Description
RDP provides remote administration of Windows VMs and commonly uses TCP port 3389. Allowing that port from 0.0.0.0/0 or ::/0 lets clients with no administrative need attempt connections to a reachable RDP service.
When a Google Cloud firewall combines source_ranges and source_tags, a source only needs to satisfy either one. Adding a source tag therefore does not narrow an unrestricted address range.
Potential impact
- Reachable RDP services can become targets for brute-force attacks and login attempts using compromised credentials.
- Exploitation of a service vulnerability or account compromise can affect the VM and resources accessible to that account.
Remediation
- Identify the VMs and administrators that need RDP, then limit allowed sources to the required administrator networks. Check whether other rules allowing all ports or broad ranges also include
3389. - Use an administrative path through IAP TCP forwarding or a VPN, and remove or restrict directly exposed RDP rules. Configure the permissions and firewall settings required by that path.
- Review effective firewall policies and operating-system access controls. Verify that required management connections work and connections from other sources are blocked.
Examples
These historical examples are not deployable as written. The underscore in test_object is invalid in a firewall name, and the google.cloud 1.14.0 module rejects the combinations of source and target options shown. Use a valid name and supported option combinations in an actual configuration.
First configuration
- name: rdp_in_port
google.cloud.gcp_compute_firewall:
name: test_object
source_ranges:
- "0.0.0.0/0"
allowed:
- ip_protocol: tcp
ports:
- "22"
- "80"
- "3389"
target_tags:
- test-ssh-server
- staging-ssh-server
source_tags:
- test-ssh-clients
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
This configuration is written to allow TCP port 3389 from 0.0.0.0/0. The accompanying source_tags do not narrow the allowed source range.
Comparison configuration
- name: create a firewall
google.cloud.gcp_compute_firewall:
name: test_object
allowed:
- ip_protocol: tcp
ports:
- '80'
target_tags:
- test-ssh-server
- staging-ssh-server
source_tags:
- test-ssh-clients
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
The comparison specifies only TCP port 80. If RDP administration is needed, configure a separate restricted management path and review the access allowed by other firewall rules.