How to get remote access without a VPN

Use a remote-access tool whose app on the computer connects out to a service you sign in to, so your router stays closed and there's no VPN to run. The shortcut to avoid is opening the computer's remote desktop directly to the internet.

Why VPNs are the usual answer

Built-in tools like Windows Remote Desktop and Mac Screen Sharing connect straight to the computer, which works in the office but not from home. A VPN puts your laptop on the office network as if you were there, so those tools work again. That's why Microsoft, describing how to reach a PC from outside, calls port forwarding "not recommended" and says it's preferable to use a VPN (Microsoft: access your PC from outside).

The cost is upkeep. Someone has to set up the VPN on the router or a server, configure every laptop that connects, and keep it all updated. A VPN usually connects a device to the whole network rather than to the one computer you need. For a five-person office, that's often more than anyone wants to look after.

Ways to connect without a traditional VPN

Each of these avoids opening a port on your router to a computer. They differ in what runs where and who looks after it.

Remote-access software that connects out

A small app on the computer connects out to the tool's service, and you connect through that service. Nothing on your network accepts connections from the internet.

  • Chrome Remote Desktop needs only outbound UDP and TCP on port 443, plus port 3478 (STUN), and Google says sessions are fully encrypted (Google: Chrome Remote Desktop).
  • Quick Assist, for helping someone on Windows, runs over port 443 through Microsoft's relay, and the person at the PC has to allow it (Microsoft: Quick Assist).

The trade-off: you rely on the provider's service, so the sign-in to that service becomes the front door.

Remote Desktop Gateway

Remote Desktop Gateway is a Windows Server role that gives encrypted access to Remote Desktop over the internet without a VPN (Microsoft: Remote Desktop Gateway). Instead of exposing each PC, you expose one gateway. It suits businesses that already run Windows Server and have someone to maintain it.

Outbound-only tunnels

Cloudflare Tunnel runs a small program, cloudflared, on your network. It connects out to Cloudflare, needs no public IP address, and lets you block all inbound traffic (Cloudflare: connect networks). It's a technical setup, usually done by someone comfortable with networking.

Mesh networks (VPN-like)

Tailscale builds a private network between your devices on WireGuard, with no port forwarding. When devices can't reach each other directly, traffic passes through relays that can't decrypt it (Tailscale: what is Tailscale).

Be clear about what it is: a VPN, built differently. It removes the router setup, not the VPN software on each device. WireGuard's own site calls it "an extremely simple yet fast and modern VPN" (WireGuard).

The approaches side by side

Ways to reach a computer remotely without a traditional VPN
Criterion Remote-access softwareRemote Desktop GatewayOutbound tunnelMesh network
Example Chrome Remote Desktop, Quick AssistWindows Server roleCloudflare TunnelTailscale
Ports opened to the internet NoneThe gateway'sNoneNone
On the device you connect from The tool's app or a browserA Remote Desktop appDepends on what you publishThe mesh app
Best for Small teams reaching specific computersBusinesses already running Windows ServerTechnical teams publishing servicesTechnical users who want a private network

Why opening remote desktop to the internet is risky

The tempting shortcut is to forward port 3389 (Windows Remote Desktop) or 5900 (Screen Sharing and other VNC) on your router straight to a computer. Anyone on the internet can then reach that computer's sign-in, and any flaw in the remote desktop software is exposed with it.

VNC has its own problem. Apple warns that VNC software from other companies may not encrypt keystrokes and stores the VNC password insecurely (Apple: computers running VNC software).

How to choose

Ask these questions of any option, including ours:

  • Does anything on your network accept connections from the internet? The fewer open doors, the better.
  • How does each person sign in, and can you remove someone's access the day they leave?
  • Does the person at a computer know when someone connects to it?
  • Who keeps the software on each computer updated?
  • When it stops working at 8:45 on a Monday, who do you call?
  • Does it reach every kind of computer you have: Mac, Windows, Linux?

How Aile Insight connects

Nothing to change on your network. A small app on each Mac, Windows PC or Linux server makes an outbound, encrypted connection to Aile Insight. You sign in from a web browser with your email or a passkey and open the machine: Mac Screen Sharing for a Mac, Windows Remote Desktop for a PC, a terminal for a server. No ports are opened and nothing is installed on the device you connect from.

To be plain about the technology: the connection uses WireGuard, the VPN technology described above. The difference for you is that there's no VPN to set up on your router and no VPN app on your laptop. We install the app on each machine with you on a 20-minute call and check that each one opens from where you need it.

How Aile Insight protects remote access

Questions

Is remote access without a VPN safe?

It can be, depending on how the connection is made. Tools whose app on the computer connects out don't leave anything on your network open to the internet. What matters then is the sign-in: strong passwords or passkeys, and access only for the people who need it.

Can I just forward port 3389 on my router?

You can, but Microsoft calls it "not recommended" and says a VPN is preferable, and CISA, the FBI and the NSA list exploited Remote Desktop connections among the top three ways ransomware gets in. If Remote Desktop must be reachable, CISA's advice is to put it behind a VPN or a gateway with multi-factor sign-in.

Is Tailscale a VPN?

It's VPN-like. Tailscale builds a private network between your devices using WireGuard, without port forwarding. If your goal is to avoid running a traditional VPN server, it may suit you. If a policy says "no VPN software on this device", it probably counts as one.

Do I need a static IP address?

Not for tools that connect out, and Cloudflare says its tunnel needs no public IP address. Port forwarding is the approach that usually needs dynamic DNS and a fixed internal address for the computer.

Does Aile Insight need a VPN?

No. The app on each machine connects out, and you open machines in a web browser, so there's no VPN to install on the device you connect from and nothing to change on your router.