I follow the security through obscurity idea and forward a random port high in the range to 3389 on my home pc.
It's tcp traffic, by the way.
I have an ipcop (dedicated linux-based firewall and router) which also keeps my no-ip dynamic dns up to date with my current ip, which is great. Make sure you're connecting to your external ip and set a port to forward to your comp on the internal network and you'll be fine.
|