xfreerdp - Man Page


xfreerdp - Man Page

FreeRDP X11 client

Examples (TL;DR)

  • Connect to a FreeRDP server:xfreerdp /u:username /p:password /v:ip_address
  • Connect to a FreeRDP server and activate audio output redirection using sys:alsa device:xfreerdp /u:username /p:password /v:ip_address /sound:sys:alsa


xfreerdp [file] [options] [/v:server[:port]]


xfreerdp is an X11 Remote Desktop Protocol (RDP) client which is part of the FreeRDP project. An RDP server is built-in to many editions of Windows. Alternative servers included xrdp and VRDP (VirtualBox).


/a:addin[,options], /addin:addin[,options]



Action script (default:~/.config/freerdp/action.sh)

/admin,  /console

Admin (or console) session


desktop composition (default:off)

/app:path or ||alias

Remote application program


Remote application command-line parameters


File to open with remote application


Remote application GUID


Remote application icon for user interface


Remote application name for user interface

/app-workdir:workspace path

Remote application workspace path


Remote assistance password


Automatically request remote assistance input control


Asynchronous channels (experimental) (default:off)


Asynchronous input (default:off)


Asynchronous update (default:off)


Audio output mode


Authenticate only (default:off)


Authentication (experimental) (default:on)


Automatic reconnection (default:off)


Automatic reconnection maximum retries, 0 for unlimited [0,1000]


bitmap cache (default:off)


Session bpp (color depth) (default:16)


Print the build configuration

/cert:[deny,ignore,name:name,tofu,fingerprint:hash:hash as hex[,fingerprint:hash:another hash]]

Certificate accept options. Use with care! * deny ... Automatically abort connection if the certificate does not match, no user interaction. * ignore ... Ignore the certificate checks altogether (overrules all other options) * name ... Use the alternate <name> instead of the certificate subject to match locally stored certificates * tofu ... Accept certificate unconditionally on first connect and deny on subsequent connections if the certificate does not match * fingerprints ... A list of certificate hashes that are accepted unconditionally for a connection


[deprecated, use /cert:deny] Automatically abort connection for any certificate that can not be validated.


[deprecated, use /cert:ignore] Ignore certificate


[deprecated, use /cert:name:<name>] Certificate name


[deprecated, use /cert:tofu] Automatically accept certificate on first connect


Client Build Number sent to server (influences smartcard behaviour, see [MS-RDPESC])


Client Hostname to send to server


Redirect clipboard. * use-selection:<atom> ... (X11) Specify which X selection to access. Default is CLIPBOARD. PRIMARY is the X-style middle-click selection. (default:on)


Bitmap codec cache

-compression,  -z

compression (default:on)


Compression level (0,1,2)


credentials delegation (default:off)




Window decorations (default:on)


Display control


Redirect directory <path> as named share <name>. Hotplug support is enabled with /drive:hotplug,*. This argument provides the same function as "Drives that I plug in later" option in MSTSC.


Redirect all mount points as shares (default:off)


Dynamic virtual channel


Send resolution updates when the window is resized


Echo channel


Encryption (experimental) (default:on)


RDP standard security encryption methods


Fullscreen mode (<Ctrl>+<Alt>+<Enter> toggles fullscreen)


fast-path input/output (default:on)


FIPS mode (default:off)


floatbar is disabled by default (when enabled defaults to sticky in fullscreen mode)


smooth fonts (ClearType) (default:on)


Number of frame acknowledgement


Read credentials from stdin. With <force> the prompt is done before connection, otherwise on server request.


Gateway Hostname

/gateway-usage-method:[direct|detect], /gum:[direct|detect]

Gateway usage method


Gateway domain


GDI rendering


Geometry tracking channel


Consume multitouch input locally (default:off)


RDP8 graphics pipeline


RDP8 graphics pipeline using progressive codec (default:off)


RDP8 graphics pipeline using small cache mode (default:off)


RDP8 graphics pipeline using thin client mode (default:off)


Glyph cache (experimental) (default:off)


Gateway password


Grab keyboard (default:on)


Gateway transport type


Gateway username

/gat:access token

Gateway Access Token


Height (default:768)


Support heartbeat PDUs (default:on)

/help,  /?

Print help


Redirect user home as share (default:off)

/ipv6,  /6

Prefer IPv6 AAA record over IPv4 A record

/kbd:0xid or name

Keyboard layout


Keyboard active language identifier


Function key value


List keyboard layouts


List keyboard languages

/kbd-remap:List of key=value,... pairs to remap scancodes

Keyboard scancode remapping


Keyboard subtype


Keyboard type


Load balance info


Set logger filters, see wLog(7) for details


Set the default log level, see wLog(7) for details


Specify maximum fast-path update size


Specify maximum time in milliseconds spend treating packets


menu animations (default:off)

/microphone[:[sys:sys,][dev:dev,][format:format,][rate:rate,][channel:channel]], /mic[:[sys:sys,][dev:dev,][format:format,][rate:rate,][channel:channel]]

