What an open port costs you
- Password guessing and credential stuffing with leaked passwords, around the clock.
- Exposure to pre-authentication vulnerabilities in the RDP service itself: a bug of the BlueKeep kind needs only a reachable port.
- Account lockouts caused by the guessing, which lock out the real users.
- A finding in every external scan and on every cyber-insurance questionnaire.
Fixes that do not fix it
| Measure | What it does | What it leaves |
|---|---|---|
| Move RDP to another port | Hides it from the laziest scanners | Full-range scanners find it; the service is just as reachable |
| IP allow-list on the firewall | Works well for fixed office addresses | Breaks for home, mobile and travelling users with changing IPs |
| Account lockout policy | Slows password guessing | The port still answers; attackers can lock out your users on purpose |
| Strong passwords only | Stops guessing | Does nothing against a stolen or phished password |
The approach that works: default-deny, opened on proof
The exposure disappears when the port is blocked for everyone and opens only for a user who has already proven who they are — and only for that user's address. A VPN does this at the network level. A port gate does it for RDP alone, without a VPN to run.
RDP-FIDO-GATE implements it with the Windows Firewall on the host itself. Port 3389 is blocked. A small gate service listens on TCP 7440 and accepts only a FIDO2 key confirmation (or, in code mode, an authenticator code). After a valid confirmation the gate adds a firewall rule for the caller's IP, keeps it for about 90 seconds — long enough for the RDP client to connect — and removes it. An established session continues; new connections are blocked again. Every 30 seconds the gate re-asserts the block.
Set it up
- On the host run
RdpFido-Setup.exe, choose Host and note the one-time enrollment code on the last page. - If the host is behind a router, forward 7440/TCP and 3389/TCP to its LAN address. The forwarded 3389 stays closed at the host firewall until a key is confirmed.
- On your PC run the installer again, choose Client, add a session with the host address, port 7440 and the code, and touch your key to enroll it.
- Click the session and touch the key to connect.
The RDP port keeps working as before until the first key is enrolled, so you cannot lock yourself out half-way through the installation.
Verify from the outside
Run these from a machine outside your network, before touching the key:
Test-NetConnection your-host.example.com -Port 7440 # TcpTestSucceeded : True
Test-NetConnection your-host.example.com -Port 3389 # TcpTestSucceeded : False
The first line shows the gate is reachable; the second shows RDP is not. An external port scan of your address should now list 7440 only.
Several machines behind one router
Give each host its own pair of external ports — for example 7440 and 3389 for the first, 7450→7440 and 3390→3389 for the second — and enter those external ports in the client session. Each host runs its own gate and keeps its own keys.