TSplus Advanced Security: Installation, Static IP and Port Forwarding
Quick Answer TSplus Advanced Security is security software installed on a Windows computer or server to help control access, block suspicious connections and...
Quick Answer
TSplus Advanced Security is security software installed on a Windows computer or server to help control access, block suspicious connections and detect ransomware activity. Install it with administrator privileges, configure its protection settings and verify that legitimate users can still connect. It protects an existing remote-access environment; it does not create a remote desktop service or web portal by itself.
You do not need a static public IP or router port forwarding just to install Advanced Security. Those requirements depend on how users reach the server. For a typical TSplus Remote Access HTTPS portal, the external port is TCP 443. Native Remote Desktop Protocol (RDP) normally uses 3389, but access through a VPN is preferable to exposing RDP directly. Keep the server’s local IP stable when creating forwarding rules. :chatgpt-content-reference{index="0"}
How TSplus Advanced Security Works
The software applies protection on the Windows machine where it is installed. Its controls address different parts of server security:
| Protection | Purpose |
|---|---|
| Bruteforce Protection | Monitors failed sign-ins and blocks source IP addresses when configured thresholds are reached. |
| Hacker IP Protection | Blocks addresses identified as malicious by the product’s threat information. |
| Geographic Protection | Restricts connections according to allowed countries and related access rules. |
| Firewall and IP lists | Lets administrators manage blocked and trusted addresses. |
| Working Hours | Limits when designated users or groups can access the server. |
| Ransomware Protection | Analyzes activity for ransomware behavior and provides response controls. |
| Trusted Devices | Applies restrictions based on approved client device names. |
Check which features your purchased license includes. Treat these controls as additional protection alongside Windows updates, endpoint security, strong authentication and tested backups. Device-name restrictions should not be treated as a replacement for multifactor authentication. :chatgpt-content-reference{index="1"}
Before You Install
- Check compatibility: The dedicated vendor prerequisites page lists Windows 11 Pro and Windows Server 2016, 2019, 2022 and 2025 among compatible systems. It specifies .NET Framework 4.7.2 or later. Use an operating system that also receives applicable Microsoft security updates; product compatibility alone does not establish operating-system security support.
- Use an administrator account: Installation and security configuration require elevated permissions.
- Prepare recovery access: Have a local console, virtual-machine console or another independent administrative route available.
- Record existing settings: Save the server’s network configuration, router forwarding rules and relevant security policies.
- Confirm the access method: Decide whether users need a VPN, native RDP or a separately installed TSplus Remote Access web portal.
- Schedule a maintenance window: Allow time for prerequisite installation, policy testing and any requested restart.
The dedicated prerequisites page should be checked before deployment because requirements can change. :chatgpt-content-reference{index="2"}
Install TSplus Advanced Security
- Open the official installation page linked in Sources and download the Advanced Security installer from its download link.
- On the Windows machine to protect, right-click the downloaded installer and select Run as administrator.
- Select the installation language if requested.
- Choose Recommended for a standard installation. The Advanced option provides additional choices such as custom proxy settings or downloading without installing.
- Read and accept the license agreement, then complete the setup wizard.
- Open TSplus Advanced Security and confirm that its interface loads.
- Review the license status and activate your purchased license when appropriate. The installation documentation describes a fully featured 15-day trial.
Follow any restart prompt shown by the installer. :chatgpt-content-reference{index="3"}
Configure Protection Before Allowing External Access
1. Review trusted administrative addresses
Use the Firewall section to review blocked and whitelisted IP addresses. If a trusted management address needs an exception, add only the necessary address and give it a meaningful description. Identify the address the server actually sees; a remote administrator’s private home address may differ from the source address recorded on the server.
Keep exceptions narrow. Whitelisting an entire shared network can exempt more devices than intended. :chatgpt-content-reference{index="4"}
2. Check Bruteforce Protection
Confirm that the relevant Windows and HTML5 sign-in monitoring indicators are healthy. The vendor documents a default threshold of 10 failed attempts per source IP, but review the settings displayed in your installed version.
