Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows 10 (latest updates) RDP is requesting UDP port 3389 traffic

Hi all,

Since i have recently updated my main Windows 10 workstation, I've got some RDP dropped connections. The connection drops for 2 seconds and reconnect. A quick wireshark analysis revealed that the RDP protocol is requesting UDP port 3389 traffic to the target RDP server.

As per Sophos UTM, the RDP protocol definition is TCP:3389 (which is also what I've had in mind).

Did anyone saw such behaviors ? I'm pretty reluctant to add TCP & UDP port 3389 for my RDP rules. Although i'll test this now to acknowledge if that is counter measuring my issues...

Thanks,
Regards,
M.



This thread was automatically locked due to age.
Parents
  • Well something is strange indeed because there is not a single packets on UDP originating from my RDP sessions to any RDP servers target (as per wireshark, RST flagged frames are all TCP) but Sophos UTM 9.401-11 show some UDP:3389 traffic from my host to the RDP servers (in the default DROP of course...)

    Any comments would be welcome,
    Cheers,
    M.

Reply
  • Well something is strange indeed because there is not a single packets on UDP originating from my RDP sessions to any RDP servers target (as per wireshark, RST flagged frames are all TCP) but Sophos UTM 9.401-11 show some UDP:3389 traffic from my host to the RDP servers (in the default DROP of course...)

    Any comments would be welcome,
    Cheers,
    M.

Children
No Data