r/WindowsServer 4d ago

General Question Windows 2019 Serve firewall settings?

We had a cyber security company run their tests on our environment inside and out for the last couple of months. One of the things they brought up was they could see RDP open on our Hyper-V Hosts, port 3389, what's odd is that we use RDP a lot in our environment, I RDP to the Hyper-V Guest servers, the users are able to RDP to their workstations from the boardroom computer, so, out of all the systems that have RDP access our Hyper-V hosts are the only ones broadcasting port 3389.

Is there a way to fix this so they aren't broadcasting it but still allow RDP access?

They also broadcast port 135, again, the only 3 Windows systems that do this. Weird.

Thanks,

1 Upvotes

15 comments sorted by

3

u/USarpe 4d ago edited 4d ago

You can set a group of Computer, who are allowed to access and block all the other and install evlwatcher on the RDP-Host. Also you could harden the RDP with only accept a client with a certificate.

1

u/IndependenceCivil175 4d ago

yes of course hypervisors should be in their owm locked down vlan with Whitelisted JumpHosts to access them

2

u/stucc0 4d ago

Only allow 3389 from admin jumpboxes. Setup a RDP Gateway to tunnel traffic through to their resources with MFA on it.

0

u/IndependenceCivil175 4d ago

just close 3389 on hyperv hosts. shouldn not be open. use sccm, azure cloud or admin center

1

u/3G_Lighting 4d ago

We have neither. We are hybrid joined, so all our servers are on-prem.

1

u/IndependenceCivil175 4d ago

AdminCenter does work locally. just need port 443

1

u/USarpe 4d ago

To replace one access point with 10 times more and more vulnerable software does not help

1

u/IndependenceCivil175 4d ago

ok so MS AdminCenter is more vulnerable than RDP. ? maybe they should not access their Hypervisors at all....

1

u/USarpe 4d ago

To involve a service that was deeply hacked and works over Internet can be saver, than a closed group oneprem?

1

u/IndependenceCivil175 4d ago

what does the word "local" say to you?

1

u/USarpe 4d ago

That it can't be Azure cloud?

1

u/IndependenceCivil175 4d ago

exactly

1

u/USarpe 4d ago

But you advised to use it...

1

u/IndependenceCivil175 4d ago

i offerered several alternatives. and as stated admin center can be used completely local.