Port 3389: Remote Desktop (RDP)
What it is, why it matters and how to restrict it.
The port of Windows Remote Desktop. It is one of the most attacked ports on the internet, used for password guessing and for exploiting RDP vulnerabilities.
Secure it
Put RDP behind a VPN or a gateway, require Network Level Authentication, and keep Windows patched. If you must allow direct access, limit it to fixed source addresses.
Allow only one address on Linux
sudo iptables -I INPUT 1 -p tcp --dport 3389 -j DROP sudo iptables -I INPUT 1 -p tcp -s 203.0.113.5 --dport 3389 -j ACCEPT
The drop rule goes in first and the allow rule is inserted above it, so 203.0.113.5 is matched first. Replace it with your own address. With ufw, the equivalent allow rule is:
sudo ufw allow from 203.0.113.5 to any port 3389 proto tcp
Windows Firewall
New-NetFirewallRule -DisplayName "RDP from one IP" -Direction Inbound -Protocol TCP -LocalPort 3389 -RemoteAddress 203.0.113.5 -Action Allow
Check from outside
nc -vz SERVER_IP 3389
Run it from an allowed address and from another one. A connection should succeed from the first and fail or time out from the second. Build custom rules with allow a port from specific IPs, or see all common ports.
FAQ
What is port 3389 used for?
Port 3389 is the default TCP port of Remote Desktop (RDP).
Should port 3389 be open to the internet?
Usually not. Keep it on localhost, behind a VPN, or limited to specific source IPs.
How do I block port 3389 for everyone except one IP?
Add an ACCEPT rule for that address, then a DROP rule for the port below it. The commands above do this in the correct order.