The method of modifying port 3389
The method of modifying port 3389
In order to prevent others from scanning the remote desktop connection port and ensure the security of the server, we can modify port 3389.
There are a total of two steps: one is to modify the server-side port settings; the other is the client connection method. The method is as follows (take Windows Server 2003 as an example, other systems are for reference only):
First, modify the port settings on the server side (there are 2 places in the registry that need to be modified)
1. The first place:
[HKEY_LOCAL_MACHINE\ SYSTEM\ CurrentControlSet\ Control\ Terminal Server\ Wds\ rdpwd\ Tds\ tcp]
The value of PortNumber is 3389 by default. Select decimal and change it to the port you want (range from 1024 to 65535 and cannot conflict with each other), such as 6000, as shown below:
2. The second place:
[HKEY_LOCAL_MACHINE\ SYSTEM\ CurrentControlSet\ Control\ Terminal Server\ WinStations\ RDP-Tcp]
The value of PortNumber is 3389 by default. Select decimal and change it to the port you want (range from 1024 to 65535 and cannot conflict with each other), such as 6000, as shown below:
3. Restart the system to make the settings effective.
Note: the two modified ports should be the same.
As a matter of fact, it is possible to modify only the second point.
In addition, the standard connection form in the second place is [HKEY_LOCAL_MACHINE\ SYSTEM\ CurrentControlSet\ Control\ Terminal Server\ WinStations\], which indicates a specific RDP-TCP connection (there should be one or more RDP-TCP-like subkeys here, depending on how many RDP services you set up), and change the PortNumber as well.
II. Client connection method
1. Open the remote Desktop connection: type "mstsc" in the run under win 7/win 8/win 10).
2. The format of the connection: IP: the modified port, such as 10.10.10.10V6000