# HTML5 support for RDP

**URL:** <https://community.f5.com/t/html5-support-for-rdp/74706>\
**Category:** Technical Forums\
**Tags:** application-delivery\
**Created:** [June 24, 2024, 8:56am UTC](https://community.f5.com/t/html5-support-for-rdp/74706 "2024-06-24T08:56:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marvin](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Marvin](https://community.f5.com/u/Marvin)\
**Post date:** [June 24, 2024, 8:56am UTC](https://community.f5.com/t/html5-support-for-rdp/74706/1 "2024-06-24T08:56:58Z")

</div>

I there any support for HTML5 for RDP connnections behind F5 without using a client? Or even possible with a client?

The use case is to have a webtop with a link to establish an RDP connection but we would like to have it via HTML5 embedded.

Looking at the following&nbsp; artcile it indicate it is not supported can someone confirm?

> **[myF5](https://my.f5.com/manage/s/article/K08943176#link_06_05)**

---

<div class="post-metadata">

**Author:** ![Lucas\_Thompson](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/lucas_thompson/32/19403_2.png) [@Lucas\_Thompson](https://community.f5.com/u/Lucas_Thompson)\
**Post date:** [June 24, 2024, 4:52pm UTC](https://community.f5.com/t/html5-support-for-rdp/74706/2 "2024-06-24T16:52:44Z")

</div>

As far as I know, we haven’t officially evaluated Microsoft’s new native HTML5 RDP client. It’s likely possible to make it work with APM, but some protocol (auth, SSO, etc) and security reviews are needed:

> **[RDWeb and HTML5 Client - Microsoft Q&A](https://learn.microsoft.com/en-us/answers/questions/1275851/rdweb-and-html5-client)**
>
> Hi,
> I am using RD Web and the new HTML5 web client. (https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-web-client-admin) I am interested to know if anyone has been able to get this working with...

---

<div class="post-metadata">

**Author:** ![Marvin](https://avatars.discourse-cdn.com/v4/letter/m/2bfe46/32.png) [@Marvin](https://community.f5.com/u/Marvin)\
**Post date:** [June 27, 2024, 8:41am UTC](https://community.f5.com/t/html5-support-for-rdp/74706/3 "2024-06-27T08:41:25Z")

</div>

It is registered **(Bug ID 578545) [RFE] Support RDP HTML5 client on APM Webtop**&nbsp;no ETA yet however by implementing this you would also solve this bug **Bug ID 969097: Native RDP Route Domain and SNAT Selection not applying SNAT settings**

> **[Bug ID 969097](https://cdn.f5.com/product/bugtracker/ID969097.html)**

The use case is very simple an easy to use web based RDP access and based on the role defined in access profile assign the correct SNAT IP address. Please have this implemented.

---

<div class="post-metadata">

**Author:** ![Lucas\_Thompson](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/lucas_thompson/32/19403_2.png) [@Lucas\_Thompson](https://community.f5.com/u/Lucas_Thompson)\
**Post date:** [June 28, 2024, 4:48am UTC](https://community.f5.com/t/html5-support-for-rdp/74706/4 "2024-06-28T04:48:45Z")

</div>

Thanks for the additional detail. 969097 is difficult from an architecture standpoint. That 578545 issue was a request to evaluate 3rd party HTML5 clients like Guacamole and Hobsoft, but since Microsoft now have a native HTML webclient it’s probably best to focus on theirs.

After looking at it for a while, it seems like the only L4-ish solution (because of 969097) is to use a data group to hold a list of SNAT selectors and an irule (or maybe an LTM policy), and probably an extra vip, which is a way overload of extra configuration.

An L7 solution \*that does support SSO\* might be to use SAML IDP-chaining with Azure or a local SAML SSO chained from whatever you currently logon with in the same way that CyberArk (no affiliation) provides a nice configuration guide on here:

[https://docs.cyberark.com/identity/latest/en/Content/Applications/certified-apps/RDWeb\_SSO.htm](https://docs.cyberark.com/identity/latest/en/Content/Applications/certified-apps/RDWeb_SSO.htm)

NOTE: I just stumbled on that from a google search for something like “webclient html5 microsoft saml” and have not tested it at all. They do have an impressive number of nice generic-SAML-ish integration articles!

BIG-IP APM does support these SAML-SSO-intercept and IdP-Chaining use cases that should allow you to both behave as and offer SSO for your users.

---

<div class="post-metadata">

**Author:** ![LiefZimmerman](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/liefzimmerman/32/3355_2.png) [@LiefZimmerman](https://community.f5.com/u/LiefZimmerman)\
**Post date:** [October 10, 2024, 7:22pm UTC](https://community.f5.com/t/html5-support-for-rdp/74706/5 "2024-10-10T19:22:45Z")

</div>

@Marvin - if your issue was resolved please consider **Mark As Solution** to help other community members find help faster/easier.

Thanks,

Lief
