So I have 3 terminal servers which are being attacked. This person, or group seems to know our employee naming convention because he is using all the correct names which is what scares me. We have strong passwords, but at this rate, I do not know how long they will hold up. I've changed the ports on the terminal servers, but that didn't stop them long. I have a security policy set to lock the account after 3 unsucessful tries, but my logs are showing these guys have tried over 20K times to login over the past week. When I attempt to login with bad passwords using various rdp clients I get disconnected and locked out for 30 minutes after 3 unsucessful attempts... so what is allowing these guys to continue to brute force 1000's of times a night?