Port 3389: RDP
TCP/UDP 3389 is the port for Remote Desktop Protocol. Never directly on the internet. Use a VPN, Remote Desktop Gateway (443), or a zero-trust tunnel, and enable Network Level Authentication.
| Service | Remote Desktop Protocol |
|---|---|
| Protocol | TCP/UDP |
| Exposure risk | High: do not expose to the internet |
| Range | Registered (1024–49151) |
What port 3389 does
Windows Remote Desktop listens on TCP 3389 and also UDP 3389 for better performance. It is the single most common way attackers gain initial access in ransomware incidents.
Should port 3389 be open?
Never directly on the internet. Use a VPN, Remote Desktop Gateway (443), or a zero-trust tunnel, and enable Network Level Authentication.
Find what's listening on port 3389
- Linux:
sudo ss -tulpn | grep :3389 - macOS:
sudo lsof -nP -i :3389 - Windows:
netstat -ano | findstr :3389, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 3389/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=3389/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 3389" -Direction Inbound -Protocol TCP -LocalPort 3389 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 3389
What is port 3389 used for?
Remote Desktop Protocol. Windows Remote Desktop listens on TCP 3389 and also UDP 3389 for better performance. It is the single most common way attackers gain initial access in ransomware incidents.
Is port 3389 TCP or UDP?
Both. RDP uses TCP and UDP on port 3389.
Is it safe to open port 3389?
High: do not expose to the internet. Never directly on the internet. Use a VPN, Remote Desktop Gateway (443), or a zero-trust tunnel, and enable Network Level Authentication.
How do I check if port 3389 is open?
Use the checker on this page: it connects to your host on TCP 3389 from the internet. Locally, run
nc -vz host 3389 (macOS/Linux) or Test-NetConnection host -Port 3389 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :3389 (Linux) or netstat -ano | findstr :3389 (Windows).