Windows Remote Desktop – Disconnections whilst using default RDP port (3389)
Brute-force traffic on the default RDP port 3389 causes disconnections and account lockouts. This guide shows how to move xrdp to a different port, update your firewall rules to allow only your IP address, and reconnect using the new port.
Move RDP off 3389, allow only the new port at your firewall for your own IP, then connect using server:port. This reduces the brute-force noise that often causes Remote Desktop disconnects and lockouts.
Before you start
- Have the Virtualizor VNC console ready in your Hostworld client area so you can recover if RDP stops responding.
- Pick an unused high port, for example 3390, and know your public source IP address.
- Use an account with sudo or root on the server.
- Leave the existing 3389 rules in place until the new port is proven to work. You remove them at the end.
Step 1: Change the xrdp listening port
This backs up the xrdp configuration file.
sudo cp /etc/xrdp/xrdp.ini /etc/xrdp/xrdp.ini.bak
This sets xrdp to listen on port 3390 instead of 3389.
sudo sed -i 's/^port=.*/port=3390/' /etc/xrdp/xrdp.ini
This shows the port line so you can confirm the edit matched.
grep '^port=' /etc/xrdp/xrdp.ini
AlmaLinux 9 only: on a minimal image the semanage command is not installed. This installs the package that provides it.
sudo dnf install -y policycoreutils-python-utils
AlmaLinux 9 only: if SELinux is enforcing, this maps the new port to the RDP SELinux type so xrdp can bind to it.
sudo semanage port -a -t rdp_port_t -p tcp 3390 || sudo semanage port -m -t rdp_port_t -p tcp 3390
This restarts xrdp to apply the change. Restarting xrdp ends any Remote Desktop session that is currently open, including the one you may be reading this in, so do it from the Virtualizor VNC console or at a point where losing the session does not matter.
sudo systemctl restart xrdp
This confirms xrdp is now listening on the new port before you touch the firewall.
sudo ss -ltnp | grep 3390
Step 2: Open the new RDP port in your firewall and restrict it to your IP
Ubuntu 24.04 (ufw)
This allows TCP on port 3390 from your IP only.
sudo ufw allow from 198.51.100.25 to any port 3390 proto tcp
This allows UDP on port 3390 from your IP to keep TCP and UDP rules aligned.
sudo ufw allow from 198.51.100.25 to any port 3390 proto udp
AlmaLinux 9 (firewalld)
This adds a permanent rule to allow TCP on port 3390 from your IP only.
sudo firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=198.51.100.25/32 port protocol=tcp port=3390 accept'
This adds a permanent rule to allow UDP on port 3390 from your IP.
sudo firewall-cmd --permanent --add-rich-rule='rule family=ipv4 source address=198.51.100.25/32 port protocol=udp port=3390 accept'
This reloads the firewall so the permanent rules take effect.
sudo firewall-cmd --reload
Step 3: Reconnect using the new port, then remove the old rules
Point your RDP client at the new port by appending :3390, for example 203.0.113.10:3390 or server.example.com:3390. Update any saved shortcuts. Keep TCP and UDP firewall rules aligned so legitimate sessions do not degrade.
Once you have a working session on 3390, remove the 3389 rules. A removal command only matches a rule written the same way it was added, so list the rules first rather than guessing.
Ubuntu 24.04 (ufw)
This lists the active rules with a number against each one.
sudo ufw status numbered
This deletes a rule by its number. Deleting renumbers the list, so re-run the status command between deletions.
sudo ufw delete 4
AlmaLinux 9 (firewalld)
This shows the permanent configuration, including whether 3389 was added as a plain port or as a rich rule.
sudo firewall-cmd --permanent --list-all
Remove it in the form it appears. Use the first line for a plain port entry, or the second with the rich rule copied exactly as listed, then reload.
sudo firewall-cmd --permanent --remove-port=3389/tcp
sudo firewall-cmd --permanent --remove-rich-rule='rule family=ipv4 source address=198.51.100.25/32 port protocol=tcp port=3389 accept'
sudo firewall-cmd --reload
Run the listing command again afterwards and check no 3389 entry remains.
If it does not work
- You are still connecting to 3389. In your RDP client, type the address as host:3390, for example 203.0.113.10:3390. Check any saved connection that may still point at 3389.
- xrdp is not listening on 3390. Re-run the grep and ss commands from Step 1. If the port line did not change, edit /etc/xrdp/xrdp.ini directly and restart xrdp again.
- The firewall is blocking the new port. On Ubuntu, re-run the ufw allow lines for 3390 and check sudo ufw status numbered. On AlmaLinux, confirm you ran firewall-cmd --reload after adding the rules. If you lose access, use the Virtualizor VNC console from your Hostworld client area to revert the change and try again.
- SELinux blocked xrdp on AlmaLinux 9. If semanage reports command not found, install policycoreutils-python-utils as shown in Step 1, run the semanage command, then restart xrdp. If you are still stuck or cannot regain access, open a support ticket.
What next
Changing the port reduces noise but exposure remains risky. Prefer allowing only your source IPs at the firewall or placing RDP behind a VPN or hardened gateway. For the wider context behind this change, see our VPS guides.
Common questions
Will changing the port stop the disconnects permanently?
It usually stops the bulk of unsolicited traffic that can cause performance spikes and lockouts on 3389. It is not a substitute for access control. Limit source IPs and consider a VPN or a gateway for RDP to reduce risk further.
Do I need to open UDP as well as TCP?
RDP uses TCP and also uses UDP on the same port in many setups. Keep TCP and UDP rules aligned on your chosen port so legitimate sessions do not fall back or degrade. If you prefer to keep UDP closed, test your workflow after the change and allow it only if you see issues.
I am on Windows Server. Can I move its RDP port?
Yes. Microsoft documents changing the listening port in the registry and adding matching Windows Firewall rules for both TCP and UDP on the new port. You will then connect as server:port. Have the Virtualizor VNC console available before changing the registry so you can recover if needed.
Was this article helpful?
0 people found this helpful