How to change RDP's default port

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to change RDP's default port

L1 Bithead

As you know, the RDP's default port is 3389,  but someone always try to connect via this default port, this result the domain 

 

accounts are locked frequently. so I would like to chang its default port,such as 33089, then others don't know the port,

 

so they can't use this port to try remote desktop access, the question is How I config in Palo Alto to achieve this target?

 

My device is PA-500.

 

thanks in advance

1 ACCEPTED SOLUTION

Accepted Solutions

you won't need the custom application as your connection is normal RDP and APP-ID will identify it as that application, even if it is not running on the default port

 

you will need to make sure your security policy allows the connection

 

security.png

nat.png

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

View solution in original post

13 REPLIES 13

Cyber Elite
Cyber Elite

you can accomplish this by creating a NAT policy to do port translation

 

translate.png

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

L1 Bithead

Thank you for your reply, but could you tell me the entire process?  what is the service 7777 in your screenshot?

in my example port 7777 is the 'original' destination port

 

 

so what this rule does is from my trust network 192.168.0.0/24 to my dms 10.0.0.0/24

the firewall takes the role of host 192.168.0.5

 

anyone in the trust network connecting to 192.168.0.5 from trust, on port 7777 will be translated to dmz server 10.0.0.5 on port 3389

rdp.png

 

i can create a security policy that blocks direct connections to 3389 and only allows 7777

Tom Piens
PANgurus - SASE and Strata specialist; (co)managed services, VAR and consultancy

Ok ,my question is where I can create the "original' destination port 7777"? Thanks

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!