Why a key in front of RDP, not inside it
Most RDP break-ins do not defeat the login screen — they reach it. Port 3389 is scanned around the clock, and once it answers, attackers try stolen passwords and unpatched pre-authentication bugs.
A gate in front of RDP changes the order of events. The port is blocked by the Windows Firewall by default. You prove possession of a hardware key first; only then does the firewall open 3389 — for your IP address alone and for about 90 seconds. To everyone else the port never answers.
What you need
- A Windows host with Remote Desktop: Windows 10 version 1903 or newer, Windows 11 or Windows Server.
- Any FIDO2 / WebAuthn key that Windows recognises — YubiKey, Feitian, SoloKeys and similar. Windows Hello works as a key too.
- RDP-FIDO-GATE: the gate on the host, the client on the PC you connect from. Both are in one installer and the Free edition is enough.
- For access from the internet: the ability to forward two TCP ports on the router.
Step 1. Install the gate on the host
- Download
RdpFido-Setup.exeon the machine you want to reach, run it and choose Host. Windows asks for administrator confirmation. - The installer enables Remote Desktop with NLA, binds a TLS certificate to the gate port 7440 and starts the gate service.
- The last page shows a one-time key enrollment code, valid for 15 minutes, together with the machine's addresses. Note the address and the code.
- If the code expires, run
RdpFidoGate.exe codeas administrator to get a new one.
For a management system the gate installs silently: msiexec /i RdpFidoGate-Setup.msi /qn.
Step 2. Forward the ports (internet access only)
On the same LAN you can skip this step. From the internet, forward two ports on the router to the host's LAN address:
| External port | Protocol | Purpose |
|---|---|---|
| 7440 | TCP | The gate: control channel and key confirmation |
| 3389 | TCP | RDP — passes only while the gate holds it open for your IP |
Reserve the host's LAN address in the router's DHCP settings, and use a DDNS name if your public IP changes. Forwarding 3389 does not expose RDP: the host firewall keeps it blocked until the key is confirmed.
Step 3. Install the client and enroll the key
- On your own PC run the same
RdpFido-Setup.exeand choose Client. It installs per user and needs no administrator rights. - Activate the client with your e-mail address: a code arrives by mail.
- Add a session: the host address, gate port 7440 and the one-time enrollment code from step 1.
- Touch the key when asked. The key is now registered for this host.
Step 4. Connect
Click the session tile and touch the key. The gate verifies the WebAuthn signature, opens 3389 for your current IP for about 90 seconds and the client starts mstsc. Windows then asks for its own password as usual — so the session is protected by two independent factors.
The gate re-asserts the firewall block every 30 seconds, so an opening cannot be left behind.
Check that it works
- From outside,
Test-NetConnection <host> -Port 7440must returnTcpTestSucceeded : True. Test-NetConnection <host> -Port 3389must fail until you have touched the key. That is the point.- If a session does not open, check that the gate service is running, that both ports are forwarded to the host's current LAN address and that the public IP has not changed.