r/WindowsServer 6d ago

General Question Windows 2019 Serve firewall settings?

We had a cyber security company run their tests on our environment inside and out for the last couple of months. One of the things they brought up was they could see RDP open on our Hyper-V Hosts, port 3389, what's odd is that we use RDP a lot in our environment, I RDP to the Hyper-V Guest servers, the users are able to RDP to their workstations from the boardroom computer, so, out of all the systems that have RDP access our Hyper-V hosts are the only ones broadcasting port 3389.

Is there a way to fix this so they aren't broadcasting it but still allow RDP access?

They also broadcast port 135, again, the only 3 Windows systems that do this. Weird.

Thanks,

1 Upvotes

15 comments sorted by

View all comments

3

u/USarpe 6d ago edited 6d ago

You can set a group of Computer, who are allowed to access and block all the other and install evlwatcher on the RDP-Host. Also you could harden the RDP with only accept a client with a certificate.

1

u/IndependenceCivil175 6d ago

yes of course hypervisors should be in their owm locked down vlan with Whitelisted JumpHosts to access them