preloader
post-thumb

Last Update: October 7, 2026


BYauthor-thumberic

|Loading...

Keywords

There are two usual ways to Remote Desktop into a machine that isn't on your LAN, and both are bad in their own way.

The first is to forward port 3389 on the router and connect to the public IP. It works, and it's also how a huge share of ransomware gets in — an exposed RDP port is a doormat that every scanner on the internet is already knocking on. The second is to stand up a VPN first, which is more work, more to maintain, and usually gives the remote device far more of your network than "I just want to reach that one PC."

Reach RDP is a third way: your existing Remote Desktop client connects to the remote machine over an identity-gated tunnel, with nothing exposed and nothing forwarded.

What it looks like

The remote machine turns on "Share this PC," which advertises its RDP service (port 3389) to your TYO ID — or to a teammate you've explicitly shared it with. From the other end you pick that machine and Reach does two things: it stands up a local forward (a listener on 127.0.0.1) and launches your normal RDP client at it. To mstsc / Microsoft Remote Desktop / Remmina, it looks exactly like connecting to a machine on your own desk. The bytes, meanwhile, are travelling through Reach's tunnel to a box that could be behind NAT, behind CGNAT, or in another country entirely.

No inbound firewall rule. No public 3389. No static IP. The remote machine makes an outbound control connection to Reach and waits; your connection is matched to it by identity, not by address.

How the bytes travel

Same substrate as the rest of Reach. If your device and the target are on the same subnet, the connection goes peer-to-peer, directly, and the gateway never sees your pixels. Otherwise it rides the gateway relay. Either way the RDP stream is tunnelled raw, with a couple of deliberate tunings — TCP_NODELAY and interactive PDUs flushed immediately — because the thing that makes tunnelled RDP feel awful is buffering keystrokes and mouse movement, and we don't.

The security posture, and the sharp edges we filed down

RDP is fiddly, and getting it to tunnel cleanly took solving some genuinely annoying failure modes. A few worth naming, because they're the difference between "works" and "works reliably":

  • NLA stays on. The tunnel doesn't weaken authentication — CredSSP / Network Level Authentication is preserved (authentication level:i:2). Reach moves bytes; it doesn't stand between you and the server's auth.
  • A forced, fresh credential prompt. Because every Reach target shares 127.0.0.1 on your machine, mstsc would happily reuse a credential it cached against that address from a different box — connect to a domain-joined machine, then a workgroup one, and it tries Kerberos against a KDC it can't reach and dies before you even see a prompt (0x80090311). Reach's generated .rdp forces the prompt so you enter that machine's own credentials.
  • An old-server quirk (HYBRID_EX). Some older RDP servers reset the connection if the client advertises PROTOCOL_HYBRID_EX; Reach can strip it from the X.224 request for exactly those hosts (off by default, because modern Windows needs it kept).
  • Secure mode. For locked-down access you can strip the clipboard, drive and USB redirection virtual channels, so a session is view-and-control only with no data bridge back to the host.

Multi-monitor, and other client features

Because Reach tunnels the raw RDP stream, multi-monitor works out of the box. Reach's generated .rdp now sets use multiple monitors:i:1, so a full-screen session spans all your displays as if the box were on your desk — it's a no-op on a single monitor, and windowed mode still behaves normally. Same story for other RDP features: they're between your client and the host, and Reach is transparent to them.

Coming from TeamViewer or AnyDesk?

If you reach your machines with TeamViewer, AnyDesk or Dualmon today, Reach is the same "get to any of my boxes from anywhere" capability with a very different design underneath. Those tools re-encode the remote screen with a proprietary codec and relay it through the vendor's cloud. Reach instead tunnels each OS's native remote protocol end-to-end: RDP to Windows, VNC to a Mac (its built-in Screen Sharing) or Linux, SSH for a shell. So you get native fidelity — real multi-monitor, proper keyboard/printer/USB redirection on RDP — rather than a screen video stream, and the whole session is identity-gated with nothing exposed. There's no anonymous nine-digit session code to read out to whoever's on the phone, which is precisely the mechanism those tools get abused through. The trade: Reach reaches machines you own or have been granted, not a stranger's PC on a one-off support call.

What it isn't

  • It's a transport, not an RDP server. You still need a remote machine actually running Remote Desktop (a Pro/Enterprise/Server edition — Windows Home doesn't host RDP, and multimon needs a non-Home edition too). That's the Windows door specifically — to reach a Mac or Linux box you use Reach's VNC/SSH path instead, so non-Windows targets aren't left out.
  • Secure mode is a trade. Stripping clipboard/drive/USB is the point when you want it, and an annoyance when you forget it's on — it's per-forward, so you choose.

The headline, though, is the one that matters for anyone who's ever port-forwarded 3389 and then watched the failed-login counter climb: you can have Remote Desktop to any of your machines, from anywhere, using the client you already use — and leave nothing listening on the public internet.

Comments (0)

Leave a Comment
Your email won't be published. We'll only use it to notify you of replies to your comment.
Loading comments...
Previous Article
post-thumb

Oct 03, 2021

Setting up Ingress for a Web Service in a Kubernetes Cluster with NGINX Ingress Controller

A simple tutorial that helps configure ingress for a web service inside a kubernetes cluster using NGINX Ingress Controller

Next Article
post-thumb

Oct 06, 2026

Reach UDP: carrying the traffic that tunnels usually drop

Most proxies and tunnels carry TCP beautifully and quietly mangle UDP — which is exactly the protocol your voice calls, video, games and real-time tools run on. Reach now carries UDP too, with an adaptive layer that picks the right transport per connection.

agico

We transform visions into reality. We specializes in crafting digital experiences that captivate, engage, and innovate. With a fusion of creativity and expertise, we bring your ideas to life, one pixel at a time. Let's build the future together.

Copyright ©  2026  TYO Lab · v0.0.32