Remote Desktop Protocol (RDP)
Protect Remote Desktop access through separate Pomerium TCP and UDP routes when both transports are required.
Overview
Remote Desktop Protocol provides graphical remote access to Windows systems. RDP normally uses TCP and can also use UDP port 3389. The current Pomerium RDP guide documents a TCP tunnel.
Remote Desktop Protocol can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can start the selected RDP route. The Windows host remains responsible for Network Level Authentication, accounts, desktop permissions, and session controls.
How it works
Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.
Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.
Create the documented TCP route and local tunnel. Test the selected RDP client, gateway placement, reconnect behavior, clipboard policy, and session security. Test any added UDP path as a separate deployment-specific design.
Example
An administrator starts the documented Pomerium TCP tunnel for a private Windows host and points the RDP client to the local listener. Windows keeps Network Level Authentication and desktop permissions.
Considerations
- The named Pomerium guide documents the TCP path. Treat a combined TCP and UDP design as deployment-specific until Pomerium tests and documents it.
- Preserve Network Level Authentication, RDP TLS, Windows account policy, and host authorization.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
Sources and official resources
- Microsoft Remote Desktop ServicesOfficial website
- Remote Desktop Protocol overviewOfficial documentation
- Remote Desktop Services portsPrimary source
- Tunneled RDP connectionsPomerium documentation
- Pomerium HTTP routingPomerium documentation
- Pomerium non-HTTP accessPomerium documentation
- Pomerium clientsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
