Remote Desktop Linux to Windows: Remmina, xfreerdp and Fixes
- September 24, 2026
- 9:00 am
- By Adrien Roche
- Updated October 3, 2026
- Tutorials

Which Linux remote desktop client should you use?
Microsoft does not ship an RDP client for Linux: Windows App covers Windows, macOS, iOS, Android and the browser, not a Linux desktop. What Linux has is FreeRDP, an open-source implementation of the protocol, and a few front ends built on it: Remmina (GTK, saved profiles), GNOME Connections and KDE's KRDC (fewer knobs), and xfreerdp, FreeRDP's own command-line client with every option exposed.
| Client | Interface | NLA (CredSSP) | Modern codecs | Redirection | Status |
|---|---|---|---|---|---|
| Remmina | GTK GUI, saved profiles | Yes (via FreeRDP) | RemoteFX, GFX, H.264 where FreeRDP is built with them | Clipboard, folders, printers, audio, microphone | Actively maintained |
| xfreerdp (FreeRDP 3) | Command line | Yes | RemoteFX, GFX, H.264 | Everything FreeRDP supports | Actively maintained |
| GNOME Connections / KRDC | Desktop-integrated GUI | Yes (via FreeRDP) | Depends on the FreeRDP build | Basic (clipboard, scaling) | Maintained with the desktop |
| rdesktop | Command line | Kerberos only, no NTLM | No (legacy bitmap codecs) | Clipboard, disk, sound | Last release 1.9.0, October 2019 |
Use Remmina for the machines you connect to daily, but learn xfreerdp anyway: when Remmina fails, it fails with a FreeRDP error, and the command line is the fastest place to diagnose it. Keep rdesktop for hosts that cannot do Network Level Authentication, such as unpatched Windows XP or Server 2003.
Prepare the Windows side first
Before touching Remmina or xfreerdp, enable Remote Desktop on the Windows 11 machine and check three things while you are there:
- Edition: only Windows Pro, Enterprise and Server accept incoming RDP sessions; Home cannot host one, whatever the client.
- Account: the user needs a real password (a Windows Hello PIN does not work over RDP) and must be an administrator or in Remote Desktop Users.
- Address: note the IP with
ipconfig: a private address on a LAN, the public IP for a Windows VPS, or a VPN into the network for a home PC reached across the internet.
From Linux, confirm that something is listening before blaming the client:
nc -vz 203.0.113.10 3389A succeeded result means the port is reachable; a refusal or a hang is covered in the errors section.
Remmina: the graphical route
1. Install Remmina and its RDP plugin
RDP support is a separate plugin on most distributions; the secret plugin stores passwords in your desktop keyring:
# Debian / Ubuntu
sudo apt install remmina remmina-plugin-rdp remmina-plugin-secret
# Fedora
sudo dnf install remmina remmina-plugins-rdp remmina-plugins-secret
# Arch Linux
sudo pacman -S remmina freerdp
# Any distribution (Flatpak)
flatpak install flathub org.remmina.Remmina2. Create the connection profile
Click + for a new profile and set Protocol to RDP - Remote Desktop Protocol. In Server, enter the IP or hostname, appending a non-standard port with a colon, as in 203.0.113.10:3390. Fill in Username and Password; leave Domain empty for a local Windows account. Save and double-click to connect; the certificate section below explains the prompt you will see first.
3. Resolution, scaling and quality
In the Basic tab, Resolution offers Use initial window size, Use client resolution (right for fullscreen) and fixed sizes; the toolbar's dynamic resolution toggle then lets Windows re-lay-out the desktop when you resize the window. Colour depth defaults to Automatic (32 bpp); GFX AVC444 (32 bpp) is sharpest on current Windows, while High colour (16 bpp) with Quality at Poor (fastest) suits a slow link. On a HiDPI screen, Remote scale factor in the Advanced tab makes Windows render its UI larger instead of stretching pixels on your side.
