Skip to content
Networking & DNSIntermediate

TSplus Advanced Security: Installation, Static IP and Port Forwarding

Quick Answer TSplus Advanced Security is security software installed on a Windows computer or server to help control access, block suspicious connections and...

BI
Bison Technical Team Enterprise IT specialists
Updated 07 Oct 2026 10 min read 1 total views
Structured technical guidanceSafety notes included where requiredSources listed below

Quick Answer

TSplus Advanced Security is security software installed on a Windows computer or server to help control access, block suspicious connections and detect ransomware activity. Install it with administrator privileges, configure its protection settings and verify that legitimate users can still connect. It protects an existing remote-access environment; it does not create a remote desktop service or web portal by itself.

You do not need a static public IP or router port forwarding just to install Advanced Security. Those requirements depend on how users reach the server. For a typical TSplus Remote Access HTTPS portal, the external port is TCP 443. Native Remote Desktop Protocol (RDP) normally uses 3389, but access through a VPN is preferable to exposing RDP directly. Keep the server’s local IP stable when creating forwarding rules. :chatgpt-content-reference{index="0"}

Advertisement

How TSplus Advanced Security Works

The software applies protection on the Windows machine where it is installed. Its controls address different parts of server security:

Protection Purpose
Bruteforce Protection Monitors failed sign-ins and blocks source IP addresses when configured thresholds are reached.
Hacker IP Protection Blocks addresses identified as malicious by the product’s threat information.
Geographic Protection Restricts connections according to allowed countries and related access rules.
Firewall and IP lists Lets administrators manage blocked and trusted addresses.
Working Hours Limits when designated users or groups can access the server.
Ransomware Protection Analyzes activity for ransomware behavior and provides response controls.
Trusted Devices Applies restrictions based on approved client device names.

Check which features your purchased license includes. Treat these controls as additional protection alongside Windows updates, endpoint security, strong authentication and tested backups. Device-name restrictions should not be treated as a replacement for multifactor authentication. :chatgpt-content-reference{index="1"}

Before You Install

  • Check compatibility: The dedicated vendor prerequisites page lists Windows 11 Pro and Windows Server 2016, 2019, 2022 and 2025 among compatible systems. It specifies .NET Framework 4.7.2 or later. Use an operating system that also receives applicable Microsoft security updates; product compatibility alone does not establish operating-system security support.
  • Use an administrator account: Installation and security configuration require elevated permissions.
  • Prepare recovery access: Have a local console, virtual-machine console or another independent administrative route available.
  • Record existing settings: Save the server’s network configuration, router forwarding rules and relevant security policies.
  • Confirm the access method: Decide whether users need a VPN, native RDP or a separately installed TSplus Remote Access web portal.
  • Schedule a maintenance window: Allow time for prerequisite installation, policy testing and any requested restart.

The dedicated prerequisites page should be checked before deployment because requirements can change. :chatgpt-content-reference{index="2"}

Warning: IP restrictions, country restrictions and firewall changes can block your own administrative connection. Do not apply restrictive policies over your only available remote session without a recovery route.

Install TSplus Advanced Security

  1. Open the official installation page linked in Sources and download the Advanced Security installer from its download link.
  2. On the Windows machine to protect, right-click the downloaded installer and select Run as administrator.
  3. Select the installation language if requested.
  4. Choose Recommended for a standard installation. The Advanced option provides additional choices such as custom proxy settings or downloading without installing.
  5. Read and accept the license agreement, then complete the setup wizard.
  6. Open TSplus Advanced Security and confirm that its interface loads.
  7. Review the license status and activate your purchased license when appropriate. The installation documentation describes a fully featured 15-day trial.

Follow any restart prompt shown by the installer. :chatgpt-content-reference{index="3"}

Configure Protection Before Allowing External Access

1. Review trusted administrative addresses

Use the Firewall section to review blocked and whitelisted IP addresses. If a trusted management address needs an exception, add only the necessary address and give it a meaningful description. Identify the address the server actually sees; a remote administrator’s private home address may differ from the source address recorded on the server.

