GCP firewall allows unrestricted RDP access

Allowing RDP from every address exposes reachable services to unnecessary authentication attempts and attacks. Limit access to the sources and paths needed for administration.

Description

RDP provides remote administration of Windows VMs and commonly uses TCP port 3389. Allowing that port from 0.0.0.0/0 or ::/0 lets clients with no administrative need attempt connections to a reachable RDP service.

When a Google Cloud firewall combines source_ranges and source_tags, a source only needs to satisfy either one. Adding a source tag therefore does not narrow an unrestricted address range.

Potential impact

  • Reachable RDP services can become targets for brute-force attacks and login attempts using compromised credentials.
  • Exploitation of a service vulnerability or account compromise can affect the VM and resources accessible to that account.

Remediation

  • Identify the VMs and administrators that need RDP, then limit allowed sources to the required administrator networks. Check whether other rules allowing all ports or broad ranges also include 3389.
  • Use an administrative path through IAP TCP forwarding or a VPN, and remove or restrict directly exposed RDP rules. Configure the permissions and firewall settings required by that path.
  • Review effective firewall policies and operating-system access controls. Verify that required management connections work and connections from other sources are blocked.

Examples

These historical examples are not deployable as written. The underscore in test_object is invalid in a firewall name, and the google.cloud 1.14.0 module rejects the combinations of source and target options shown. Use a valid name and supported option combinations in an actual configuration.

First configuration

yaml
- name: rdp_in_port
  google.cloud.gcp_compute_firewall:
    name: test_object
    source_ranges:
      - "0.0.0.0/0"
    allowed:
      - ip_protocol: tcp
        ports:
          - "22"
          - "80"
          - "3389"
    target_tags:
      - test-ssh-server
      - staging-ssh-server
    source_tags:
      - test-ssh-clients
    project: test_project
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present

This configuration is written to allow TCP port 3389 from 0.0.0.0/0. The accompanying source_tags do not narrow the allowed source range.

Comparison configuration

yaml
- name: create a firewall
  google.cloud.gcp_compute_firewall:
    name: test_object
    allowed:
    - ip_protocol: tcp
      ports:
      - '80'
    target_tags:
    - test-ssh-server
    - staging-ssh-server
    source_tags:
    - test-ssh-clients
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present

The comparison specifies only TCP port 80. If RDP administration is needed, configure a separate restricted management path and review the access allowed by other firewall rules.

References