Sheridan Posted January 31, 2022 Posted January 31, 2022 Got a weird issue with firewall rules on 2019 server. The server has a GPO that allows RDP from some specific IP addresses (separate range from normal network) but it still allows RDP from other subnets - in fact any routable subnets When I check the server firewall rules, the only rule allowing 3389 in is the one with the specific IPs, there isn't a whitelist rule to allow RDP for all, so I don't know how its not working. Running the RSOP shows that 3389 is only enabled by that GPO/rule, yet the firewall log shows an RDP attempt from an IP not in the list as ALLOWed to 3389 - where else can it whitelisted like this that I'm missing?
Steve21 Posted January 31, 2022 Posted January 31, 2022 Have you checked the default firewall rules? There’s three that are enabled as soon as you turn RDP on and they wouldn’t show in RSOP as it’s local rules Steve
Sheridan Posted January 31, 2022 Author Posted January 31, 2022 Yeah I deleted those so they don't apply. I think its because the setting 'Allow users to connect remotely by using Remote Desktop Services' was enabled - which overrides everything, switch it off and no one can access. So it looks like that setting is too much of a global setting to user when you need firewall granularity
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now