Port 3389: RDP

Windows Remote Desktop. The most common way into Windows servers for ransomware groups. Put it behind a VPN or restrict by source address.

  • Free
  • No Sign-Up
  • Runs in Your Browser

Examples:

Ports

1 of 41

Port Lookup

Port 3389 at a glance

Port3389
ProtocolTCP/UDP
ServiceRDP
Open to the Internet?Only to addresses that need it
See What Is Listeningss -lntup | grep ':3389 '
Test From Outsidenc -zv your-server 3389
Block with UFWufw deny 3389/tcp; ufw deny 3389/udp
Block with nftablesnft add rule inet filter input meta l4proto { tcp, udp } th dport 3389 drop

RDP uses TCP/UDP port 3389. Windows Remote Desktop.

The most common way into Windows servers for ransomware groups. Put it behind a VPN or restrict by source address.

Allow port 3389 only from the addresses that need it: your office, a VPN or a bastion host. The firewall rule generator builds those rules for nftables, iptables and UFW.

Questions

What is port 3389 used for?
RDP. Windows Remote Desktop.
Is it safe to open port 3389?
Only to addresses that need it. The most common way into Windows servers for ransomware groups. Put it behind a VPN or restrict by source address.
How do I check if port 3389 is open?
On the server, ss -lntup | grep ':3389 ' shows what is listening. From another machine, nc -zv your-server 3389 shows whether the firewall lets it through.
How do I block port 3389?
With UFW: ufw deny 3389/tcp and ufw deny 3389/udp. With nftables, add a drop rule for dport 3389 in your input chain.

Abuse from open ports on your VMs?

Frabs spots amplification, scans and floods leaving any VM and stops them, without touching your firewall.