How to Protect SSH or RDP with Cloudflare Access/Tunnel

This article explains safer options for administrative access to Linux and Windows servers.

Overview

SSH and RDP should not be publicly exposed unless necessary. Cloudflare Access and Tunnel can reduce exposure by requiring authenticated access before users reach the private service.

  1. Confirm who needs administrative access and from where.
  2. Keep direct SSH or RDP restricted by IP while migration is planned.
  3. Create a Cloudflare Tunnel from the server or private network.
  4. Publish SSH, RDP, or another admin service using the supported Cloudflare One method.
  5. Create Access policies based on email, identity provider group, or device posture when available.
  6. Test access with an authorized user.
  7. Disable or further restrict public inbound SSH/RDP after confirming the protected method works.

Common Mistakes to Avoid

  • Leaving SSH or RDP open to the entire internet.
  • Using weak passwords instead of keys, MFA, or identity-based access.
  • Giving broad Access policies to all users.
  • Forgetting emergency access procedures.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support