SSH, RDP, and WinRM are protocols used to administer remote systems. SSH commonly uses port 22, RDP commonly uses port 3389, and WinRM commonly uses ports 5985 and 5986. A port number identifies a network entry point, but it does not by itself determine whether remote access is secure.
Table of Contents
What each protocol is designed to do
| Protocol | Common port | Typical administration use | Best fit |
|---|---|---|---|
| SSH | 22 | Command-line access to a remote server | Unix and Linux administration, server management, and remote work from a terminal |
| RDP | 3389 | Graphical remote access to a Windows system | Windows administration that requires a desktop interface |
| WinRM | 5985 or 5986 | Remote Windows administration through management commands and services | Windows administration that can be performed without a full graphical desktop |
SSH is a protocol for encrypted remote connections to servers. It lets an administrator work directly from a computer terminal instead of using a graphical interface. Data sent over SSH is encrypted, as described in the mybox SSH overview.
How the ports differ
Port 22 is the conventional SSH port. Port 3389 is the conventional RDP port. WinRM uses port 5985 or 5986. These numbers help a client find the service, but changing a service to another port does not replace access controls, encryption, or restricted network access.
A port can be open, closed, or restricted by a firewall. For a remote connection to work, the selected service must be running, the network path must allow traffic to its port, and the account must be allowed to authenticate. If any of these conditions is not met, the connection will fail even when the port number is correct.
Encryption and authentication should guide the choice
Encryption protects data while it travels between the administrator’s computer and the remote system. SSH provides encrypted remote communication. For RDP and WinRM, administrators should select the secured connection option supported by their environment and apply the required authentication controls before making the service reachable from an untrusted network.
Authentication determines who may use the service. A port number is not an identity check. Use named accounts, strong credentials, and the access controls available in the operating system and remote-access service. The exact authentication method depends on the protocol and the system configuration.
Which protocol should you choose?
- Choose SSH when command-line administration is sufficient, especially for a Linux or Unix server. SSH gives direct terminal access without a graphical interface. The mybox SSH command reference covers common commands used for website management, troubleshooting, backups, and server administration.
- Choose RDP when the administrator needs to work through the Windows desktop. This is appropriate for tasks that depend on a graphical interface rather than terminal commands.
- Choose WinRM when the target is Windows and the task can be completed through remote management commands or services. It is a better fit for repeatable administration that does not require the full desktop.
Firewall and exposure decisions
Allow only the remote-access service that the administration task requires. If a server needs terminal administration, there is no reason to expose a graphical remote desktop service for the same task. If a Windows task requires a desktop, RDP may be needed, while WinRM can remain unavailable unless it is part of the administration process.
Firewall rules should limit which networks or addresses can reach the service. A service exposed to the public internet has a wider attack surface than one reachable only from a private administration network. Restricting access reduces the number of systems that can attempt to connect, but it does not remove the need for encryption and authentication.
Safer ways to provide remote access
A VPN can place administration traffic inside a private network path instead of exposing the remote service directly to the public internet. Another option is to allow access only from approved network addresses or through a restricted administration network. These controls can be used with SSH, RDP, or WinRM.
Changing port 22, 3389, 5985, or 5986 to another number may reduce automated scanning based on default ports, but it is not a security control on its own. The service still needs encryption, authentication, and firewall restrictions. Treat the port change as a configuration choice, not as a replacement for limiting access.
Practical selection checklist
- Identify the operating system you need to administer.
- Decide whether the task needs a graphical desktop or only command-line and management access.
- Select SSH, RDP, or WinRM based on that task.
- Confirm that the service is running and that its required port is allowed by the firewall.
- Use encrypted communication and suitable authentication.
- Restrict access through a VPN, approved source addresses, or another private administration path where possible.
- Do not treat changing the default port as the main security measure.
The right choice depends on the administration task: SSH for terminal-based access, RDP for a Windows graphical desktop, and WinRM for Windows remote management without a full desktop. In every case, secure remote administration depends on the complete access design, not only on the port number.