| Windows 7: Windows 7 firewall - allow alternate ports for RDP |
10 Aug 2009
|
#1 | | |
Windows 7 firewall - allow alternate ports for RDP Hi all,
I'm looking for help configuring Windows 7 (RTM) firewall to allow traffic for an alternate Remote Desktop listening port in the most secure way possible. I know how to just open up the port completely, which works, but I'd rather not do that if I can just open it up for the Remote Desktop program.
I don't seem to be able to just "copy" the built-in Remote Desktop rule and change the port because the port number cannot be edited in some of the built in rules (or copies thereof, I guess). If it matters, I need to be able to access this port with both "old" and "new" versions of Remote Desktop (from an XP machine, as well as another windows 7 machine, for example).
Can anyone offer any assistance or otherwise offer any advice for my situation?
Thanks,
Scott | My System Specs |
| System Manufacturer/Model Number Home built OS Windows 7 RTM CPU Xeon E3110 3.0 GHz Motherboard Asus P5E-VM HDMI Memory 4 GB Patriot Extreme DDR2 Graphics Card On-board Sound Card On-board PSU See case Case Antec NSK1380 MicroATX with 350W PSU Hard Drives Western Digital WD7500AACS 750 GB |
10 Aug 2009
|
#2 | | Windows 7 Ultimate x64 SP1 Somewhere on the 3rd rock from the sun. |
AFAIK, RDP has always used 3389 - why would you need separate posts? After all, you cannot have multiple RD sessions, anyway, coming into the machine, so I fail to see the need for alternate ports....
Have you tried editing the existing ED rule to just add another port? | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number The Beast Model V OS Windows 7 Ultimate x64 SP1 CPU Core i7 965 EE @3.6 GHz Motherboard eVGA x58 Classified3 Memory 3 * 4GB Mushkin Enh Redline CL7 DDR3 1600 MHz (PC3-12800) Graphics Card eVGA 560 Ti 448 Core Classified + eVGA GTX260 SSC (PhysX) Sound Card Realtek HD Audio (on-board) Monitor(s) Displays 2 * Acer X213Wbd Screen Resolution 2 * 1680 x 1050 Keyboard Logitech G15 Keyboard Mouse Logitech Performance Mouse MX PSU ThermalTake BlackWidow TX TR2 850 W Case ThermalTake Level 10 GT (Black) Cooling Corsair H100 CPU | 2 * TT 140mm TriLED | 2 * Antec TriCool Hard Drives 1 * Intel Cheryville 520 180 GB SATA III SSD |
1 * Intel X-25M G2 80 GB SATA II SSD |
2 * Seagate 1 TB 32MB Cache 7200.12 SATA II Mech. Internet Speed Cable - 35 Mbit down / 12 Mbit up advertised (30 / 6 act.) Antivirus M$Se / MBAM Pro / WinPatrol Pro Browser Chome(dev) / Canary / Firefox Minefield / Opera Next / IE 10 Other Info Wacom Bamboo Touch |
Hauppauge WinTV-HVR-1850 |
Optimus STAV-3400 AV Receiver |
Bose 301 Series III Speakers (Main channel) |
Bose 161 Speakers (Surround) |
Optimus 3 way 100-W speaker (Center) |
Logitech Clearchat PC Wireless Headset |
Koss ProDJ 100 Headphones |
Microsoft LifeCam Studio |
Motorola Droid BIONIC |
ASUS Transformer Infinity 64GB |
10 Aug 2009
|
#3 | | |
Thanks for the reply. The reason I'd like to open alternate ports is because I have two computers behind my router that I'd like to connect to with Remote Desktop. I have the router configured to forward requests on port 3389 to one computer, and another port for the other computer.
