Current host, backend and discovery traffic to permit.
Permit the host’s outbound control connection and UDP session traffic. The current installer creates a program-scoped UDP rule for PrimalDeskHost.exe; it does not rely on one fixed media port. Domain policy or a perimeter firewall may override the Windows rule, so verify the effective policy after installation.
| Traffic | Default requirement |
|---|---|
Host and client to api.primaldesk.com |
Outbound TCP 443 for sign-in, authorization and persistent host control |
| Client and Windows host session traffic | UDP on ports allocated for the connection; permit the signed host executable through Windows Firewall and allow the corresponding UDP flows on perimeter firewalls |
| Discovery service | Outbound UDP 3478 to the configured STUN endpoint |
| Relay, when available | Outbound UDP to the relay endpoints and ports supplied for that session; do not assume UDP 3478 carries the desktop stream |
The client and host test reachable UDP routes; address discovery can make a direct connection possible without manual forwarding. It cannot bypass a firewall, corporate policy, VPN routing or carrier-grade NAT. Allow return traffic for the outbound UDP flows on stateful firewalls.
Do not forward the old fixed media-port values as a general installation step: the current connection stack does not bind its session traffic to that setting. A local firewall exception does not configure your router. Networks that block UDP may prevent both direct and current relay connections. Do not open TCP 3389 to the internet for PrimalDesk; Windows Remote Desktop Services can be used locally by the host without a public RDP port.