Unrestricted RDP access in a GCP firewall

RDP port 3389 is open to the entire internet

Description

Allowing RDP port 3389 from 0.0.0.0/0 or ::/0 lets internet hosts attempt to reach the remote administration service. Restrict administrative access to approved networks and connection paths.

Potential impact

The server may face more brute-force attempts or connections using stolen credentials, increasing the risk of compromise.

Remediation

Restrict the source ranges of RDP firewall rules to administrator networks. Provide the required path through a VPN or administration host, and remove unnecessary RDP allow rules.

Examples

These examples restrict RDP sources to 10.20.0.0/24. Replace this range with the actual administrator network and provide a connection path from that network.

Before

hcl
resource "google_compute_firewall" "rdp_open" {
  name      = "test-firewall"
  network   = google_compute_network.default.name
  direction = "INGRESS"

  allow {
    protocol = "tcp"
    ports    = ["3389"]
  }

  source_ranges = ["0.0.0.0/0"]
}

After

hcl
resource "google_compute_firewall" "rdp_restricted" {
  name      = "test-firewall"
  network   = google_compute_network.default.name
  direction = "INGRESS"

  allow {
    protocol = "tcp"
    ports    = ["3389"]
  }

  source_ranges = ["10.20.0.0/24"]
}

References