Description
Allowing RDP port 3389 from 0.0.0.0/0 or ::/0 lets internet hosts attempt to reach the remote administration service. Restrict administrative access to approved networks and connection paths.
Potential impact
The server may face more brute-force attempts or connections using stolen credentials, increasing the risk of compromise.
Remediation
Restrict the source ranges of RDP firewall rules to administrator networks. Provide the required path through a VPN or administration host, and remove unnecessary RDP allow rules.
Examples
These examples restrict RDP sources to 10.20.0.0/24. Replace this range with the actual administrator network and provide a connection path from that network.
Before
hcl
resource "google_compute_firewall" "rdp_open" {
name = "test-firewall"
network = google_compute_network.default.name
direction = "INGRESS"
allow {
protocol = "tcp"
ports = ["3389"]
}
source_ranges = ["0.0.0.0/0"]
}
After
hcl
resource "google_compute_firewall" "rdp_restricted" {
name = "test-firewall"
network = google_compute_network.default.name
direction = "INGRESS"
allow {
protocol = "tcp"
ports = ["3389"]
}
source_ranges = ["10.20.0.0/24"]
}