Skip to main content
See All Integrations

Remote Desktop Protocol (RDP)

Protect Remote Desktop access through separate Pomerium TCP and UDP routes when both transports are required.

First-party Pomerium access capability

Category
Non-HTTP Services

Overview

Remote Desktop Protocol provides graphical remote access to Windows systems. RDP normally uses TCP and can also use UDP port 3389. The current Pomerium RDP guide documents a TCP tunnel.

Remote Desktop Protocol can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can start the selected RDP route. The Windows host remains responsible for Network Level Authentication, accounts, desktop permissions, and session controls.

How it works

Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.

Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.

Create the documented TCP route and local tunnel. Test the selected RDP client, gateway placement, reconnect behavior, clipboard policy, and session security. Test any added UDP path as a separate deployment-specific design.

Example

An administrator starts the documented Pomerium TCP tunnel for a private Windows host and points the RDP client to the local listener. Windows keeps Network Level Authentication and desktop permissions.

Considerations

  • The named Pomerium guide documents the TCP path. Treat a combined TCP and UDP design as deployment-specific until Pomerium tests and documents it.
  • Preserve Network Level Authentication, RDP TLS, Windows account policy, and host authorization.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect SSH access with Pomerium native SSH or TCP routes.

  • Protect access to private TCP services through Pomerium routes.

  • Protect access to private UDP services through Pomerium CONNECT-UDP routes.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo