Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Open RDP Port 3389 for an entire subnet

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      pfsenselearner
      last edited by

      Hello everybody,
      Can someone please give me a tip. I would like for a short time to open port 3389 in one subnet so that they can access via RDP to an external computer. Have PFSense in the current version. Is it sufficient under Firewall / Rules / WAN to set a corresponding rule? If yes how? IPv4 TCP / Destination: WAN Address / Destination Port: 3389 / Source ???

      Thanks and Greetings

      pfsenselearner

      1 Reply Last reply Reply Quote 0
      • chpalmerC
        chpalmer
        last edited by

        ~~Yes it can be done by some port forwarding and redirects. But is it safe?  By no means would it be.

        Your best bet would be to set up VPN (s) and then you could access anything on the LAN on the other side of the firewall without allowing the rest of the world to try and steal your access.

        People will pound on your RDP for days if you open it up to the world.

        Otherwise..  pick a port for each of your LAN clients that you want to RDP into.  Port Forward-  destination port 600 as an example..~~ Edit-  this is outbound traffic the OP is asking about..  read below.    ;)

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        1 Reply Last reply Reply Quote 0
        • chpalmerC
          chpalmer
          last edited by

          Probably another way or two to do it but this would be the way I would do it.

          You can restrict who can access these by limiting the source address to certain IP's but VPN is the way to go.

          Triggering snowflakes one by one..
          Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

          1 Reply Last reply Reply Quote 0
          • P
            pfsenselearner
            last edited by

            Thank you very much!!
            Is it also possible without forwarding? So for a whole subnet at once?
            I know it is very uncertain!

            Thanks and regards

            1 Reply Last reply Reply Quote 0
            • jahonixJ
              jahonix
              last edited by

              This is a double post to the german section as well.
              There it was clearer that the intention is for all local PCs to reach out with RDP to one host.
              It's outbound traffic and shouldn't need special care.

              1 Reply Last reply Reply Quote 0
              • chpalmerC
                chpalmer
                last edited by

                Ah- Thanks jahonix!  Reading slower I see that now.

                pfsenselearner-  what he said.    :)

                Just read that thread there (with a little help from Google) and glad to see your getting help there.

                Good luck!    :)

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                1 Reply Last reply Reply Quote 0
                • P
                  pfsenselearner
                  last edited by

                  Hello,
                  sorry for the confusion and the double post!!

                  Thank You all

                  greetings pfsenselearner

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.