1.2.1.1.1.2.13 Configure 'Windows Firewall: Allow inbound Remote Desktop exceptions'

Information

Many organizations use Remote Desktop connections in their normal troubleshooting procedures or operations. To provide flexibility for remote administration, the Windows Firewall: Allow inbound Remote Desktop exceptions setting is available. Some attacks have exploited the ports that are typically used by Remote Desktop.

Solution

Configure the following Group Policy setting in a manner that is consistent with the security and operational requirements of your organization-

Computer Configuration\Administrative Templates\Network\Network Connections\Windows Firewall\Domain Profile\Windows Firewall- Allow inbound Remote Desktop exceptions

Impact- If you enable this policy setting, Windows Firewall opens TCP port 3389 for inbound connections. You must also specify the IP addresses or subnets from which these inbound messages are allowed. If you disable this policy setting, Windows Firewall blocks this port and prevents the computer from receiving Remote Desktop requests. If an administrator adds this port to a local port exceptions list in an attempt to open it, Windows Firewall does not open the port. Computers in your environment should accept Remote Desktop requests from as few computers as possible.

See Also

https://workbench.cisecurity.org/files/42

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(11), CCE|CCE-16825-2

Plugin: Windows

Control ID: 1687979987fd0498699030bd4ac58f4eb3c7d7dbf656ed556cf1ea35bd0dd390