Skip to content

RDP how-to

RDP port 3389 explained: TCP vs UDP and when to change it

Remote Desktop listens on port 3389, over TCP and UDP. Here is what each does, how to confirm the port on your server, and how to change it without locking yourself out.

RyzenRDP guide cover: RDP port 3389 explained: TCP vs UDP and when to change it

Key takeaways

  • RDP uses port 3389 by default, on both TCP and UDP. TCP carries the connection; UDP is an optional faster transport the client uses when it can.
  • Check the configured port with Get-ItemProperty on the RDP-Tcp registry key, and confirm it is listening with netstat -ano.
  • Change it by editing the PortNumber value, adding firewall rules for the new port, then restarting Remote Desktop Services.
  • A new port cuts automated scanning noise, but real protection comes from strong passwords, Network Level Authentication and limiting who can reach the port.
On this page
  1. What port does RDP use?
  2. TCP 3389 vs UDP 3389
  3. How to check which port RDP is listening on
  4. How to change the RDP port (registry and firewall)
  5. Should you change the default port?
  6. What actually protects RDP
  7. Connecting to a custom port with mstsc

What port does RDP use?

Remote Desktop Protocol (RDP) listens on port 3389 by default, on TCP and UDP. When you type a server's IP address into Remote Desktop Connection without a port, the client connects to 3389. That is true on Windows 10 and 11 and on every current version of Windows Server, including the Windows Server VPS you get from a hosting provider.

The port is a setting, not a fixed part of the protocol: an administrator can move it, and if they do, you must add the new port to the address you connect to.

TCP 3389 vs UDP 3389

  • TCP 3389 carries the connection: sign-in, encryption negotiation and, if nothing better is available, all of the screen, keyboard and mouse traffic. RDP always works over TCP.
  • UDP 3389 is an additional transport defined in Microsoft's RDP UDP extension. When the client and the network allow it, graphics travel over UDP, which copes better with packet loss and delay. If UDP is blocked, the session simply stays on TCP.

So a firewall that only allows TCP 3389 still lets you connect; opening UDP 3389 as well can make the session smoother on long-distance or lossy links.

How to check which port RDP is listening on

Open PowerShell as Administrator on the server.

  1. Read the configured port from the registry:

    Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name 'PortNumber'
    
  2. Confirm Windows is listening on it (replace 3389 if the value above is different):

    netstat -ano | findstr :3389
    

    You should see a TCP ... LISTENING line and usually a UDP line for the same port. The last column is the process ID; tasklist /svc /fi "PID eq 1234" shows which service owns it.

Terminal showing netstat output with RDP listening on TCP and UDP port 3389

How to change the RDP port (registry and firewall)

Do the steps in this order, and keep your current session open until you have tested the new port: if the firewall rule is missing when the service restarts, you lose remote access.

Registry Editor showing the PortNumber value for RDP-Tcp

  1. Pick a port that nothing else uses, for example 3390, and check it is free with netstat -ano | findstr :3390.

  2. Allow it in Windows Firewall for TCP and UDP. Microsoft's procedure uses:

    $portValue = 3390
    New-NetFirewallRule -DisplayName 'RDPPORTLatest-TCP-In' -Profile 'Public' -Direction Inbound -Action Allow -Protocol TCP -LocalPort $portValue
    New-NetFirewallRule -DisplayName 'RDPPORTLatest-UDP-In' -Profile 'Public' -Direction Inbound -Action Allow -Protocol UDP -LocalPort $portValue
    

    Check which network profile your server uses with Get-NetConnectionProfile and set -Profile to match. If there is a firewall outside Windows, allow the port there too.

  3. Change the listening port in the registry:

    Set-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name 'PortNumber' -Value $portValue
    
  4. Restart Remote Desktop Services (this ends current sessions) or restart the server:

    Restart-Service -Name TermService -Force
    
  5. Test from your computer with mstsc /v:SERVER_IP:3390. Once it works, you can remove the old 3389 rule.

If you do lock yourself out on a RyzenRDP server, open a support ticket from the console.

Should you change the default port?

Changing the port is noise reduction, not security. Internet-wide scanners hammer port 3389 with password guesses; moving RDP elsewhere cuts that background noise in your logs. A determined attacker will still find the new port with a port scan, so treat it as an optional extra, never as the thing that keeps you safe.

Reasons not to change it: some corporate networks only allow outbound 3389, and every user must remember the custom port.

What actually protects RDP

  • A long, unique Administrator password, or a separate admin account with a strong password.
  • Network Level Authentication (NLA), which makes the client authenticate before a full session starts. It is on by default in current Windows Server versions; keep it on.
  • An account lockout policy (Local Security Policy, Account Lockout Policy) so repeated wrong passwords lock the account for a while.
  • Restricting who can connect. If you connect from fixed IP addresses, limit the firewall rule to them, for example with Set-NetFirewallRule -DisplayName 'RDPPORTLatest-TCP-In' -RemoteAddress 198.51.100.7. A VPN or a Remote Desktop Gateway are the next step up.
  • Windows Update. Most serious RDP attacks used vulnerabilities that already had patches.

Connecting to a custom port with mstsc

Add the port to the address after a colon:

mstsc /v:203.0.113.10:3390

The same address:port form works in the Computer field of Remote Desktop Connection and in Microsoft's Remote Desktop apps for Mac, iOS and Android. In a saved .rdp file, put it in the full address:s: line. Every switch is covered in our mstsc command guide.

FAQ

Is port 3389 used for RDP?

Yes. 3389 is the default Remote Desktop Protocol port on Windows and Windows Server, unless an administrator has changed it.

Is RDP port 3389 TCP or UDP?

Both. The session is established over TCP 3389, and modern Windows also listens on UDP 3389 so clients can use UDP for smoother graphics on lossy connections, falling back to TCP when UDP is blocked.

Does RDP use port 443?

Not when you connect directly. Port 443 (HTTPS) is used when RDP is tunnelled through a Remote Desktop Gateway, which forwards the session to the server's own RDP port inside the network.

Is RDP port 22?

No. Port 22 is the default for SSH, a different protocol. Windows Server can run an OpenSSH server on port 22, but Remote Desktop itself uses 3389.

Sources

  1. Microsoft Learn: Change the listening port for Remote Desktop on Windows and Windows Server
  2. Microsoft Learn: Troubleshoot Remote Desktop disconnected errors (port conflicts, restarting Remote Desktop Services, checking the listener)
  3. Microsoft Learn: mstsc command reference
  4. Microsoft Learn: [MS-RDPEUDP] Remote Desktop Protocol: UDP Transport Extension

Run Windows Server on AMD Ryzen or AMD EPYC

Full Administrator access, Remote Desktop ready, set up within 24 hours. Plans from $14.99/mo.