Link to home
Start Free TrialLog in
Avatar of willmarple
willmarple

asked on

Chage RDP listening port on a computer that is a member of a domain

I have a brand new, just built windows 7 ultimate x64 machine that I want to connect to via RDP on a port other than 3389.  I already changed the "PortNumber" registry key.  I've tested several different ports and ip addresses to check for conflicts.  I've found several articles implying that there is more to be done if a workstation is a member of a domain (this workstation is).  Please lend me your expertise!
Avatar of Lee W, MVP
Lee W, MVP
Flag of United States of America image

Make sure whatever port you put it on has an exception in the firewall (why are you doing this?  How are you connecting?  Is this open to the internet so I could hack it easily if I were to find the right IP?  Aren't you using VPN and if not, why not?
Yes, try it internally and see if it works.  if it does, then open the required port in the firewall.  As Leew says though, you should be putting any connections in over a VPN, changing the port number and allowing multiple connections through the router is insecure.

Make sure you check your firewall profiles.

The whole on a domain off a domain difference is rubbish, its only the authentication that changes, the principles of RDP remain the same.
Avatar of willmarple
willmarple

ASKER

The client wants to access the whole desktop, not just connect to server applications or shares of data.  Would using rdp over a vpn work just as well as this method?  There are multiple computers in the target LAN that are being rdp'ed in to.The first can obviously use 3389 but there are roughly 3 others that need to be configured to use a different port.  I will check the firewall.
After you change the port in the registry, you restarted your computer?
If you use a VPN, you have a more secure connection between the the remote computer and the target network.  Once connected to the VPN, you would connect via RDP as you would if you were local.  No port mappings needed.

Is this a Small Business Server domain?  If so, you should be using Remote Web Workplace.
@Coast-IT

I thought that the domain thing was rubbish.  I know the authentication changes but didn't know if there was some magical change that takes place when adding computer to a domain that affects rdp.  I will definitely make the recommendation to the client to use vpn.  However, I'm pretty sure that he's not going to go for buying any hardware so a software vpn using routing and remote access on their dc would be the only option.  What are your opinions about this as I'm sure a point to point hardware vpn with encryption would be the most secure?
@leew

They have Server 2008 R2 Standard on a new dell r710.  It's their only server though.  So remote web workspace is not available in this version?  Also I am not familiar with it, I'm assuming this is just a web based version of rdp?  Why is is better, does it use secure http?
ASKER CERTIFIED SOLUTION
Avatar of Lee W, MVP
Lee W, MVP
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Yea, agreed, RRAS is fine to use if it's the only option and I too have set it up on DCs when it's the only option.

His current firewall maybe capable of some simple VPN capabilities though, have you checked it out?
It's a dinky linksys.  I'm not sure that it's even one of the models that are capable of vpn.  Even if it were, we would have to buy an identical one for the other endpoint because they certainly don't support software vpn clients to connect do they?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
I agree with your proposal.  Please close this question as you have suggested.