
Last Update: October 7, 2026
BY
eric
Keywords
There are two usual ways to Remote Desktop into a machine that isn't on your LAN, and both are bad in their own way.
The first is to forward port 3389 on the router and connect to the public IP. It works, and it's also how a huge share of ransomware gets in — an exposed RDP port is a doormat that every scanner on the internet is already knocking on. The second is to stand up a VPN first, which is more work, more to maintain, and usually gives the remote device far more of your network than "I just want to reach that one PC."
Reach RDP is a third way: your existing Remote Desktop client connects to the remote machine over an identity-gated tunnel, with nothing exposed and nothing forwarded.
What it looks like
The remote machine turns on "Share this PC," which advertises its RDP service (port 3389) to your TYO ID — or to a teammate you've explicitly shared it with. From the other end you pick that machine and Reach does two things: it stands up a local forward (a listener on 127.0.0.1) and launches your normal RDP client at it. To mstsc / Microsoft Remote Desktop / Remmina, it looks exactly like connecting to a machine on your own desk. The bytes, meanwhile, are travelling through Reach's tunnel to a box that could be behind NAT, behind CGNAT, or in another country entirely.
No inbound firewall rule. No public 3389. No static IP. The remote machine makes an outbound control connection to Reach and waits; your connection is matched to it by identity, not by address.
How the bytes travel
Same substrate as the rest of Reach. If your device and the target are on the same subnet, the connection goes peer-to-peer, directly, and the gateway never sees your pixels. Otherwise it rides the gateway relay. Either way the RDP stream is tunnelled raw, with a couple of deliberate tunings — TCP_NODELAY and interactive PDUs flushed immediately — because the thing that makes tunnelled RDP feel awful is buffering keystrokes and mouse movement, and we don't.
The security posture, and the sharp edges we filed down
RDP is fiddly, and getting it to tunnel cleanly took solving some genuinely annoying failure modes. A few worth naming, because they're the difference between "works" and "works reliably":
- NLA stays on. The tunnel doesn't weaken authentication — CredSSP / Network Level Authentication is preserved (
authentication level:i:2). Reach moves bytes; it doesn't stand between you and the server's auth. - A forced, fresh credential prompt. Because every Reach target shares
127.0.0.1on your machine, mstsc would happily reuse a credential it cached against that address from a different box — connect to a domain-joined machine, then a workgroup one, and it tries Kerberos against a KDC it can't reach and dies before you even see a prompt (0x80090311). Reach's generated.rdpforces the prompt so you enter that machine's own credentials. - An old-server quirk (
HYBRID_EX). Some older RDP servers reset the connection if the client advertisesPROTOCOL_HYBRID_EX; Reach can strip it from the X.224 request for exactly those hosts (off by default, because modern Windows needs it kept). - Secure mode. For locked-down access you can strip the clipboard, drive and USB redirection virtual channels, so a session is view-and-control only with no data bridge back to the host.
Multi-monitor, and other client features
Because Reach tunnels the raw RDP stream, multi-monitor works out of the box. Reach's generated .rdp now sets use multiple monitors:i:1, so a full-screen session spans all your displays as if the box were on your desk — it's a no-op on a single monitor, and windowed mode still behaves normally. Same story for other RDP features: they're between your client and the host, and Reach is transparent to them.
Coming from TeamViewer or AnyDesk?
If you reach your machines with TeamViewer, AnyDesk or Dualmon today, Reach is the same "get to any of my boxes from anywhere" capability with a very different design underneath. Those tools re-encode the remote screen with a proprietary codec and relay it through the vendor's cloud. Reach instead tunnels each OS's native remote protocol end-to-end: RDP to Windows, VNC to a Mac (its built-in Screen Sharing) or Linux, SSH for a shell. So you get native fidelity — real multi-monitor, proper keyboard/printer/USB redirection on RDP — rather than a screen video stream, and the whole session is identity-gated with nothing exposed. There's no anonymous nine-digit session code to read out to whoever's on the phone, which is precisely the mechanism those tools get abused through. The trade: Reach reaches machines you own or have been granted, not a stranger's PC on a one-off support call.
What it isn't
- It's a transport, not an RDP server. You still need a remote machine actually running Remote Desktop (a Pro/Enterprise/Server edition — Windows Home doesn't host RDP, and multimon needs a non-Home edition too). That's the Windows door specifically — to reach a Mac or Linux box you use Reach's VNC/SSH path instead, so non-Windows targets aren't left out.
- Secure mode is a trade. Stripping clipboard/drive/USB is the point when you want it, and an annoyance when you forget it's on — it's per-forward, so you choose.
The headline, though, is the one that matters for anyone who's ever port-forwarded 3389 and then watched the failed-login counter climb: you can have Remote Desktop to any of your machines, from anywhere, using the client you already use — and leave nothing listening on the public internet.





Comments (0)
Leave a Comment