Keep exceptions narrow. Whitelisting an entire shared network can exempt more devices than intended. :chatgpt-content-reference{index="4"}

2. Check Bruteforce Protection

Confirm that the relevant Windows and HTML5 sign-in monitoring indicators are healthy. The vendor documents a default threshold of 10 failed attempts per source IP, but review the settings displayed in your installed version.

Choose thresholds appropriate for your users and account-lockout policy. Several users behind the same public IP may share the consequences of an IP block. Investigate repeated failures rather than simply increasing the limit. :chatgpt-content-reference{index="5"}

3. Apply geographic and working-hour restrictions gradually

Allow the countries needed by your users before enforcing country restrictions. Include legitimate travel and VPN exit locations in your planning. Test working-hour restrictions with a noncritical account before applying them broadly.

4. Configure ransomware protection

On a known-clean server, use the documented learning period to establish normal application behavior. Exercise legitimate business applications during testing, then review protection events and exceptions. Keep independent backups with a tested restore procedure.

Use the dashboard and event view to review activity after each policy change. :chatgpt-content-reference{index="6"}

Do You Need a Static IP at the Server Location?

Distinguish the server’s address inside the office network from the internet-facing address assigned by the internet service provider.

Address Example Role
Server’s local IP 192.168.1.50 Identifies the server inside the local network. Keep it stable for forwarding rules.
Router’s public IP Assigned by the ISP Identifies the internet-facing connection used for direct inbound access.
DNS hostname remote.example.com Provides a name that resolves to the intended external endpoint.

A static public IP is convenient for a business service, but a changing public IP can work with correctly configured Dynamic DNS. A stable local address can be maintained through a router DHCP reservation or a carefully configured static address. :chatgpt-content-reference{index="7"}

Check for carrier-grade NAT: If your ISP places the connection behind carrier-grade NAT (CGNAT), a forwarding rule on your office router alone will not normally provide inbound access. Ask the ISP about a public routable address, or use a suitable managed access solution. Dynamic DNS does not remove CGNAT. :chatgpt-content-reference{index="8"}

Which Port Should You Open?

There is no universal “Advanced Security port” to forward for users. Select the port according to the service they will use.

Connection method Typical port Configuration guidance
Advanced Security protection on the server No user-access forwarding rule solely for installation Do not expose a service simply because protection software is installed.
TSplus Remote Access HTTPS portal TCP 443 by default Forward to the actual HTTPS listener or designated gateway. Configure a trusted TLS certificate.
HTTP web service TCP 80 by default Open only for a documented requirement, such as an intended redirect or certificate-validation workflow. Use HTTPS for user access.
Native RDP 3389 by default Prefer VPN access. TCP is used for connectivity; UDP requirements depend on the RDP deployment.
VPN Depends on the VPN Follow the VPN product’s instructions; there is no single universal VPN port.

TSplus Remote Access web ports are configurable. Its prerequisites guidance recommends closing external TCP 3389 when only web-based connections are needed. Opening TCP 443 does not install a portal or convert an RDP listener into HTTPS. :chatgpt-content-reference{index="9"}

Warning: Directly exposing RDP increases the server’s exposure to internet attacks. Microsoft recommends VPN access instead. Installing Advanced Security or choosing an unusual external port does not remove that risk.

Example: Forward HTTPS to a TSplus Remote Access Server

This example assumes that TSplus Remote Access is already installed, its HTTPS service works internally, and the server has the local address 192.168.1.50. Substitute your actual address and listener port.

Router field Example value
Rule name TSplus-HTTPS
External or WAN port 443
Internal destination address 192.168.1.50
Internal destination port 443
Protocol TCP
Allowed source Approved client public addresses where practical
  1. Reserve the server’s local address and verify that the intended HTTPS service is reachable inside the network.
  2. Sign in to the router using an authorized administrator account.
  3. Locate Port Forwarding, Virtual Server or the equivalent NAT configuration page.
  4. Create the single forwarding rule shown above, adjusted for your environment.
  5. Check that the applicable Windows firewall rule permits the service on its actual internal port. If another firewall or cloud security group is present, review that layer too.
  6. Ensure the chosen WAN port is not already assigned to another service or router administration.
  7. Point your chosen hostname to the correct public endpoint and configure a certificate matching that hostname.
  8. Test from a separate internet connection, such as a mobile hotspot.

Router menus differ by manufacturer and firmware. Avoid placing the server in a router DMZ merely to make connectivity work; use specific forwarding rules. :chatgpt-content-reference{index="10"}

Verify Connectivity and Protection

Test the TCP connection

On a Windows client, open PowerShell. Administrator privileges are not normally required for this diagnostic command. Replace the example hostname with your actual server hostname:

Test-NetConnection -ComputerName remote.example.com -Port 443 -InformationLevel Detailed

TcpTestSucceeded: True means a TCP connection to that destination port succeeded. It does not prove that the TLS certificate is valid, authentication works or Advanced Security is correctly configured. A failed ping alone does not establish that the TCP service is unavailable. :chatgpt-content-reference{index="11"}

Test the complete user workflow

  • Open the configured HTTPS hostname and confirm that no certificate warning appears.
  • Sign in with a normal user account and launch an authorized application or session.
  • Confirm that the intended access restrictions are applied.
  • Review Advanced Security’s dashboard, monitoring status and events.
  • Test a denied-access policy only with a controlled test account or source and an independent recovery session available.

A successful login proves accessibility. Verifying a specific protection requires checking its configuration and corresponding events.

Troubleshooting

Symptom Checks Next action
Works locally but fails externally WAN address, forwarding destination, protocol, source restrictions and upstream NAT Correct the matching rule or resolve the upstream connectivity issue.
Forwarding appears correct but remains unreachable Public WAN address, CGNAT, double NAT and ISP restrictions Ask the ISP about inbound connectivity. With two routers, review the complete path.
Access stops after security configuration Blocked IP list, country rules, working hours and device restrictions Use console access to identify and reverse the specific incorrect restriction.
TCP test succeeds but the browser reports a certificate error Certificate hostname, validity and trust chain Correct the certificate or hostname rather than bypassing the warning.
Works over mobile data but not from the office using the public hostname Router NAT loopback support and internal DNS resolution Use an appropriate internal DNS configuration or supported router setting.
Several users are blocked together Shared public source address and repeated failed sign-ins Correct stale credentials or the responsible client before changing protection thresholds.

For forwarding failures, first confirm that the service works locally. Then check the router and upstream network. Avoid disabling all firewall protection as a diagnostic shortcut. :chatgpt-content-reference{index="12"}

Rollback and Recovery

  1. If a newly exposed service creates a problem, disable its new router forwarding rule first.
  2. Use local or independent console access if remote administration is blocked.
  3. Review the recorded changes and undo the specific incorrect security rule.
  4. Restore the previous network settings if an address change caused the failure.
  5. Retest legitimate access before introducing the restriction again.

If uninstalling Advanced Security becomes necessary, follow the official uninstall procedure and review its option for removing previously blocked IP addresses. Do not assume that uninstalling automatically removes every blocking rule. :chatgpt-content-reference{index="13"}

Frequently Asked Questions

Can I enter a static public IP directly on the Windows server?

In a typical office network behind a router, the public IP belongs on the ISP-facing connection. The Windows server uses a private local address. Public addressing directly on a server requires a deliberately designed network configuration.

Can I use external port 8443 instead of 443?

Yes, if the router supports translating external TCP 8443 to the server’s actual HTTPS port. Users must specify the external port in the URL. This changes the connection address, not the underlying security requirements. :chatgpt-content-reference{index="14"}

Does whitelisting an address automatically open the router port?

No. Advanced Security’s IP exception and the router’s forwarding rule are separate controls. The service must also be listening, and the remaining firewall layers must permit the connection.

Do I need to forward ports when users connect through an existing VPN?

You generally do not need a public forwarding rule to the server’s RDP service when the VPN already provides authorized access to its private address. The VPN endpoint has its own connectivity requirements. :chatgpt-content-reference{index="15"}

Should I open both 443 and 3389 for browser access?

Open only the ports required by the selected connection method. For a deployment exclusively using the TSplus web client, the vendor recommends closing external TCP 3389. :chatgpt-content-reference{index="16"}

Sources

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy. Unsubscribe at any time.