As for editing the existing rule, when I try to do that I get the following message:
"This is a predefined rule and some of its properties cannot be modified." | My System Specs | | System Manufacturer/Model Number Home built OS Windows 7 RTM CPU Xeon E3110 3.0 GHz Motherboard Asus P5E-VM HDMI Memory 4 GB Patriot Extreme DDR2 Graphics Card On-board Sound Card On-board PSU See case Case Antec NSK1380 MicroATX with 350W PSU Hard Drives Western Digital WD7500AACS 750 GB |
10 Aug 2009
|
#4 | | Windows 7 Ultimate x64 SP1 Somewhere on the 3rd rock from the sun. |
Hmmm, doesn't your router allow port mapping? I mean that it takes incoming, say port 4455, and sends that to IP#1 @ port 3389, and takes incoming @ port 3389 and sends to IP #2 @ 3389?
As for editing the existing rule, yah, saw that myself when I started fooling with it.
However, I think using the path Code: %windir%\system32\mstsc.exe I think you might be able to create a second rule if need be....and make it a separate port.... | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number The Beast Model V OS Windows 7 Ultimate x64 SP1 CPU Core i7 965 EE @3.6 GHz Motherboard eVGA x58 Classified3 Memory 3 * 4GB Mushkin Enh Redline CL7 DDR3 1600 MHz (PC3-12800) Graphics Card eVGA 560 Ti 448 Core Classified + eVGA GTX260 SSC (PhysX) Sound Card Realtek HD Audio (on-board) Monitor(s) Displays 2 * Acer X213Wbd Screen Resolution 2 * 1680 x 1050 Keyboard Logitech G15 Keyboard Mouse Logitech Performance Mouse MX PSU ThermalTake BlackWidow TX TR2 850 W Case ThermalTake Level 10 GT (Black) Cooling Corsair H100 CPU | 2 * TT 140mm TriLED | 2 * Antec TriCool Hard Drives 1 * Intel Cheryville 520 180 GB SATA III SSD |
1 * Intel X-25M G2 80 GB SATA II SSD |
2 * Seagate 1 TB 32MB Cache 7200.12 SATA II Mech. Internet Speed Cable - 35 Mbit down / 12 Mbit up advertised (30 / 6 act.) Antivirus M$Se / MBAM Pro / WinPatrol Pro Browser Chome(dev) / Canary / Firefox Minefield / Opera Next / IE 10 Other Info Wacom Bamboo Touch |
Hauppauge WinTV-HVR-1850 |
Optimus STAV-3400 AV Receiver |
Bose 301 Series III Speakers (Main channel) |
Bose 161 Speakers (Surround) |
Optimus 3 way 100-W speaker (Center) |
Logitech Clearchat PC Wireless Headset |
Koss ProDJ 100 Headphones |
Microsoft LifeCam Studio |
Motorola Droid BIONIC |
ASUS Transformer Infinity 64GB |
10 Aug 2009
|
#5 | | |
I tried using:
%windir%\system32\mstsc.exe
as the program name, but this rule does not work. I'm trying to connect from an XP computer, so my guess is that the XP version and the windows 7 version of the mstsc.exe are different enough that the windows 7 firewall doesn't recognize them as the same for the purposes of the rule. That's the best I could come up with.
With respect to the port mapping, my router software (linksys wrt54g2) only allows me to forward incoming ports to IP addresses, not specific ports at that IP address. Maybe a third party firmware for the router would allow me to do this? That would be pretty slick, and would probably be a good solution to my problem... I'll look into it. | My System Specs | | System Manufacturer/Model Number Home built OS Windows 7 RTM CPU Xeon E3110 3.0 GHz Motherboard Asus P5E-VM HDMI Memory 4 GB Patriot Extreme DDR2 Graphics Card On-board Sound Card On-board PSU See case Case Antec NSK1380 MicroATX with 350W PSU Hard Drives Western Digital WD7500AACS 750 GB |
12 Aug 2009
|
#7 | | |
Hi all,
Thanks for the replies. In the end, I took JohnGalt's advice and set up port-to-port (single port) forwarding. Because the Linksys WRT54G2 default firmware doesn't allow this, I flashed my router with DD-WRT, which does allow port-to-port forwarding. This allowed me to keep the Remote Desktop listening at port 3389 (default) and also use the built-in Windows Firewall rules, while at the same time directing external Remote Desktop requests to two different computers on my home network by specifying the port from the RDP client. | My System Specs | | System Manufacturer/Model Number Home built OS Windows 7 RTM CPU Xeon E3110 3.0 GHz Motherboard Asus P5E-VM HDMI Memory 4 GB Patriot Extreme DDR2 Graphics Card On-board Sound Card On-board PSU See case Case Antec NSK1380 MicroATX with 350W PSU Hard Drives Western Digital WD7500AACS 750 GB |
03 Sep 2009
|
#8 | | |
scottfreeze,
I had this same problem and the solution is actually so rediculously simple that I wanted to slam my head against the wall after fighting with it for hours.