4. Clipboard, folder and audio redirection
Clipboard sync is on by default (the Advanced tab has a Turn off clipboard sync switch). Share folder in the Basic tab redirects a local directory into the session, where it appears in Windows Explorer under This PC. Set Sound to Local to hear Windows through your Linux speakers, and enable Redirect local microphone for the other direction.
xfreerdp (FreeRDP 3): the command-line route
1. Install FreeRDP 3
# Debian 12+ / Ubuntu 24.04+ (binary: xfreerdp3)
sudo apt install freerdp3-x11
# Fedora (binary: xfreerdp, version 3.x)
sudo dnf install freerdp
# Arch Linux (binary: xfreerdp)
sudo pacman -S freerdpDebian and Ubuntu name the FreeRDP 3 binary xfreerdp3 so it can coexist with freerdp2-x11 (plain xfreerdp). Check with xfreerdp3 /version and substitute below. On Wayland, xfreerdp runs through XWayland; freerdp3-sdl packages FreeRDP's newer native SDL client.
2. Connect
xfreerdp3 /v:203.0.113.10 /u:Administrator /from-stdin +dynamic-resolution +clipboard/from-stdin prompts for the password instead of leaving it in shell history via /p:. For a domain account, write /u:CORP\alice or /u:[email protected]; a non-default port goes on the server argument, /v:203.0.113.10:3390. Other useful flags:
/ffor fullscreen (Ctrl+Alt+Enter toggles it), or/size:1920x1080and percentages such as/size:80%./multimonto span all monitors, or/monitors:0,1to pick some./kbd:layout:0x40cto force a keyboard layout (French);/list:kbdprints the codes.
3. Redirect the clipboard, a folder, audio and printers
xfreerdp3 /v:203.0.113.10 /u:Administrator /from-stdin \
+clipboard \
/drive:share,$HOME/rdp-share \
/sound /microphone \
/printer/drive:name,path exposes a local directory to the session; it appears in Windows Explorer as share on <your-hostname> under This PC. +home-drive shares your whole home directory, +drives every mounted filesystem (usually broader than you want). /sound plays Windows audio through your default audio subsystem (PulseAudio, or PipeWire's compatibility layer); /audio-mode:1 leaves audio on the server.
4. Resolution and HiDPI scaling
+dynamic-resolution makes Windows change its own desktop size when you resize the window, so text stays crisp. /smart-sizing keeps the remote desktop fixed and scales the picture on the Linux side, which is blurry at anything but 100%. On a 4K panel, use /scale:180 (accepted values: 100, 140, 180) so Windows renders its UI at 180%, or /scale-desktop:200 for finer control. For bandwidth, /gfx:AVC444 selects the H.264 pipeline on hosts that support it and -wallpaper -themes /bpp:16 is the low-bandwidth combination.
Certificate warnings, explained
On the first connection to a host, xfreerdp prints the certificate's subject, issuer and SHA-256 fingerprint, then: The above X.509 certificate could not be verified, possibly because you do not have the CA certificate in your certificate store, or the certificate has expired. Do you trust the above certificate? (Y/T/N). Y stores the fingerprint permanently, T trusts it for this session, N aborts (Remmina asks the same in an Accept certificate? dialog). The warning is expected: Windows generates a self-signed certificate for the Remote Desktop service, issued to the machine's own name, and no certificate authority vouches for it. The session is still encrypted; the client just cannot prove who is on the other end. To verify, compare it with the certificate under Remote Desktop, Certificates in certlm.msc on the Windows machine. Accepted fingerprints live in one file per host under ~/.config/freerdp/server/ (FreeRDP 2 used ~/.config/freerdp/known_hosts2).
The warning to take seriously is !!!Certificate for host:port has changed!!!. It fires when the stored fingerprint no longer matches: legitimate after a Windows reinstall, a hostname change or a certificate renewal, but also exactly what a man-in-the-middle looks like. Confirm the change on the Windows side, then delete the host's entry from the FreeRDP store and reconnect. For automation, /cert:tofu accepts on first use and pins afterwards; /cert:fingerprint:sha256:<hex> pins a known certificate explicitly. /cert:ignore and Remmina's Ignore certificate disable the check entirely (lab use only).
