A remote desktop is useful when you need to interact with a graphical Linux session. But if you're only restarting services, editing configuration, or checking logs, SSH is usually simpler and lighter.
The right choice depends on the desktop environment and whether you need to share an existing session or connect to a separate one.
Pick the method that fits the machine
| Method | Good starting point | Keep in mind |
|---|---|---|
| GNOME Remote Desktop | A current GNOME desktop | Built in, but interactive sharing requires a logged-in session |
| xrdp | Older systems or desktops such as XFCE and MATE | Often needs an Xorg session; can conflict with another RDP server on port 3389 |
| VNC | Cross-platform or legacy setups | Security varies; don't assume the connection is encrypted |
| SSH | Command-line administration | No full graphical desktop |
If you're using a current Ubuntu or Fedora GNOME desktop, try GNOME Remote Desktop first. It speaks RDP, so you can connect with an RDP client rather than installing a separate server. For a Linux client, compare the available RDP clients if you need help choosing one.
Set up GNOME Remote Desktop
On the Linux desktop, open Settings → System → Remote Desktop, enable Remote Desktop, and set the connection username and password. These credentials don't have to be the same as your Linux login, so choose strong, unique ones.
From Windows, open Remote Desktop Connection (search for mstsc) and connect to the Linux machine's IP address. On macOS, use Microsoft's Remote Desktop app. On Linux, Remmina is one option.
The Settings toggle shares the currently logged-in desktop. If nobody is logged in locally, there may be no interactive session to share. GNOME also has a separate remote-login mode for access to the login screen, configured with grdctl rather than the Settings toggle.
When xrdp makes more sense
xrdp is an RDP server to consider for older distributions or non-GNOME desktops. On Debian-based systems, the source gives this basic installation and service setup:
sudo apt install xrdp
sudo systemctl enable --now xrdp
A common snag is the desktop session type. xrdp often relies on Xorg, so Wayland sessions may need extra configuration or may fail to start correctly. On Ubuntu 24.04 and newer, if you get a black screen or an immediate disconnect, try logging out and choosing the Xorg session from the login screen's gear menu before reconnecting.
Also check which RDP server is already using the port. GNOME Remote Desktop and xrdp both default to TCP port 3389; running both on the same port causes a conflict. Disable one or change xrdp's port if you need both.
Treat VNC as a security decision
VNC can be useful when you need compatibility with an existing setup. But its security depends on the server and configuration: some VNC setups may not encrypt traffic by default. Use strong authentication and TLS where supported, or put VNC behind a VPN or SSH tunnel. Don't expose a VNC port directly to the internet just because the client can connect to it.
Keep remote desktop off the public internet
Don't forward RDP port 3389 or a VNC port from your router, and don't leave it open to the internet in a cloud firewall. For remote access from outside your local network, use a VPN or tunnel the desktop connection through SSH.
For example, if SSH and RDP are available on the Linux machine, create a local forward:
ssh -L 13389:localhost:3389 user@linux-host
Leave that SSH connection running, then point your RDP client at localhost:13389. The SSH server connects to localhost:3389 from the Linux host, so the desktop service doesn't need to be directly reachable from the internet. Using 13389 locally also avoids taking over local port 3389 if another service already uses it. See this guide to SSH port forwarding for how the forwarding direction works.
A tunnel only protects the route through SSH; it doesn't replace strong desktop credentials or sensible access controls. If SSH itself isn't reachable, fix that connection first rather than opening the desktop port as a shortcut.
Troubleshoot in a useful order
-
Check that the desktop service is running. For xrdp, inspect it with
systemctl status xrdp. - Check the session type. A black screen or instant disconnect with xrdp can point to a Wayland/Xorg mismatch.
- Check for a port conflict. GNOME Remote Desktop and xrdp both default to 3389.
- Use the right credentials. The remote desktop username and password may differ from your normal Linux login.
- Confirm the session exists. GNOME's interactive mode shares a logged-in desktop; it isn't the same as connecting to a login screen.
- Check reachability and firewalls. Verify the service is listening and that host and network firewalls allow the intended connection. A local listening service doesn't by itself prove that a remote client can reach it.
If the task doesn't require a GUI, skip the desktop server entirely. SSH gives you a remote shell for routine administration without adding another graphical service to secure and maintain.
I originally published a more detailed version of this guide on the SSHFlow blog.
I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.
Top comments (0)