Prepare your devices and network
SubnetDesk is for mutually reachable LANs, private links and VPNs. It does not provide public device IDs, Internet rendezvous or relays. Establish a trusted network path first rather than exposing remote-control ports directly to the public Internet.
- Choose the official installer matching your system and architecture from the product downloads.
- Run the app on controller and host, and confirm mutual network reachability.
- Grant required screen-capture, accessibility or input permissions on the host.
- On Linux, review session, login-screen and Wayland limitations. There is currently no official native iOS installer.
Configure the host
- Set a LAN username and password in LAN settings. Use a strong, dedicated password.
- Check the listening port; the default is
TCP 21118. - Restrict allowed sources to the required network ranges using the CIDR allowlist.
- Check the host's identity fingerprint and provide it to the controller through a trusted channel.
Allow only necessary ports and source ranges through the firewall. Do not disable the whole firewall or SELinux for convenience.
Make your first connection
- Choose an automatically discovered device, or enter its hostname, IP address and port.
- Enter the LAN username and password configured on the host.
- Compare the fingerprint on first connection. Stop if it differs from the expected identity; do not accept an unexpected change blindly.
- Once connected, move the pointer or type harmless text to check display, input and permission behavior.
- Use recent connections or favorites for frequent targets, while still paying attention to identity-change warnings.
Direct routing across subnets or a VPN does not guarantee mDNS discovery. If you know the target address, enter it directly instead of waiting for discovery.
Work in a native session
Use the session toolbar to choose supported displays or adjust the view. File, clipboard and audio behavior depends on both platforms, versions and permissions.
- Check the destination directory and permissions before a transfer, then verify the received file.
- Test clipboard sync with ordinary text before using sensitive information.
- For audio, check session settings, system volume and capture support; not every platform combination is equivalent.
- Disconnect when finished. After temporary support, review whether credentials and access ranges should remain enabled.
Optional: connect from a browser
- Explicitly enable the Web entry point on a supported host; it is not open by default.
- Follow the app's instructions for trusted HTTPS access and use a browser supporting WebCodecs.
- Authenticate, verify the target and choose appropriate session permissions.
- Use
view-onlywhen viewing is enough; use the appropriate control mode for input.
Only collaboration enables browser text clipboard access. Browser sessions do not support file transfer, audio, remote restart, recording, blocking input or privacy mode. Do not assume native capabilities are all available through the Web entry point.
Updates and maintenance
Update checking is on by default for Windows and macOS desktops; automatic downloading is off. Update delivery depends on correctly configured build signing and trust information. Review settings or update manually from the official releases.
No public relay does not mean no outbound requests: update checking may contact GitHub. Private-network connectivity is not a promise that the app never accesses the Internet.
Troubleshoot common problems
| Symptom | Check in this order |
|---|---|
| Discovery list is empty | Same subnet and mDNS, then try a known hostname or IP directly |
| Connection times out | Host availability, routing or VPN, listening port, firewall and CIDR allowlist |
| Authentication fails | Host LAN username and password, not credentials for another service |
| Display or input is unavailable | System permissions, desktop session type and platform support |
| Browser has no file or audio controls | These are Web-session limitations; use a supported native client |
| Fingerprint changes unexpectedly | Stop and verify a reinstall or identity change through a trusted channel |
Read the SubnetDesk documentation for the full capability comparison and limitations.
