CPGuard Firewall ทำงานอย่างไร ป้องกัน Brute Force และ IP Blacklist
CPGuard Firewall ป้องกันเซิร์ฟเวอร์จากการโจมตีเครือข่ายทุกรูปแบบ ตั้งแต่ Brute Force ไปจนถึง DDoS
สารบัญ
CPGuard Firewall คืออะไร
CPGuard Firewall คือโมดูลที่ควบคุมการรับส่ง Network Traffic ระดับ IP และ Port บนเซิร์ฟเวอร์ Hosting ทำงานร่วมกับ Linux Firewall (iptables/nftables) เพื่อ Block IP อันตราย จำกัด Rate ของ Connection และป้องกันการโจมตีที่พุ่งมาที่ Port สำคัญ เช่น SSH (22), FTP (21), SMTP (25) และอื่นๆ ทำงานประสานกับ WAF และ Malware Scanner ของ CPGuard เพื่อสร้างชั้นป้องกันครบวงจร
CPGuard Firewall controls network traffic at the IP and port level on hosting servers, working with the Linux firewall (iptables/nftables) to block dangerous IPs, rate-limit connections, and protect critical ports such as SSH (22), FTP (21), and SMTP (25). It works in concert with CPGuard WAF and Malware Scanner for comprehensive layered protection.
- Block IP อันตรายอัตโนมัติจาก Blacklist ทั่วโลก
- Rate Limiting ป้องกัน Connection Flood
- Port Control เปิด/ปิด Port ที่ไม่ต้องการ
- ทำงานร่วมกับ iptables/nftables ของ Linux
- Dashboard ดู Real-time Traffic ที่น่าสงสัย
IP Blacklist และ Auto-blocking
CPGuard ดึงฐานข้อมูล IP Blacklist จากแหล่งข้อมูลความปลอดภัยชั้นนำและอัปเดตอัตโนมัติ ทำให้ IP ที่เคยโจมตีเซิร์ฟเวอร์อื่นทั่วโลกถูก Block โดยอัตโนมัติก่อนที่จะเข้ามา Request ใดๆ ยิ่งไปกว่านั้น เมื่อ CPGuard ตรวจพบการโจมตีจาก IP ใหม่ที่ยังไม่อยู่ใน Blacklist ก็จะเพิ่มเข้าอัตโนมัติและแชร์ข้อมูลกลับไปยังฐานข้อมูลกลาง
CPGuard pulls IP blacklist data from leading security threat intelligence feeds and updates automatically — pre-blocking IPs known to have attacked other servers worldwide before they can make any request. When CPGuard detects an attack from an IP not yet in the blacklist, it adds it automatically and can contribute the data back to the central threat intelligence database.
- ดึง Threat Intelligence Feed จากแหล่งนำระดับโลก
- Block IP อันตรายก่อน Request ถึงเซิร์ฟเวอร์
- Auto-add IP ที่พบการโจมตีใหม่ในเซิร์ฟเวอร์นั้น
- Whitelist IP ที่เชื่อถือได้เพื่อป้องกัน False Block
- ดู Block Log ย้อนหลังได้ทั้งหมด
Rate Limiting และ Connection Throttling
Rate Limiting คือการจำกัดจำนวน Connection หรือ Request ต่อวินาทีจาก IP เดียวกัน CPGuard ตั้งค่า Limit ได้ตามประเภท Traffic เช่น HTTP Request, SMTP Connection, SSH Login เมื่อ IP เกิน Limit ระบบจะ Throttle หรือ Block ชั่วคราว ทำให้การโจมตีแบบ Flood หรือ DDoS ขนาดเล็กไม่สามารถทำ Server ให้ล้นได้
Rate limiting caps the number of connections or requests per second from any single IP. CPGuard applies limits per traffic type — HTTP requests, SMTP connections, SSH login attempts. When an IP exceeds the limit, the system throttles or temporarily blocks it, preventing small-scale flood and DDoS attacks from overwhelming the server.
- ตั้ง Limit แยกตาม Protocol: HTTP, SMTP, FTP, SSH
- Throttle อัตโนมัติเมื่อเกิน Threshold
- Temporary Block สำหรับ IP ที่ Flood ซ้ำๆ
- ปรับ Sensitivity ได้ตาม Traffic Pattern ของเซิร์ฟเวอร์
Port Control และ Service Hardening
เซิร์ฟเวอร์ทั่วไปเปิด Port จำนวนมากที่ไม่จำเป็นต้องใช้ทุก Port ในทุกสถานการณ์ CPGuard Firewall ช่วยปิด Port ที่ไม่ใช้งาน ทำให้ Surface Area ที่ผู้โจมตีเข้าถึงได้แคบลง รวมถึงตั้งกฎให้เปิดเฉพาะ IP ที่กำหนดสำหรับ Service สำคัญ เช่น ให้เข้า SSH ได้เฉพาะจาก IP ของ Admin เท่านั้น
Servers commonly have many ports open unnecessarily. CPGuard Firewall helps close unused ports, reducing the attack surface accessible to intruders. It also enables rules that restrict access to critical services — for example, allowing SSH only from specific administrator IP addresses.