Audio input (microphone)


List detected monitors


Select monitors to use


Send mouse motion (default:on)


Use multiple monitors


Redirect multitouch input (default:off)


Support multitransport protocol (default:off)


protocol security negotiation (default:on)


Network connection type

/nsc,  /nscodec

NSCodec support


offscreen bitmap cache (default:off)


Orientation of display in degrees


Use the old license workflow (no CAL and hwId set to 0) (default:off)




Redirect parallel device


Parent window id


Use smart card authentication with password as smart card PIN (default:off)


Preconnection Blob


Preconnection Id


Physical height of display (in millimeters)


Replay rfx pcap file


Server port


suppress output when minimized (default:on)


Print base64 reconnect cookie after connecting (default:off)


Redirect printer device


Proxy settings: override env. var (see also environment variable below). Protocol "socks5" should be given explicitly where "http" is default.


Pass the hash (restricted admin mode)


Physical width of display (in millimeters)

/rdp2tcp:executable path[:arg...]

TCP redirection


Pass base64 reconnect cookie to the connection


Override the preferred redirection order


Do not check if a RDP order was announced during capability exchange, only use when connecting to a buggy server

/restricted-admin,  /restrictedAdmin

Restricted admin mode




RemoteFX mode


Scaling factor of the display (default:100)


Scaling factor for desktop applications (value between 100 and 500) (default:100)


Scaling factor for app store applications (default:100)


Force specific protocol security


NLA extended protocol security (default:off)


NLA protocol security (default:on)


RDP protocol security (default:on)


TLS protocol security (default:on)

/serial[:name[,path[,driver[,permissive]]]], /tty[:name[,path[,driver[,permissive]]]]

Redirect serial device


Alternate shell


Shell working directory

/size:widthxheight or percent%[wh]

Screen size (default:1024x768)


Scale remote desktop to window size


Redirect the smartcard devices containing any of the <str> in their names.


Activates Smartcard Logon authentication. (EXPERIMENTAL: NLA not supported)

/sound[:[sys:sys,][dev:dev,][format:format,][rate:rate,][channel:channel,][latency:latency,][quality:quality]], /audio[:[sys:sys,][dev:dev,][format:format,][rate:rate,][channel:channel,][latency:latency,][quality:quality]]

Audio output (sound)


Span screen over multiple monitors


SPN authentication service class


SSH Agent forwarding channel


Window title


themes (default:on)

/timeout:time in ms/timeout:time in ms

Advanced setting for high latency links: Adjust connection timeout, use if you encounter timeout failures with your connection (default:9000)


Allowed TLS ciphers


TLS security level - defaults to 1 (default:1)


Alt+Ctrl+Enter to toggle fullscreen (default:on)


[experimental] directly manipulate freerdp settings, use with extreme caution! (default:)


Print options allowed for /tune




Let server see real physical pointer button (default:off)


Server hostname


Static virtual channel


Print version


Video optimized remoting channel


Hyper-V console (use port 2179, disable negotiation)


Width (default:1024)


wallpaper (default:on)


full window drag (default:off)


window position


Set the WM_CLASS hint for the window instance


Use available work area

Environment Variables

wlog environment variable

xfreerdp uses wLog as its log facility, you can refer to the corresponding man page (wlog(7)) for more informations. Arguments passed via the /log-level or /log-filters have precedence over the environment variables.


xfreerdp connection.rdp /p:Pwd123! /f

Connect in fullscreen mode using a stored configuration connection.rdp and the password Pwd123!

xfreerdp /u:USER /size:50%h /v:rdp.contoso.com

Connect to host rdp.contoso.com with user USER and a size of 50 percent of the height. If width (w) is set instead of height (h) like /size:50%w. 50 percent of the width is used.

xfreerdp /u:CONTOSO\\JohnDoe /p:Pwd123! /v:rdp.contoso.com

Connect to host rdp.contoso.com with user CONTOSO\\JohnDoe and password Pwd123!

xfreerdp /u:JohnDoe /p:Pwd123! /w:1366 /h:768 /v:

Connect to host on port 4489 with user JohnDoe, password Pwd123!. The screen width is set to 1366 and the height to 768

xfreerdp /u:JohnDoe /p:Pwd123! /vmconnect:C824F53E-95D2-46C6-9A18-23A5BB403532 /v:

Establish a connection to host with user JohnDoe, password Pwd123! and connect to Hyper-V console (use port 2179, disable negotiation) with VMID C824F53E-95D2-46C6-9A18-23A5BB403532


Activate clipboard redirection


Activate drive redirection of /home/user as home drive


Activate smartcard redirection for device device


Activate printer redirection for printer device using driver driver


Activate serial port redirection for port device


Activate parallel port redirection for port device


Activate audio output redirection using device sys:alsa


Activate audio input redirection using device sys:alsa


Activate multimedia redirection using device sys:alsa


Activate USB device redirection for the device identified by 054c:0268

Post a Comment

Previous Post Next Post