Choose thresholds appropriate for your users and account-lockout policy. Several users behind the same public IP may share the consequences of an IP block. Investigate repeated failures rather than simply increasing the limit. :chatgpt-content-reference{index="5"}
3. Apply geographic and working-hour restrictions gradually
Allow the countries needed by your users before enforcing country restrictions. Include legitimate travel and VPN exit locations in your planning. Test working-hour restrictions with a noncritical account before applying them broadly.
4. Configure ransomware protection
On a known-clean server, use the documented learning period to establish normal application behavior. Exercise legitimate business applications during testing, then review protection events and exceptions. Keep independent backups with a tested restore procedure.
Use the dashboard and event view to review activity after each policy change. :chatgpt-content-reference{index="6"}
Do You Need a Static IP at the Server Location?
Distinguish the server’s address inside the office network from the internet-facing address assigned by the internet service provider.
| Address | Example | Role |
|---|---|---|
| Server’s local IP | 192.168.1.50 | Identifies the server inside the local network. Keep it stable for forwarding rules. |
| Router’s public IP | Assigned by the ISP | Identifies the internet-facing connection used for direct inbound access. |
| DNS hostname | remote.example.com | Provides a name that resolves to the intended external endpoint. |
A static public IP is convenient for a business service, but a changing public IP can work with correctly configured Dynamic DNS. A stable local address can be maintained through a router DHCP reservation or a carefully configured static address. :chatgpt-content-reference{index="7"}
Check for carrier-grade NAT: If your ISP places the connection behind carrier-grade NAT (CGNAT), a forwarding rule on your office router alone will not normally provide inbound access. Ask the ISP about a public routable address, or use a suitable managed access solution. Dynamic DNS does not remove CGNAT. :chatgpt-content-reference{index="8"}
Which Port Should You Open?
There is no universal “Advanced Security port” to forward for users. Select the port according to the service they will use.
| Connection method | Typical port | Configuration guidance |
|---|---|---|
| Advanced Security protection on the server | No user-access forwarding rule solely for installation | Do not expose a service simply because protection software is installed. |
| TSplus Remote Access HTTPS portal | TCP 443 by default | Forward to the actual HTTPS listener or designated gateway. Configure a trusted TLS certificate. |
| HTTP web service | TCP 80 by default | Open only for a documented requirement, such as an intended redirect or certificate-validation workflow. Use HTTPS for user access. |
| Native RDP | 3389 by default | Prefer VPN access. TCP is used for connectivity; UDP requirements depend on the RDP deployment. |
| VPN | Depends on the VPN | Follow the VPN product’s instructions; there is no single universal VPN port. |
TSplus Remote Access web ports are configurable. Its prerequisites guidance recommends closing external TCP 3389 when only web-based connections are needed. Opening TCP 443 does not install a portal or convert an RDP listener into HTTPS. :chatgpt-content-reference{index="9"}
Example: Forward HTTPS to a TSplus Remote Access Server
This example assumes that TSplus Remote Access is already installed, its HTTPS service works internally, and the server has the local address 192.168.1.50. Substitute your actual address and listener port.
| Router field | Example value |
|---|---|
| Rule name | TSplus-HTTPS |
| External or WAN port | 443 |
| Internal destination address | 192.168.1.50 |
| Internal destination port | 443 |
| Protocol | TCP |
| Allowed source | Approved client public addresses where practical |
- Reserve the server’s local address and verify that the intended HTTPS service is reachable inside the network.
- Sign in to the router using an authorized administrator account.
- Locate Port Forwarding, Virtual Server or the equivalent NAT configuration page.
- Create the single forwarding rule shown above, adjusted for your environment.
- Check that the applicable Windows firewall rule permits the service on its actual internal port. If another firewall or cloud security group is present, review that layer too.
- Ensure the chosen WAN port is not already assigned to another service or router administration.
- Point your chosen hostname to the correct public endpoint and configure a certificate matching that hostname.
- Test from a separate internet connection, such as a mobile hotspot.
Router menus differ by manufacturer and firmware. Avoid placing the server in a router DMZ merely to make connectivity work; use specific forwarding rules. :chatgpt-content-reference{index="10"}
Verify Connectivity and Protection
Test the TCP connection
On a Windows client, open PowerShell. Administrator privileges are not normally required for this diagnostic command. Replace the example hostname with your actual server hostname:
Test-NetConnection -ComputerName remote.example.com -Port 443 -InformationLevel Detailed
TcpTestSucceeded: True means a TCP connection to that destination port succeeded. It does not prove that the TLS certificate is valid, authentication works or Advanced Security is correctly configured. A failed ping alone does not establish that the TCP service is unavailable. :chatgpt-content-reference{index="11"}
Test the complete user workflow
- Open the configured HTTPS hostname and confirm that no certificate warning appears.