You create a custom rule with the program specifications set exactly like the preconfigured one. In other words, you assign the rule to a specific program and the path is "System". Set it to your custom TCP port and save it. Go back and edit it, go to the Advanced tab and make sure you allow Edge Traversal. As long as you port forward it in your router then you're golden.
I could do what you did, but I feel much more comfortable with it being on a completely different port. | My System Specs | | |
06 Sep 2009
|
#9 | | Windows 7 Ultimate x64 SP1 Somewhere on the 3rd rock from the sun. |

Quote: Originally Posted by scottfreeze Hi all,
Thanks for the replies. In the end, I took JohnGalt's advice and set up port-to-port (single port) forwarding. Because the Linksys WRT54G2 default firmware doesn't allow this, I flashed my router with DD-WRT, which does allow port-to-port forwarding. This allowed me to keep the Remote Desktop listening at port 3389 (default) and also use the built-in Windows Firewall rules, while at the same time directing external Remote Desktop requests to two different computers on my home network by specifying the port from the RDP client. I am highly surprised that the native Router did not allow port forwarding in the settings. however, you're still better off with DD-WRT - it rocks.
****
Good answer, Kaosu - I didn't think about the Edge traversal part of the FW settings. makes sense, in retrospect. Stickified and Rep added. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number The Beast Model V OS Windows 7 Ultimate x64 SP1 CPU Core i7 965 EE @3.6 GHz Motherboard eVGA x58 Classified3 Memory 3 * 4GB Mushkin Enh Redline CL7 DDR3 1600 MHz (PC3-12800) Graphics Card eVGA 560 Ti 448 Core Classified + eVGA GTX260 SSC (PhysX) Sound Card Realtek HD Audio (on-board) Monitor(s) Displays 2 * Acer X213Wbd Screen Resolution 2 * 1680 x 1050 Keyboard Logitech G15 Keyboard Mouse Logitech Performance Mouse MX PSU ThermalTake BlackWidow TX TR2 850 W Case ThermalTake Level 10 GT (Black) Cooling Corsair H100 CPU | 2 * TT 140mm TriLED | 2 * Antec TriCool Hard Drives 1 * Intel Cheryville 520 180 GB SATA III SSD |
1 * Intel X-25M G2 80 GB SATA II SSD |
2 * Seagate 1 TB 32MB Cache 7200.12 SATA II Mech. Internet Speed Cable - 35 Mbit down / 12 Mbit up advertised (30 / 6 act.) Antivirus M$Se / MBAM Pro / WinPatrol Pro Browser Chome(dev) / Canary / Firefox Minefield / Opera Next / IE 10 Other Info Wacom Bamboo Touch |
Hauppauge WinTV-HVR-1850 |
Optimus STAV-3400 AV Receiver |
Bose 301 Series III Speakers (Main channel) |
Bose 161 Speakers (Surround) |
Optimus 3 way 100-W speaker (Center) |
Logitech Clearchat PC Wireless Headset |
Koss ProDJ 100 Headphones |
Microsoft LifeCam Studio |
Motorola Droid BIONIC |
ASUS Transformer Infinity 64GB Windows 7 firewall - allow alternate ports for RDP problems? All times are GMT -5. The time now is 12:53 AM. | |