A computer mouse with its long cable trailing off into the dark, scroll wheel lit cyan.

Open source remote desktop: which TeamViewer alternative to pick

Three open source tools let you take control of remote machines from your own server instead of going through TeamViewer, and each one puts its software in a different place. RustDesk runs on both computers, and its free server only brokers the connection: the web console, user accounts and 2FA are kept for its paid, closed-source Pro server. MeshCentral installs a permanent agent on every machine and manages the fleet from a browser. Apache Guacamole installs nothing on the machines: it is a web gateway that opens RDP, VNC or SSH sessions to servers it has to be able to reach. MeshCentral and Guacamole are under Apache-2.0, and neither advertises a paid plan.

Client on both ends, permanent agent or browser gateway

RustDesk, which its repository pitches as a TeamViewer alternative designed for self-hosting, runs the same application on the computer you drive from and on the machine being controlled; the client exists for Windows, macOS, Linux, Android and iOS. There is a public web client, but hosting it yourself requires the Pro server. On Android, the client is no longer on Google Play, which RustDesk left because of scams according to the project FAQ; it comes as an APK from the GitHub releases, or through F-Droid.

MeshCentral splits the roles differently. The admin installs the agent the server generates once on each machine in the fleet, whether it runs Windows, Linux, macOS, FreeBSD or Android. On the admin's side, a browser is all it takes to open the desktop, a terminal or the files. On PCs with Intel AMT, a second, hardware-level connection reaches the BIOS and power controls even when the operating system is down, and an "Intel AMT only" device group manages machines with no software installed at all. The user guide expects readers to know the basics of networking, operating systems and network security.

Apache Guacamole calls itself "clientless": the user installs no plugin and no client, and the target machine gets no Guacamole software. From a web page, the user picks a machine from a list, and the gateway opens an RDP, VNC, SSH, telnet or Kubernetes session to the server that machine already runs. Desktops and terminals sit in the same list, every session can be recorded and played back in the browser, and a share link gives someone else access to the running session.

MeshCentral partly overlaps with that role: an agent on a remote network can relay SSH, SFTP, RDP or VNC sessions to neighbouring machines that have no agent, even when the server runs in WAN mode.

Which way the connection goes, and what the network has to allow

RustDesk connects the two computers through two server programs. hbbs keeps the ID registry and tries a direct connection between them through NAT hole punching; hbbr relays the stream when that fails, which the documentation describes as the exception. Out of the box, clients go through RustDesk's public servers. With your own server, you open at least TCP ports 21115 to 21117 and UDP port 21116, then give each client the server address and the id_ed25519.pub public key that hbbs generates on first start. The free server has no console to push that configuration, so it happens machine by machine: by hand, by pasting a config string copied from another computer, or by script with rustdesk.exe --config. The documentation aims this server at individuals and teams willing to handle deployment, networking and upgrades themselves.

The MeshCentral agent opens the connection to the server itself and keeps it alive, so a machine behind a NAT router stays reachable without opening any port on its side. The server, on the other hand, has to be reachable by the agents. Started without arguments, it runs in LAN mode and agents find it by multicast; managing machines over the internet takes a static IP or a DNS name, plus ports 443 for agents and the console and 4433 for Intel AMT by default. The Windows agent installer holds no sensitive data and can be reused from one computer to the next: the FAQ describes unknown machines showing up in a console after an antivirus sent the installer to its vendor, who ran it on test machines. The agentAllowedIP setting restricts agents to given address ranges, and version 1.2.6 limits new enrollments by source address.

Apache Guacamole works the other way round. Its guacd daemon opens the connection to each machine's RDP, VNC or SSH server, "on behalf of the user" in the words of the architecture documentation. Every target therefore has to run that server and be reachable from the network guacd runs on.

What each tool needs to run

Read from the repositories and documentation on 7 October 2026.

