ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Windows Server

Windows Remote Desktop Connection Failed: Troubleshooting RDP Port 3389, Firewall and CredSSP Errors

6 steps 13 min read 1792 views 49
On this page

One of the most common issues after deploying a Windows VPS or dedicated server is a failed Windows Remote Desktop connection: the client says it "can't connect to the remote computer", hangs forever, or throws a CredSSP / NLA authentication error. This guide walks you through RDP troubleshooting from the outside in — port 3389, Windows Firewall, Remote Desktop Services, Network Level Authentication and account credentials — on Windows Server 2016, 2019 and 2022.

Make sure the server is powered on and was not just reinstalled or rebooted. A fresh install or a pending update can delay RDP availability by 5–15 minutes.

Step 1: Check whether RDP port 3389 is reachable

From your local computer, ping the server and then test the Remote Desktop port. Many servers block ICMP, so a failed ping alone does not mean the server is down — the port test is what matters. In PowerShell on your local Windows PC, run:

ping 203.0.113.10
Test-NetConnection 203.0.113.10 -Port 3389

If you see TcpTestSucceeded : True, the port is open and the problem is most likely authentication or the account. If it is False, continue with the service and firewall checks below. On macOS or Linux you can use nc -vz 203.0.113.10 3389. If you changed the RDP port earlier, test that port instead and connect using IP:port.

Step 2: Log in through the VNC console

You do not need to reinstall the OS when RDP fails. Log in to the IMIDC client area → My Products & Services → select your server → Manage, then open the VNC / console (dedicated servers usually provide IPMI/KVM). This gives you a local-screen session to repair Windows. If you cannot find the console, open a ticket and our support team will help.

Step 3: Make sure Remote Desktop Services are enabled and listening

In the VNC console, open PowerShell as Administrator and check whether Remote Desktop is disabled, whether the TermService service is running and whether port 3389 is listening:

reg query "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections
Get-Service TermService
netstat -ano | findstr :3389

A value of 0x1 for fDenyTSConnections means Remote Desktop is turned off. Re-enable it and restart the service:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" -Name fDenyTSConnections -Value 0
Set-Service TermService -StartupType Automatic
Restart-Service TermService -Force

Step 4: Check the Windows Firewall Remote Desktop rules

A firewall or security tool blocking port 3389 is a very common cause of RDP failures. The following commands use the language-independent rule group name, so they work on both English and localized editions of Windows:

Enable-NetFirewallRule -Group "@FirewallAPI.dll,-28752"
Get-NetFirewallRule -Group "@FirewallAPI.dll,-28752" | Select-Object DisplayName, Enabled, Profile

If you installed third-party security software, also review its port blocking and IP blacklist settings. To confirm whether the firewall is the culprit, you can briefly disable it and then turn it back on immediately afterwards:

Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled False
Set-NetFirewallProfile -Profile Domain,Public,Private -Enabled True

Step 5: Fix NLA and CredSSP authentication errors

The message "An authentication error has occurred. The function requested is not supported… This could be due to CredSSP encryption oracle remediation" means your PC and the server are on different security patch levels. The proper fix is to fully update both sides. If you cannot update the server right away, run this on your local PC as Administrator as a temporary workaround:

reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters" /f /v AllowEncryptionOracle /t REG_DWORD /d 2

If Network Level Authentication (NLA) is blocking the login, temporarily disable it on the server from the VNC console:

Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp" -Name UserAuthentication -Value 0
Disabling NLA and relaxing CredSSP both weaken security. Once you are back in and Windows Update has run, set UserAuthentication back to 1 and remove the AllowEncryptionOracle value from your PC.

Step 6: Verify the account and credentials

If you see "Your credentials did not work" or "The logon attempt failed", check that the username is Administrator (or the account you created), remember that passwords are case-sensitive, and avoid copying trailing spaces. Repeated failures may lock the account. Reset the password and unlock the account from the VNC console:

net user Administrator *
net user Administrator /active:yes
net accounts

net user Administrator * prompts for the new password twice (nothing is echoed). Windows Server also allows only two concurrent admin sessions by default; if they are in use, list them with query session and sign one out with logoff <session ID>.

FAQ

RDP connects but drops after a few seconds. Why?

This is usually packet loss, a server running out of CPU or memory, or a session timeout policy. Check resource usage in Task Manager and run ping -t <server IP> locally to look for sustained packet loss.

The server does not respond to ping. Is it down?

Not necessarily. Windows Firewall often blocks ICMP by default. If Test-NetConnection succeeds on port 3389, the server is online.

RDP fails only from my office network. What can I do?

Your ISP or corporate network may block port 3389, or your IP may be blacklisted by security software on the server. Try changing the RDP port or check the server's IP blacklist.

If none of the steps above solve the problem, submit a ticket to IMIDC 24/7 technical support with your server IP, a screenshot of the error and the steps you have already tried.

Was this answer helpful?

Related Tutorials