RDP port 3389 explained: TCP vs UDP and when to change it
Remote Desktop listens on port 3389, over TCP and UDP. Here is what each does, how to confirm the port on your server, and how to change it without locking yourself out.
Key takeaways
- RDP uses port 3389 by default, on both TCP and UDP. TCP carries the connection; UDP is an optional faster transport the client uses when it can.
- Check the configured port with
Get-ItemPropertyon theRDP-Tcpregistry key, and confirm it is listening withnetstat -ano. - Change it by editing the
PortNumbervalue, adding firewall rules for the new port, then restarting Remote Desktop Services. - A new port cuts automated scanning noise, but real protection comes from strong passwords, Network Level Authentication and limiting who can reach the port.
On this page
What port does RDP use?
Remote Desktop Protocol (RDP) listens on port 3389 by default, on TCP and UDP. When you type a server's IP address into Remote Desktop Connection without a port, the client connects to 3389. That is true on Windows 10 and 11 and on every current version of Windows Server, including the Windows Server VPS you get from a hosting provider.
The port is a setting, not a fixed part of the protocol: an administrator can move it, and if they do, you must add the new port to the address you connect to.
TCP 3389 vs UDP 3389
- TCP 3389 carries the connection: sign-in, encryption negotiation and, if nothing better is available, all of the screen, keyboard and mouse traffic. RDP always works over TCP.
- UDP 3389 is an additional transport defined in Microsoft's RDP UDP extension. When the client and the network allow it, graphics travel over UDP, which copes better with packet loss and delay. If UDP is blocked, the session simply stays on TCP.
So a firewall that only allows TCP 3389 still lets you connect; opening UDP 3389 as well can make the session smoother on long-distance or lossy links.
How to check which port RDP is listening on
Open PowerShell as Administrator on the server.
-
Read the configured port from the registry:
Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name 'PortNumber' -
Confirm Windows is listening on it (replace 3389 if the value above is different):
netstat -ano | findstr :3389You should see a
TCP ... LISTENINGline and usually aUDPline for the same port. The last column is the process ID;tasklist /svc /fi "PID eq 1234"shows which service owns it.
How to change the RDP port (registry and firewall)
Do the steps in this order, and keep your current session open until you have tested the new port: if the firewall rule is missing when the service restarts, you lose remote access.
-
Pick a port that nothing else uses, for example 3390, and check it is free with
netstat -ano | findstr :3390. -
Allow it in Windows Firewall for TCP and UDP. Microsoft's procedure uses:
$portValue = 3390 New-NetFirewallRule -DisplayName 'RDPPORTLatest-TCP-In' -Profile 'Public' -Direction Inbound -Action Allow -Protocol TCP -LocalPort $portValue New-NetFirewallRule -DisplayName 'RDPPORTLatest-UDP-In' -Profile 'Public' -Direction Inbound -Action Allow -Protocol UDP -LocalPort $portValueCheck which network profile your server uses with
Get-NetConnectionProfileand set-Profileto match. If there is a firewall outside Windows, allow the port there too. -
Change the listening port in the registry:
Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name 'PortNumber' -Value $portValue -
Restart Remote Desktop Services (this ends current sessions) or restart the server:
Restart-Service -Name TermService -Force -
Test from your computer with
mstsc /v:SERVER_IP:3390. Once it works, you can remove the old 3389 rule.
If you do lock yourself out on a RyzenRDP server, open a support ticket from the console.
Should you change the default port?
Changing the port is noise reduction, not security. Internet-wide scanners hammer port 3389 with password guesses; moving RDP elsewhere cuts that background noise in your logs. A determined attacker will still find the new port with a port scan, so treat it as an optional extra, never as the thing that keeps you safe.
Reasons not to change it: some corporate networks only allow outbound 3389, and every user must remember the custom port.
What actually protects RDP
- A long, unique Administrator password, or a separate admin account with a strong password.
- Network Level Authentication (NLA), which makes the client authenticate before a full session starts. It is on by default in current Windows Server versions; keep it on.
- An account lockout policy (Local Security Policy, Account Lockout Policy) so repeated wrong passwords lock the account for a while.
- Restricting who can connect. If you connect from fixed IP addresses, limit the firewall rule to
them, for example with
Set-NetFirewallRule -DisplayName 'RDPPORTLatest-TCP-In' -RemoteAddress 198.51.100.7. A VPN or a Remote Desktop Gateway are the next step up. - Windows Update. Most serious RDP attacks used vulnerabilities that already had patches.
Connecting to a custom port with mstsc
Add the port to the address after a colon:
mstsc /v:203.0.113.10:3390
The same address:port form works in the Computer field of Remote Desktop Connection and in
Microsoft's Remote Desktop apps for Mac, iOS and Android. In a saved .rdp file, put it in the
full address:s: line. Every switch is covered in our mstsc command guide.
FAQ
Is port 3389 used for RDP?
Yes. 3389 is the default Remote Desktop Protocol port on Windows and Windows Server, unless an administrator has changed it.
Is RDP port 3389 TCP or UDP?
Both. The session is established over TCP 3389, and modern Windows also listens on UDP 3389 so clients can use UDP for smoother graphics on lossy connections, falling back to TCP when UDP is blocked.
Does RDP use port 443?
Not when you connect directly. Port 443 (HTTPS) is used when RDP is tunnelled through a Remote Desktop Gateway, which forwards the session to the server's own RDP port inside the network.
Is RDP port 22?
No. Port 22 is the default for SSH, a different protocol. Windows Server can run an OpenSSH server on port 22, but Remote Desktop itself uses 3389.
Sources
- Microsoft Learn: Change the listening port for Remote Desktop on Windows and Windows Server
- Microsoft Learn: Troubleshoot Remote Desktop disconnected errors (port conflicts, restarting Remote Desktop Services, checking the listener)
- Microsoft Learn: mstsc command reference
- Microsoft Learn: [MS-RDPEUDP] Remote Desktop Protocol: UDP Transport Extension