ToolLicenceOn the remote machineTo take controlServer to runLatest release
RustDeskAGPL-3.0; Pro server closed sourcethe RustDesk clientthe RustDesk client, or the public web clienthbbs and hbbr, no external database; TCP 21115 to 21117 and UDP 21116client 1.5.0, 30 Sep 2026; free server 1.1.16, 20 Jul 2026
MeshCentralApache-2.0the MeshCentral agent, or Intel AMT alonea browserNode.js 20 or later; embedded NeDB, MongoDB for large fleets; ports 443 and 44331.2.6, 24 Sep 2026
Apache GuacamoleApache-2.0an RDP, VNC or SSH server reachable from guacda browserguacd, the Java web app in Tomcat, a MariaDB/MySQL, PostgreSQL or SQL Server database1.6.0, 22 Jun 2025

RustDesk's free server asks for little: according to the documentation, the smallest cloud server will do, a Raspberry Pi included, and a Docker Compose file (oss.yml) comes ready to run. What the docs do put numbers on is relay bandwidth, when the direct connection fails: 30 KB/s to 3 MB/s per session depending on resolution, around 100 KB/s for office work. The Pro documentation counts 1 core and 1 GB of RAM for 1,000 simultaneous relayed connections.

MeshCentral starts with Node.js alone: its embedded NeDB database sets itself up on first launch and "works well for small deployments". The documentation recommends MongoDB for large fleets and before peering several servers, and puts a few hundred devices on a Raspberry Pi or an AWS t3.nano instance, with no memory figure. With the ghcr.io/ylianst/meshcentral image, the built-in updater is off limits: you update by pulling a new image.

Apache Guacamole has the most moving parts. The guacd daemon, written in C, only enables a protocol if its library is present at build time: FreeRDP 2.0.0 or later for RDP, libssh2 for SSH, libVNCServer for VNC. The web application is a .war deployed into Tomcat or another servlet container. The default authentication, a user-mapping.xml file, is "not intended for production use", and the documentation highly recommends a database, which also brings the web admin interface, sharing links and load-balancing groups. The official Docker images split guacd and the web application, and the latter won't start until an authentication mechanism is configured.

Where the projects stand

RustDesk shipped six client releases in 2026, up to 1.5.0 on 30 September, and fourteen Pro server releases, up to 1.8.7 on 1 October. The free server got two over the same period, 1.1.15 in January and 1.1.16 on 20 July. MeshCentral ships about once a month: 1.2.6, out on 24 September 2026, is the sixteenth release in twelve months, and 1.2.0 in May 2026 made Node.js 20 mandatory. Two maintainers handle its security reports: Ylian Saint-Hilaire, who owns the repository, and Simon Smith, who authored 260 of the 490 commits over the past twelve months.

Apache Guacamole, an Apache Software Foundation project, is still on 1.6.0 from 22 June 2025. From 1.0.0 in January 2019 to 1.5.0 in February 2023, at least one minor version came out every year; 1.6.0 then took twenty-eight months. In September 2026 both of its repositories received fixes on a staging/1.6.1 branch, with no release as of 7 October 2026.

Licences and paid plans

RustDesk charges for the web console, user accounts, 2FA and SSO, which MeshCentral and Guacamole ship in their Apache-2.0 code.

RustDesk's client and free server are under AGPL-3.0. The Pro server's code isn't published: the rustdesk-server-pro repository describes itself as "some scripts", and a FAQ entry asks why Pro, though you host it yourself, is "not free and open source". RustDesk's pricing page only sells self-hosting, billed yearly. The Individual plan, at $11.88 a month, covers one user and 20 devices with the web console, 2FA, address book, audit log and access control; OIDC, LDAP and the custom client generator start with the Basic plan, at $23.88 a month for 10 users and 100 devices. A licence binds to a single hbbs machine and is checked over the internet.

MeshCentral, server and agent alike, is under Apache-2.0, and its official site mentions no paid offering; LDAP, SAML, OpenID Connect, Azure AD and a second factor through TOTP or Duo are part of the server. Apache Guacamole is under Apache-2.0 too, with no commercial tier of its own: its authentication options (database, LDAP or Active Directory, TOTP or Duo, CAS, OpenID Connect, SAML, smart cards, RADIUS) and session recording all ship with the project. Support goes through its mailing lists and JIRA, and its support page lists third-party companies that the foundation has neither endorsed nor vetted.