Firewall and ports

Current host, backend and discovery traffic to permit.

Permit the host’s outbound control connection and UDP session traffic. The current installer creates a program-scoped UDP rule for PrimalDeskHost.exe; it does not rely on one fixed media port. Domain policy or a perimeter firewall may override the Windows rule, so verify the effective policy after installation.

Traffic Default requirement
Host and client to api.primaldesk.com Outbound TCP 443 for sign-in, authorization and persistent host control
Client and Windows host session traffic UDP on ports allocated for the connection; permit the signed host executable through Windows Firewall and allow the corresponding UDP flows on perimeter firewalls
Discovery service Outbound UDP 3478 to the configured STUN endpoint
Relay, when available Outbound UDP to the relay endpoints and ports supplied for that session; do not assume UDP 3478 carries the desktop stream

The client and host test reachable UDP routes; address discovery can make a direct connection possible without manual forwarding. It cannot bypass a firewall, corporate policy, VPN routing or carrier-grade NAT. Allow return traffic for the outbound UDP flows on stateful firewalls.

Do not forward the old fixed media-port values as a general installation step: the current connection stack does not bind its session traffic to that setting. A local firewall exception does not configure your router. Networks that block UDP may prevent both direct and current relay connections. Do not open TCP 3389 to the internet for PrimalDesk; Windows Remote Desktop Services can be used locally by the host without a public RDP port.