Common errors: connection refused, timeouts, NLA and CredSSP
Connection refused: xfreerdp reports ERRCONNECT_CONNECT_FAILED [0x00020006]. The host answered, but nothing accepted the connection on that port: Remote Desktop is disabled, the service is stopped, or the port is wrong. On Windows, Get-Service TermService should say Running and netstat -ano | findstr :3389 should show a LISTENING line. If the connection hangs instead, packets are being dropped by a firewall, NAT rule or VPN route; this guide to fixing Remote Desktop connection timeouts walks through that layer by layer.
NLA and CredSSP failures: modern Windows requires Network Level Authentication. Credentials are checked through CredSSP before any desktop is drawn. The usual symptom is ERRCONNECT_LOGON_FAILURE [0x00020014], and in most cases it is a credential problem Windows deliberately does not explain: a typo, a local account written with a domain prefix, a domain account without one, or an empty password, which NLA rejects. A less obvious cause is an expired or must-change password, which CredSSP cannot handle because the change dialog lives in the GUI you have not reached yet. Forcing /sec:tls skips NLA and gets you to the Windows logon screen, if the host's policy allows it. With rdesktop the same situation reads CredSSP required by server; switch to FreeRDP, since rdesktop only speaks CredSSP with Kerberos.
Security: a VPN or tunnel first (a changed port is not security)
Where the reachability of port 3389 comes from matters more than any client option. An RDP port open to the internet collects password-guessing traffic within hours, leaving NLA and a strong password as the only defence. Moving the service to another port changes only the timing: scanners enumerate all 65,535 ports and the RDP handshake identifies itself regardless of the number. This guide to RDP port 3389 covers what listens there and why.
What actually reduces exposure: a WireGuard or other VPN so 3389 is only reachable from private addresses; a Windows Firewall rule scoped to your own source IP on a VPS; or an SSH tunnel through the Windows OpenSSH Server feature, so the RDP port never needs to be open at all:
ssh -N -L 13389:localhost:3389 [email protected]
# in a second terminal
xfreerdp3 /v:localhost:13389 /u:Administrator /from-stdin +dynamic-resolution +clipboardWhichever route you take, keep NLA on and enforce account lockout.
All of this presumes a Windows machine worth connecting to. If the goal is simply to have Windows available from your Linux desktop (for software with no Linux build, or a session that must stay up while your laptop sleeps), a home PC that reboots for updates behind a router you cannot configure is a poor target. A hosted Windows RDP server with full admin access is the simpler option: rdp.monster provisions one about 10 seconds after payment confirms, with dedicated CPU and RAM, unlimited (fair-use) bandwidth, no KYC, crypto accepted, from $8.99/month. To Remmina or xfreerdp, it is just another Windows host.
Frequently Asked Questions
Does Linux have a built-in remote desktop client for Windows?
apt install remmina remmina-plugin-rdp or your distribution's equivalent.Can I remote desktop from Linux into Windows 11 Home?
How do I copy files between Linux and Windows over RDP?
/drive:share,/home/you/folder and the directory appears in Windows Explorer under This PC as a redirected drive; in Remmina, set Share folder in the profile's Basic tab. Copying then works in both directions with normal Explorer drag and drop, and large files are far more reliable this way than pasting them through the clipboard. If the drive never appears, a Group Policy on the Windows side may be blocking drive redirection.Why is my RDP session from Linux slow, and how can I speed it up?
/gfx:AVC444 (or the GFX AVC444 colour depth in Remmina) gives the best picture on Windows 10, 11 and Server 2016 or later. On a slow or lossy link, drop to /bpp:16, add -wallpaper -themes, and let /network:auto tune the rest. A wired connection on the client side removes the most common source of stutter.Adrien Roche, Infrastructure & Hosting Editor
Systems engineer with 10+ years operating Windows Server and Linux fleets. Adrien runs the rdp.monster infrastructure documentation and writes our guides on RDP, VPS hosting, server administration, networking and privacy tooling.




