Said It Here

How to block public IP access for RDP while keeping VPN access

Even when a virtual private network is set up, standard configurations often leave Remote Desktop accessible via a public IP address. This leaves administrators stuck trying to remove public RDP options without blocking legitimate connections through approved networks.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Adding a block rule in the firewall for the public profile to port 3389
  2. 2
    Configuring upstream provider firewall rules
  3. 3
    Using alternative mesh VPN solutions like Tailscale

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

r/sysadmin2 people · September 2026

“It works, but i can't seem to remove the options to RDP via public IP.”source ↗

“I "invested" 6 full hours to no avail, searching, reading, and trying.”source ↗

Expensive-Feeling178 · r/sysadmin · 3 upvotes

“What are the methods are you all using to allow ScreenConnect to exist but not necessarily connect to non approved sites?”source ↗

Wolfram_And_Hart · r/sysadmin

Where this came up

People with this problem also raised