Setting up your own RustDesk Pro server on AWS is a fantastic way to take control of your remote desktop infrastructure. However, exposing your server to the web comes with significant security responsibilities. While you need standard encrypted web traffic to reach your server, leaving your administrative and API ports open to the public internet is a massive vulnerability.
Here is how you can secure your setup by allowing global access to port 443 while using an AWS Managed Prefix List to lock down your backend ports to only the specific physical locations you trust.
The Security Strategy: Splitting Your Traffic
To keep your environment secure without breaking functionality, your AWS Security Group inbound rules need to treat different types of traffic differently:
- Port 443/tcp (Standard HTTPS): This must remain open to the public internet (
0.0.0.0/0) so the application can function and endpoints can connect normally. - Ports 21115-21119 (API & Higher-Level Functions): These ports control the core administrative functions of RustDesk Pro. They should never be exposed globally. We will restrict these using a Prefix List.
What is an AWS Prefix List?
Instead of manually typing your home, work, and school IP addresses into multiple different security group rules, AWS offers a feature called a Managed Prefix List.
Think of a Prefix List as a custom, reusable address book of trusted IP addresses (CIDR blocks). By grouping your known locations into one list, you can apply a single rule to your Security Group that says: “Only allow traffic on ports 21115-21119 if the connection is coming from an IP address inside this specific address book.”
This effectively stops the entire public internet from probing or accessing your API, significantly reducing your attack surface.
How to Configure Your Prefix List & Security Group
Here is how to set up the restrictions to lock down your infrastructure:
- Find Your Public IPs: Determine the external, public-facing IP addresses for the locations you frequent (e.g., your home network, your office, and your school’s network). You can easily find these by searching “What is my IP” while connected to those respective networks.
- Create the Prefix List: Navigate to the VPC dashboard in your AWS Management Console. Under the “Managed Prefix Lists” section, create a new list and name it something identifiable (e.g.,
Trusted-Admin-Locations). - Populate the List: Add the public IP addresses you gathered in step one as individual CIDR block entries (e.g.,
198.51.100.14/32for a single IP). - Update Your Security Group: Go to the Security Group attached to your RustDesk Pro EC2 instance.
- Modify the Inbound Rules: * Ensure
443/tcphas its source set toAnywhere-IPv4(0.0.0.0/0).- Create a Custom TCP rule for the port range
21115 - 21119. - For the “Source”, select “Custom” and start typing the name of your new Prefix List (e.g.,
pl-123456789). Save the rules.
- Create a Custom TCP rule for the port range
Managing Dynamic IP Addresses
⚠️ CRITICAL NOTE: Most residential and school internet service providers assign dynamic IP addresses, meaning your external public IP can periodically change.
While utilizing a Prefix List is a massive security upgrade, it requires a bit of maintenance. If your home or school IP address changes, you will suddenly find yourself locked out of the RustDesk Pro higher-level functions.
If you lose access, resolving it is simple:
- Discover your new public IP address.
- Log into the AWS Console.
- Edit your Prefix List to replace the old CIDR block with the new one.
While it is not a perfectly maintenance-free solution, updating an IP address every few months is a minor inconvenience compared to the peace of mind that comes with knowing the entire public internet is blocked from accessing your API.