Why VPNs are the usual answer
Built-in tools like Windows Remote Desktop and Mac Screen Sharing connect straight to the computer, which works in the office but not from home. A VPN puts your laptop on the office network as if you were there, so those tools work again. That's why Microsoft, describing how to reach a PC from outside, calls port forwarding "not recommended" and says it's preferable to use a VPN (Microsoft: access your PC from outside).
The cost is upkeep. Someone has to set up the VPN on the router or a server, configure every laptop that connects, and keep it all updated. A VPN usually connects a device to the whole network rather than to the one computer you need. For a five-person office, that's often more than anyone wants to look after.
Ways to connect without a traditional VPN
Each of these avoids opening a port on your router to a computer. They differ in what runs where and who looks after it.
Remote-access software that connects out
A small app on the computer connects out to the tool's service, and you connect through that service. Nothing on your network accepts connections from the internet.
- Chrome Remote Desktop needs only outbound UDP and TCP on port 443, plus port 3478 (STUN), and Google says sessions are fully encrypted (Google: Chrome Remote Desktop).
- Quick Assist, for helping someone on Windows, runs over port 443 through Microsoft's relay, and the person at the PC has to allow it (Microsoft: Quick Assist).
The trade-off: you rely on the provider's service, so the sign-in to that service becomes the front door.
Remote Desktop Gateway
Remote Desktop Gateway is a Windows Server role that gives encrypted access to Remote Desktop over the internet without a VPN (Microsoft: Remote Desktop Gateway). Instead of exposing each PC, you expose one gateway. It suits businesses that already run Windows Server and have someone to maintain it.
Outbound-only tunnels
Cloudflare Tunnel runs a small program, cloudflared, on your network. It connects out to Cloudflare, needs no public IP address, and lets you block all inbound traffic (Cloudflare: connect networks). It's a technical setup, usually done by someone comfortable with networking.
Mesh networks (VPN-like)
Tailscale builds a private network between your devices on WireGuard, with no port forwarding. When devices can't reach each other directly, traffic passes through relays that can't decrypt it (Tailscale: what is Tailscale).
Be clear about what it is: a VPN, built differently. It removes the router setup, not the VPN software on each device. WireGuard's own site calls it "an extremely simple yet fast and modern VPN" (WireGuard).
The approaches side by side
| Criterion | Remote-access software | Remote Desktop Gateway | Outbound tunnel | Mesh network |
|---|---|---|---|---|
| Example | Chrome Remote Desktop, Quick Assist | Windows Server role | Cloudflare Tunnel | Tailscale |
| Ports opened to the internet | None | The gateway's | None | None |
| On the device you connect from | The tool's app or a browser | A Remote Desktop app | Depends on what you publish | The mesh app |
| Best for | Small teams reaching specific computers | Businesses already running Windows Server | Technical teams publishing services | Technical users who want a private network |
Why opening remote desktop to the internet is risky
The tempting shortcut is to forward port 3389 (Windows Remote Desktop) or 5900 (Screen Sharing and other VNC) on your router straight to a computer. Anyone on the internet can then reach that computer's sign-in, and any flaw in the remote desktop software is exposed with it.
VNC has its own problem. Apple warns that VNC software from other companies may not encrypt keystrokes and stores the VNC password insecurely (Apple: computers running VNC software).
How to choose
Ask these questions of any option, including ours:
- Does anything on your network accept connections from the internet? The fewer open doors, the better.
- How does each person sign in, and can you remove someone's access the day they leave?
- Does the person at a computer know when someone connects to it?
- Who keeps the software on each computer updated?
- When it stops working at 8:45 on a Monday, who do you call?
- Does it reach every kind of computer you have: Mac, Windows, Linux?
How Aile Insight connects
Nothing to change on your network. A small app on each Mac, Windows PC or Linux server makes an outbound, encrypted connection to Aile Insight. You sign in from a web browser with your email or a passkey and open the machine: Mac Screen Sharing for a Mac, Windows Remote Desktop for a PC, a terminal for a server. No ports are opened and nothing is installed on the device you connect from.
To be plain about the technology: the connection uses WireGuard, the VPN technology described above. The difference for you is that there's no VPN to set up on your router and no VPN app on your laptop. We install the app on each machine with you on a 20-minute call and check that each one opens from where you need it.