Guides · RDP-FIDO-GATE

How to stop exposing RDP port 3389 to the internet

If Remote Desktop is reachable from the internet, it is being scanned right now. The common fixes — a different port number, an IP allow-list, account lockout — each solve part of the problem. This guide explains what actually removes the exposure and how to set it up on a single Windows machine.

Updated

What an open port costs you

Fixes that do not fix it

MeasureWhat it doesWhat it leaves
Move RDP to another portHides it from the laziest scannersFull-range scanners find it; the service is just as reachable
IP allow-list on the firewallWorks well for fixed office addressesBreaks for home, mobile and travelling users with changing IPs
Account lockout policySlows password guessingThe port still answers; attackers can lock out your users on purpose
Strong passwords onlyStops guessingDoes nothing against a stolen or phished password

The approach that works: default-deny, opened on proof

The exposure disappears when the port is blocked for everyone and opens only for a user who has already proven who they are — and only for that user's address. A VPN does this at the network level. A port gate does it for RDP alone, without a VPN to run.

RDP-FIDO-GATE implements it with the Windows Firewall on the host itself. Port 3389 is blocked. A small gate service listens on TCP 7440 and accepts only a FIDO2 key confirmation (or, in code mode, an authenticator code). After a valid confirmation the gate adds a firewall rule for the caller's IP, keeps it for about 90 seconds — long enough for the RDP client to connect — and removes it. An established session continues; new connections are blocked again. Every 30 seconds the gate re-asserts the block.

Set it up

  1. On the host run RdpFido-Setup.exe, choose Host and note the one-time enrollment code on the last page.
  2. If the host is behind a router, forward 7440/TCP and 3389/TCP to its LAN address. The forwarded 3389 stays closed at the host firewall until a key is confirmed.
  3. On your PC run the installer again, choose Client, add a session with the host address, port 7440 and the code, and touch your key to enroll it.
  4. Click the session and touch the key to connect.

The RDP port keeps working as before until the first key is enrolled, so you cannot lock yourself out half-way through the installation.

Verify from the outside

Run these from a machine outside your network, before touching the key:

Test-NetConnection your-host.example.com -Port 7440   # TcpTestSucceeded : True
Test-NetConnection your-host.example.com -Port 3389   # TcpTestSucceeded : False

The first line shows the gate is reachable; the second shows RDP is not. An external port scan of your address should now list 7440 only.

Several machines behind one router

Give each host its own pair of external ports — for example 7440 and 3389 for the first, 7450→7440 and 3390→3389 for the second — and enter those external ports in the client session. Each host runs its own gate and keeps its own keys.

RDP-FIDO-GATE

RDP-FIDO-GATE keeps port 3389 closed and opens it for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. The Free edition covers 10 saved sessions.

Frequently asked questions

Is port 7440 not just another exposed port?

It is exposed, but it does not offer a login. The gate accepts a signed WebAuthn assertion from an enrolled key over TLS and nothing else — there is no password to guess. Compare that with 3389, which offers the full RDP stack to anyone.

What happens to my session after 90 seconds?

Nothing. The window limits when a new connection may start. An established RDP session keeps running after the rule is removed.

Does it work on a cloud VM?

Yes. Allow TCP 7440 and 3389 in the cloud provider's security group; the gate on the VM keeps 3389 blocked at the Windows Firewall until a key is confirmed.

Do I still need a VPN?

For Remote Desktop alone, no. If users also need file shares or internal web applications, a VPN covers those; the gate still adds a hardware-key check in front of RDP inside the VPN.

Related guides