Description
A firewall rule allowing TCP port 3389 from every address can permit unnecessary connections to a Remote Desktop service. Actual reachability depends on the target VM, routing, other firewall policies and the running service. Network connectivity does not grant permission to log in.
Use approved sources and controlled administration paths such as VPN or IAP.
Potential impact
- The service may receive more password-guessing attempts or logins using leaked credentials.
- Compromise of a vulnerable service or account can affect the server and other internal assets.
Remediation
- Remove unnecessary RDP access. Where required, apply the rule only to the actual administration path and necessary target VMs.
- Use approved source ranges or a controlled management path, and maintain strong authentication and service updates.
- After applying changes, verify that required administrator connections succeed and unwanted connections are blocked.
Examples
Deployment Manager support has ended. These are legacy firewall-setting excerpts. Configure the actual network and targets in a supported management tool, and replace the sample range with the approved administrator source range.
Before
resources:
- name: firewall
type: compute.v1.firewall
properties:
name: my-firewall
sourceRanges:
- 0.0.0.0/0
allowed:
- IPProtocol: tcp
ports:
- "3389"
This allows incoming TCP 3389 traffic from all IPv4 addresses. Actual exposure depends on the targets and network path.
After
resources:
- name: firewall
type: compute.v1.firewall
properties:
name: my-firewall
sourceRanges:
- 10.10.10.0/24
allowed:
- IPProtocol: tcp
ports:
- "3389"
This restricts sources to 10.10.10.0/24. A private range does not make every user authorized; verify the actual administrator addresses and connection path.