trusted sources or administrator review.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Web Attack & Scanner Protection for IIS, Apache and NginxA single Guard can protect its own server with local policy and local firewall enforcement. Organizations with multiple systems can add Scantide Guard Datacenter for shared policy, fleet visibility, licensing and coordinated reputation services.
Current Scantide source: Scantide Guard Product & Server Security GuidesHost-level intrusion and abuse prevention for Windows and Linux using authentication logs, web evidence, reputation context and local firewall response.
Current Scantide source: Scantide Guard DatacenterManage multiple Guard servers from one control point: distribute policy, see attack activity across the fleet, coordinate shared blocking and reputation, and understand which systems are protected.
Current Scantide source: Scantide Guard Product & Server Security GuidesLinux server brute-force and hostile web request protection for SSH, Apache, Nginx, Tomcat and WildFly using local evidence and nftables enforcement.
Current Scantide source: Web Attack & Scanner Protection for IIS, Apache and NginxGuard is focused on log/evidence-driven host protection and controlled firewall response. It is not positioned as a full reverse-proxy WAF replacement.
Field experience from the archive
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsIn many environments, local firewalls are disabled out of pure laziness. "We can't be bothered troubleshooting why SQL traffic doesn't work .." Have local firewalls enabled , enable logging so you can easily find what's going on. If you're in a shared environment you'll also get alerted about noisy neighbors . Local firewalls also enables you to utilize a brute force prevention software and have those attacks mitigated, no matter where they come from. If you want, I'll happily help you out with getting a brute force prevention software in place.
Historical source · JufCorp: Securing your servers, users and customers onlineMinimize the attack surface behind a good firewall that can deal with the SYN Floods and port scans and stuff. Be cautious not to open up anything more than what's absolutely necessary to and from the outside world. Use local firewalls also!
Practical review checklist
- A single Guard can protect its own server with local policy and local firewall enforcement.
- Host-level intrusion and abuse prevention for Windows and Linux using authentication logs, web evidence, reputation context and local firewall response.
- Manage multiple Guard servers from one control point: distribute policy, see attack activity across the fleet, coordinate shared blocking and reputation, and understand which systems are protected.
- Linux server brute-force and hostile web request protection for SSH, Apache, Nginx, Tomcat and WildFly using local evidence and nftables enforcement.
- Guard is focused on log/evidence-driven host protection and controlled firewall response.
- In many environments, local firewalls are disabled out of pure laziness.
- Minimize the attack surface behind a good firewall that can deal with the SYN Floods and port scans and stuff.