Sources accessed 5 October 2026.
SPICE, NoMachine NX, TeamViewer and RustDesk take other approaches covered below; xrdp is an RDP server implementation, not a separate protocol.
VNC vs RDP
VNC sends encoded framebuffer rectangles (RFC 6143, March 2011); RDP can send drawing commands and other display primitives (MS-RDPBCGR). The VNC server determines the session model: on Linux/Unix (X11), TigerVNC 1.16.2’s x0vncserver shares an existing display, while Xvnc creates a virtual desktop. RD Session Host (updated 30 October 2025) gives users isolated sessions on Windows Server 2025, 2022, 2019 and 2016. VNC has independent implementations across operating systems (RFC 6143); RDP is Windows-native, with xrdp adding RDP to Linux.
For VNC Authentication, RFC 6143, section 7.2.2 says it “is known to be cryptographically weak and is not intended for use on untrusted networks.” For RDP, Microsoft’s Enhanced RDP Security documentation describes external protocols including TLS and CredSSP, with CredSSP enabling Network Level Authentication.
Compare transports, platforms and encryption
Use the linked documentation to check the configuration you plan to run.
| Protocol or approach | Transport and ports | Platforms | Encryption mechanism | Typical use |
|---|---|---|---|---|
| VNC/RFB | TCP port 5900. RFC 6143, section 2. | The framebuffer model applies across windowing systems and applications. RFC 6143, abstract. | RFC 6143 says VNC Authentication “is known to be cryptographically weak and is not intended for use on untrusted networks. Many implementations will want to use stronger security, such as running the session over an encrypted channel provided by IPsec [RFC4301] or SSH [RFC4254]”. RFC 6143, section 7.2.2. | View and control a graphical desktop on another computer. RFC 6143, abstract. |
| RDP | TCP and UDP 3389 (configurable); RD Gateway uses TCP 443 and UDP 3391. Microsoft RDS ports. | Microsoft documents clients for Windows, macOS, iOS/iPadOS, Android/ChromeOS and web browsers. This is a client list. Microsoft remote desktop clients. | Enhanced RDP Security can use TLS 1.0, 1.1, 1.2 or 1.3, CredSSP, RDSTLS or RDS AAD Auth. CredSSP enables Network Level Authentication. Microsoft Enhanced RDP Security. | Send graphics from a remote computer and return user input. Microsoft RDP specification. |
| SPICE | Encrypted channels use a separate port. SPICE user manual. | Server library used by QEMU. SPICE server documentation. Clients listed for Windows, Linux and the web, an experimental OS X client, and third-party Android and iOS clients. SPICE client list. | TLS channels with certificate verification against a certificate authority; SASL authentication is available. SPICE authentication and TLS documentation. | Remote access to virtual machines. SPICE use cases. |
| xrdp An RDP server implementation, not a separate protocol. |
Not listed | Listed clients include FreeRDP, rdesktop, NeutrinoRDP and Microsoft Remote Desktop Client on Windows, macOS, iOS and Android. xrdp client list. | RDP transport uses TLS by default. xrdp transport documentation. | Graphical login to remote machines through an RDP client. xrdp README. |
| NoMachine NX | NX service port 4000; UDP multimedia uses 4000 since version 8. SSH uses 22, or 4022 on Windows; HTTPS uses 4443. NoMachine service ports. | Windows, macOS and Linux, with iOS and Android apps. NoMachine platforms. | OpenSSL TLS/SSL, with ECDHE-RSA-AES128-GCM-SHA256 as the default suite since version 4.1. UDP uses Blowfish negotiated through the TLS-protected TCP connection. NoMachine encryption mechanisms. | Not listed |
| TeamViewer approach Proprietary approach. |
TeamViewer’s master servers handle the handshake; a direct UDP or TCP connection is attempted, with traffic passing through TeamViewer routers if that fails (TeamViewer connection architecture). Outbound port 5938, falling back to 443, then 80; no inbound ports need opening. TeamViewer connection ports. | Windows, macOS, Linux, ChromeOS, iOS and Android. TeamViewer platform and port table. | 4096-bit RSA key exchange and 256-bit AES session encryption. TeamViewer encryption statement. | Not listed |
| RustDesk approach Open-source approach. |
An ID, rendezvous and signaling server (hbbs) and a relay (hbbr); connections use the relay if hole punching fails. Minimum ports are TCP 21115-21117, plus TCP and UDP 21116. RustDesk self-hosting documentation. |
Windows, macOS, Linux, iOS, Android and web. RustDesk platform documentation. | P2P connections use end-to-end encryption based on NaCl. RustDesk encryption documentation. Direct-IP connections are unencrypted; direct-IP access is off by default. RustDesk direct-IP FAQ. | Remote access using self-hosted rendezvous and relay services. RustDesk server roles. |
Other remote access approaches
SPICE
SPICE combines a protocol, client, server and guest components for virtual-machine access (SPICE project overview). Its server library is used by QEMU. For TLS channels, plan certificate verification against a certificate authority and check the separate encrypted-channel port; SASL authentication is also available (SPICE user manual).
xrdp
xrdp is an open-source RDP server (xrdp project overview). Its RDP transport uses TLS by default. Operators can set security_layer=tls to require TLS and configure the certificate and key (xrdp TLS configuration).
NoMachine NX
NX uses OpenSSL TLS/SSL; its documented default suite is ECDHE-RSA-AES128-GCM-SHA256 since version 4.1. UDP multimedia uses Blowfish negotiated through the TLS-protected TCP connection (NoMachine encryption documentation). Check the service ports separately: the NX service uses 4000 by default, and UDP multimedia uses 4000 since version 8 (NoMachine port documentation).
TeamViewer approach
This proprietary approach documents 4096-bit RSA key exchange and 256-bit AES session encryption (TeamViewer encryption statement). TeamViewer’s master servers handle the handshake; a direct UDP or TCP connection is attempted, with traffic passing through TeamViewer routers if that fails (TeamViewer connection architecture). Its connection path needs outbound access, starting with port 5938 and falling back to 443, then 80; no inbound ports need opening (TeamViewer network requirements).
RustDesk approach
This open-source approach lets operators provide an hbbs rendezvous service and an hbbr relay. The relay carries connections when hole punching fails (RustDesk self-hosting documentation). P2P connections use end-to-end encryption based on NaCl (RustDesk encryption documentation). Direct-IP access is off by default and those connections are unencrypted (RustDesk direct-IP FAQ).
Find viewers, servers and further reading
Continue with the VNC viewer directory, VNC server directory or Enterprise VNC directory.
For background, read What is VNC? and How the RFB protocol works, from banner to pixels.
Last updated on