- Sign in with a normal user account and launch an authorized application or session.
- Confirm that the intended access restrictions are applied.
- Review Advanced Security’s dashboard, monitoring status and events.
- Test a denied-access policy only with a controlled test account or source and an independent recovery session available.
A successful login proves accessibility. Verifying a specific protection requires checking its configuration and corresponding events.
Troubleshooting
| Symptom | Checks | Next action |
|---|---|---|
| Works locally but fails externally | WAN address, forwarding destination, protocol, source restrictions and upstream NAT | Correct the matching rule or resolve the upstream connectivity issue. |
| Forwarding appears correct but remains unreachable | Public WAN address, CGNAT, double NAT and ISP restrictions | Ask the ISP about inbound connectivity. With two routers, review the complete path. |
| Access stops after security configuration | Blocked IP list, country rules, working hours and device restrictions | Use console access to identify and reverse the specific incorrect restriction. |
| TCP test succeeds but the browser reports a certificate error | Certificate hostname, validity and trust chain | Correct the certificate or hostname rather than bypassing the warning. |
| Works over mobile data but not from the office using the public hostname | Router NAT loopback support and internal DNS resolution | Use an appropriate internal DNS configuration or supported router setting. |
| Several users are blocked together | Shared public source address and repeated failed sign-ins | Correct stale credentials or the responsible client before changing protection thresholds. |
For forwarding failures, first confirm that the service works locally. Then check the router and upstream network. Avoid disabling all firewall protection as a diagnostic shortcut. :chatgpt-content-reference{index="12"}
Rollback and Recovery
- If a newly exposed service creates a problem, disable its new router forwarding rule first.
- Use local or independent console access if remote administration is blocked.
- Review the recorded changes and undo the specific incorrect security rule.
- Restore the previous network settings if an address change caused the failure.
- Retest legitimate access before introducing the restriction again.
If uninstalling Advanced Security becomes necessary, follow the official uninstall procedure and review its option for removing previously blocked IP addresses. Do not assume that uninstalling automatically removes every blocking rule. :chatgpt-content-reference{index="13"}
Frequently Asked Questions
Can I enter a static public IP directly on the Windows server?
In a typical office network behind a router, the public IP belongs on the ISP-facing connection. The Windows server uses a private local address. Public addressing directly on a server requires a deliberately designed network configuration.
Can I use external port 8443 instead of 443?
Yes, if the router supports translating external TCP 8443 to the server’s actual HTTPS port. Users must specify the external port in the URL. This changes the connection address, not the underlying security requirements. :chatgpt-content-reference{index="14"}
Does whitelisting an address automatically open the router port?
No. Advanced Security’s IP exception and the router’s forwarding rule are separate controls. The service must also be listening, and the remaining firewall layers must permit the connection.
Do I need to forward ports when users connect through an existing VPN?
You generally do not need a public forwarding rule to the server’s RDP service when the VPN already provides authorized access to its private address. The VPN endpoint has its own connectivity requirements. :chatgpt-content-reference{index="15"}
Should I open both 443 and 3389 for browser access?
Open only the ports required by the selected connection method. For a deployment exclusively using the TSplus web client, the vendor recommends closing external TCP 3389. :chatgpt-content-reference{index="16"}
Sources
- TSplus Advanced Security — Product Overview
- TSplus Advanced Security — Prerequisites
- TSplus Advanced Security — Installation and Uninstallation
- TSplus Advanced Security — Getting Started
- TSplus Advanced Security — Bruteforce Protection
- TSplus Remote Access — Network and Security Prerequisites
- Microsoft — Remote Desktop Access from Outside Your Network
- Microsoft — Test-NetConnection
- TP-Link — Port Forwarding Setup
- TP-Link — Troubleshooting Port Forwarding
Was this guide useful?
Your answer helps us keep BISONKB accurate and practical.