- ปิด Port ที่ไม่ใช้งานลดพื้นที่โจมตี
- Restrict SSH/FTP ให้เข้าได้จาก IP กำหนดเท่านั้น
- Block Port Scan จาก IP ภายนอก
- Custom Rule สำหรับ Port พิเศษของแต่ละ App
การป้องกัน DDoS เบื้องต้น
CPGuard Firewall ช่วยรับมือ DDoS ขนาดเล็กถึงกลางได้ผ่าน Rate Limiting และ Connection Throttling อย่างไรก็ตาม DDoS ขนาดใหญ่ที่ Bandwidth เกินความสามารถของ Uplink เซิร์ฟเวอร์ต้องการ Upstream DDoS Mitigation จาก ISP หรือ CDN Provider เช่น Cloudflare ในระดับนั้น CPGuard ทำงานเป็น Layer สุดท้ายที่กรอง Traffic ที่ผ่านระบบ Upstream มาแล้ว
CPGuard Firewall handles small-to-medium DDoS through rate limiting and connection throttling. Large-scale volumetric DDoS that saturates the server uplink requires upstream mitigation from an ISP or CDN provider. At that scale, CPGuard operates as the last filtering layer for traffic that passes through upstream systems.
- รับมือ DDoS ขนาดเล็ก-กลางได้ด้วย Rate Limiting
- DDoS ขนาดใหญ่ต้องการ Upstream Mitigation เพิ่มเติม
- ทำงานร่วมกับ CDN Upstream ได้เป็น Last-mile Filter
- Block Known DDoS Source IP จาก Threat Intelligence
Firewall Log และ Monitoring
CPGuard Firewall เก็บ Log การ Block ทุกครั้งพร้อม Timestamp, Source IP, Destination Port และเหตุผลที่ Block ทำให้ Admin ตรวจสอบรูปแบบการโจมตีได้ ดูว่า IP กลุ่มไหนโจมตีมาซ้ำๆ และปรับกฎให้เหมาะสมมากขึ้น Dashboard แบบ Real-time ช่วยให้เห็นภาพรวมสถานะความปลอดภัยของเซิร์ฟเวอร์ตลอดเวลา
CPGuard Firewall logs every block event with timestamp, source IP, destination port, and reason for blocking — allowing administrators to analyse attack patterns, identify repeat offenders, and tune rules over time. The real-time dashboard provides a continuous security status overview of the server.
- Log ทุก Block Event พร้อม Timestamp และ Source IP
- กรอง Log ตาม IP, Port, Protocol, วันที่
- Export Log สำหรับ SIEM หรือการตรวจสอบภายนอก
- Dashboard Real-time แสดงสถานะปัจจุบัน
GeoIP Blocking
CPGuard รองรับ GeoIP Blocking ที่ Block การเข้าถึงจากประเทศที่กำหนด ฟีเจอร์นี้มีประโยชน์สำหรับเว็บที่ Target Audience อยู่ในไทยหรืออาเซียน และไม่มีเหตุผลที่ Traffic จากบางภูมิภาคจะต้องเข้าถึง Admin Area หรือ Login Port ลดปริมาณ Noise จาก Bot ต่างประเทศได้มาก
CPGuard supports GeoIP blocking to restrict access from specified countries. This is useful for sites targeting Thai or Southeast Asian audiences that have no legitimate reason for traffic from certain regions to access admin areas or login ports — significantly reducing noise from foreign bots.
- Block IP จากประเทศที่กำหนดได้
- ใช้ GeoIP Database ที่อัปเดตสม่ำเสมอ
- เหมาะกับเว็บที่ไม่มี Traffic จากต่างประเทศ
- Apply เฉพาะ Port หรือ URL ที่ต้องการ ไม่ต้อง Block ทั้งประเทศ
Hosting ที่มี Firewall ระดับ Server
Server Firewall ที่ดีเป็นส่วนสำคัญของ Infrastructure ที่ปลอดภัย ถามผู้ให้บริการว่ามีการตั้งค่า Firewall อย่างไรและมีระบบ Auto-blocking หรือไม่ AsiaGB.com ให้บริการ Hosting และ VPS ที่มีระบบรักษาความปลอดภัยระดับเซิร์ฟเวอร์ SSD Storage, DirectAdmin, Support ภาษาไทย 24 ชั่วโมง และ uptime 99%
A well-configured server firewall is a critical component of secure hosting infrastructure. Ask providers how their server firewall is configured and whether automatic threat blocking is in place. AsiaGB.com provides hosting and VPS with server-level security, SSD storage, DirectAdmin, 24-hour Thai support, and 99% uptime.
- ถามผู้ให้บริการว่ามี Firewall ระดับ Server ตั้งค่าอย่างไร
- Auto-blocking ของ IP อันตรายสำคัญมากสำหรับ Security
- Hosting ที่ดีควรมี Firewall และ Rate Limiting อยู่แล้ว