How to block public IP access for RDP while keeping VPN access
Even when a virtual private network is set up, standard configurations often leave Remote Desktop accessible via a public IP address. This leaves administrators stuck trying to remove public RDP options without blocking legitimate connections through approved networks.
What people tried
Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.
- 1Adding a block rule in the firewall for the public profile to port 3389
- 2Configuring upstream provider firewall rules
- 3Using alternative mesh VPN solutions like Tailscale
In their words
Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.
“It works, but i can't seem to remove the options to RDP via public IP.”source ↗
“I "invested" 6 full hours to no avail, searching, reading, and trying.”source ↗
“What are the methods are you all using to allow ScreenConnect to exist but not necessarily connect to non approved sites?”source ↗
Where this came up
People with this problem also raised
- 4Why do B2B clients keep asking to whitelist huge IP ranges?
- 2How to limit project visibility to assigned resources
- 5Locked out of new network switches because the consultant left
- 9Windows Server RDS sessions hanging after recent updates
- 8Why does my VPN or remote connection keep dropping?
- 2Why does accounting software force logins for every company file?