This article explains safer options for administrative access to Linux and Windows servers.
Overview
SSH and RDP should not be publicly exposed unless necessary. Cloudflare Access and Tunnel can reduce exposure by requiring authenticated access before users reach the private service.
Recommended Steps
- Confirm who needs administrative access and from where.
- Keep direct SSH or RDP restricted by IP while migration is planned.
- Create a Cloudflare Tunnel from the server or private network.
- Publish SSH, RDP, or another admin service using the supported Cloudflare One method.
- Create Access policies based on email, identity provider group, or device posture when available.
- Test access with an authorized user.
- Disable or further restrict public inbound SSH/RDP after confirming the protected method works.
Common Mistakes to Avoid
- Leaving SSH or RDP open to the entire internet.
- Using weak passwords instead of keys, MFA, or identity-based access.
- Giving broad Access policies to all users.
- Forgetting emergency access procedures.