How it works
RDP-FIDO-GATE 1.23 and newer can run a gate in code mode. Port 3389 stays blocked by the Windows Firewall. The client asks for the current code from your authenticator app; when the gate accepts it, the port opens for your IP for about 90 seconds and the RDP client connects. Windows still asks for its own password afterwards.
A gate signs people in one way — with keys or with codes. The mode is chosen at installation and can be switched later.
Step 1. Install the gate in code mode
- Interactive: run the gate installer on the host and pick the authenticator-app option on the “How will people sign in?” page.
- Silent:
msiexec /i RdpFidoGate-Setup.msi GATEAUTH=totp /qn. - An existing gate:
RdpFidoGate.exe auth totpas administrator. The gate restarts in the new mode;auth fidoswitches back. - On a Linux host the same command is
rdpfido-gate auth totp.
Step 2. Enroll an authenticator
- On the host run
RdpFidoGate.exe codeto get a one-time enrollment code. - In the client add a session with the host address, port 7440 and that code.
- The client shows a QR code and the secret. Scan it with the authenticator app.
- Type the first 6-digit code from the app to confirm. The account is enrolled.
An administrator can also create an account on the gate itself: RdpFidoGate.exe totp add NAME prints the QR code in the console, and totp test NAME CODE checks a code.
Step 3. Connect
Click the session, type the current code, and the RDP session opens. Each code is accepted once only, so a code seen over someone's shoulder cannot be replayed.
Limits worth knowing
- A code opens RDP only. The low-latency FIDO Stream mode and pushing gate updates from the client stay with hardware keys.
- Wrong codes are throttled per address and for the gate as a whole: 30 wrong codes within 10 minutes pause code sign-in for 10 minutes.
- Clients older than 1.23 are asked to update before they can use a code gate.
- An authenticator code is a strong second factor, but it is not phishing-resistant the way a FIDO2 key is: a user can be tricked into reading a code to someone. Where an insurer or a policy asks for phishing-resistant MFA, use keys.
Codes or keys?
| Authenticator code | FIDO2 key | |
|---|---|---|
| Hardware to buy | None — a phone app | A security key per person (or Windows Hello) |
| Phishing-resistant | No | Yes |
| Opens RDP | Yes | Yes |
| Opens FIDO Stream | No | Yes |
| Works offline on the user side | Yes | Yes |