Skip to main content
See All Integrations

UDP services

Protect access to private UDP services through Pomerium CONNECT-UDP routes.

Standard protected service pattern

Category
Non-HTTP Services

Overview

A UDP service is any private service that uses the User Datagram Protocol and is compatible with a datagram tunnel. Pomerium carries this traffic through CONNECT-UDP over HTTP/2 or HTTP/3. This is a generic access concept.

UDP services can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can start the selected UDP route. The upstream service remains responsible for protocol security, authentication, data, and service authorization.

How it works

Create a Pomerium UDP route for the private service. Use a supported Pomerium client and confirm that every HTTP proxy in front of Pomerium forwards CONNECT-UDP.

Place Pomerium near latency-sensitive services. Keep protocol security and service authorization active behind the route.

Test packet size, latency, idle behavior, client reconnects, and any TCP fallback used by the application protocol.

Example

A user starts a local Pomerium UDP tunnel for an approved private service. The client sends datagrams to the loopback port. Pomerium evaluates route access before it carries the traffic.

Considerations

  • Every HTTP proxy in front of Pomerium must forward CONNECT-UDP.
  • Latency-sensitive services need close Pomerium placement. Pomerium does not add protocol-level authorization.

Sources and official resources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo