Commercial remote desktop tools like AnyDesk, TeamViewer, and LogMeIn have become increasingly problematic for Pakistani IT departments, software houses, and MSPs. Rising licensing fees, intrusive session time limits, and security vulnerabilities associated with proprietary central servers create serious operational challenges. Furthermore, routing sensitive remote desktop sessions through overseas relay servers introduces noticeable mouse latency and compromises data privacy.
The open-source RustDesk platform solves these issues. Written in Rust, it delivers peer-to-peer (P2P) performance with NaCl/Ed25519 end-to-end encryption. By deploying your own private RustDesk Rendezvous (hbbr) and Relay (hbbs) servers on a low-latency Cloud VPS in Pakistan, you gain full data sovereignty, zero commercial licensing restrictions, and sub-15ms local latency across Pakistani ISPs (Nayatel, PTCL, StormFiber).
RustDesk Server Architecture: hbbs vs. hbbr
A complete self-hosted RustDesk infrastructure consists of two lightweight system daemons:
+---------------------------------------------------------------------------------+
| Local Client (Lahore Office) |
+---------------------------------------+-----------------------------------------+
| 1. Registration & NAT Traversal (hbbs)
v
+---------------------------------------------------------------------------------+
| Your Cloud VPS (RustDesk Server) |
| |
| +------------------------------------+ +--------------------------------+ |
| | hbbs (Rendezvous) | | hbbr (Relay) | |
| | - ID Registration & Key Discovery | | - Fallback Direct Data Relay | |
| | - UDP Hole Punching & STUN | | - TCP Streaming Port 21117 | |
| +------------------------------------+ +--------------------------------+ |
+---------------------------------------------------------------------------------+
^
| 2. P2P Direct Connect (UDP Port 21116)
| OR Relay Connect via hbbr
+---------------------------------------+-----------------------------------------+
| Remote Client (Karachi Branch) |
+---------------------------------------------------------------------------------+
hbbs(Rendezvous / ID Server): Listens for client registrations, generates cryptographic session tokens, and facilitates NAT hole-punching for direct peer-to-peer UDP connections.hbbr(Relay Server): Acts as an encrypted relay proxy when direct P2P connections cannot be established due to symmetric NAT or strict enterprise firewalls.
Prerequisites & Port Allocations
Deploying RustDesk requires opening specific TCP and UDP ports on your firewall or security group:
21115/tcp:hbbsNAT type test.21116/tcp:hbbsTCP connection handler.21116/udp:hbbsUDP heartbeat and registration.21117/tcp:hbbrRelay service connection.21118/tcp&21119/tcp: Optional web client interfaces.
Step-by-Step Installation Using Docker Compose
The most resilient method to deploy RustDesk on Ubuntu 22.04 or AlmaLinux 9 is via Docker and Docker Compose.
Step 1: Install Docker Engine
Connect to your VPS via SSH and install Docker:
curl -fsSL https://get.docker.com | sh
systemctl enable --now docker
Step 2: Create Directory & docker-compose.yml
mkdir -p /opt/rustdesk-server && cd /opt/rustdesk-server
nano docker-compose.yml
Paste the following production configuration:
version: '3'
networks:
rustdesk-net:
external: false
services:
hbbs:
container_name: rustdesk-hbbs
image: rustdesk/rustdesk-server:latest
command: hbbs -k _
volumes:
- ./data:/root
network_mode: host
restart: unless-stopped
hbbr:
container_name: rustdesk-hbbr
image: rustdesk/rustdesk-server:latest
command: hbbr -k _
volumes:
- ./data:/root
network_mode: host
restart: unless-stopped
Security Flag Note: The -k _ parameter forces mutual authentication. Clients without your server’s public key are rejected, preventing third parties from utilizing your VPS as an open relay.
Step 3: Launch Services and Retrieve Cryptographic Keys
Start the containers in detached mode:
docker compose up -d
Inspect the auto-generated cryptographic public key in the ./data directory:
cat ./data/id_ed25519.pub
Output Example:
8jK2pLm9xYzQwErTyUiOpAsDfGhJkLzXc1234567890=
Save this public key string; you will distribute it to your client endpoints.
Configuring the RustDesk Client Application
On your local Windows, macOS, or Linux machines:
- Download the official RustDesk client from rustdesk.com.
- Open RustDesk, click the three-dot menu (⋮) next to your ID, and select Network / ID/Relay Server.
- Fill in the fields:
- ID Server:
vps-ip.nextgen.pk(or your VPS IPv4 address). - Relay Server:
vps-ip.nextgen.pk. - API Server: Leave blank (or use Pro server endpoint).
- Key: Paste the public key string obtained in Step 3 (
8jK2pLm9x...).
- ID Server:
- Click Apply.
At the bottom of the client window, the status dot will turn Green (“Ready”). You now have a private remote desktop pipeline.
Commercial Comparison: Self-Hosted RustDesk vs. TeamViewer & AnyDesk
| Feature / Metric | Commercial AnyDesk / TeamViewer | Self-Hosted RustDesk on VPS |
|---|---|---|
| Hosting Control | Third-party cloud servers | 100% On-Premise / Private VPS |
| Relay Bandwidth | Shared, rate-limited | Dedicated Gigabit Port |
| Latency across Pakistan | 120ms – 250ms (Overseas relays) | 8ms – 25ms (Local Karachi/Lahore nodes) |
| Concurrent Sessions | Per-license cost tier | Unlimited (Hardware constrained only) |
| Encryption Standard | Proprietary closed-source | Open-source NaCl & Ed25519 |
| Monthly Cost | $50 – $200+ per month | $6 – $12 per month (VPS hosting) |
For organizations requiring multi-seat terminal environments, explore our comparison between Dedicated RDP vs. Shared RDP Architecture. If your enterprise needs high-throughput bare metal for multi-gigabit streaming, explore our Dedicated Servers.
Eliminate subscription fees and third-party tracking by self-hosting RustDesk, VPN gateways, and private tools on NVMe-powered Cloud VPS instances hosted in Pakistan.
