Skip to content

Enable X11 forwarding ​

X11 forwarding lets you run graphical applications on a remote Linux server and display their windows on your computer. For example, running xclock in a remote Termark terminal opens a clock window on your local desktop.

You need three things: a local X server, a remote SSH server that allows X11 forwarding, and the X11 option enabled in Termark. Your local X server displays the windows separately from Termark's terminal tabs. The remote server does not need a full desktop environment.

1. Install and start a local X server ​

Follow the section for the computer running Termark. These steps run locally, not on the remote server.

macOS: Install XQuartz ​

  1. Open the official website and download an installer compatible with your macOS version.
  2. Open the downloaded disk image and follow the included installer's instructions.
  3. After the first installation, log out of macOS and log back in so the desktop session loads XQuartz's display configuration.
  4. Start XQuartz from Applications → Utilities.
  5. Keep Authenticate connections enabled in XQuartz settings. Forwarding through a local socket does not require enabling Allow connections from network clients.

If Homebrew is installed, you can also install XQuartz from a local terminal:

bash
brew install --cask xquartz

You still need to log out and back in, then start XQuartz.

You can usually leave all three X11 settings in Termark empty. On macOS, Termark uses /opt/X11/bin/xauth by default and automatically looks up the local display.

An XQuartz display typically looks like this:

text
/private/tmp/com.apple.launchd.XXXXXX/org.xquartz:0

Do not replace it with localhost:0. If automatic detection fails, run this in a local terminal:

bash
launchctl getenv DISPLAY

Paste the actual output into Termark's Local display field. If there is no output, confirm that XQuartz is installed and running and that you logged back in after installation.

Windows: Install and start VcXsrv ​

Download and install VcXsrv, then run XLaunch:

  1. Under Display settings, select Multiple windows and leave the display number set to 0.
  2. Under Client startup, select Start no client.
  3. Under Extra settings, select Disable access control.
  4. Finish the wizard and keep VcXsrv running.

On Windows, Termark uses 127.0.0.1:0 by default and does not read xauth or Xauthority settings, so you normally do not need to enter anything. If VcXsrv uses another display number, expand Advanced settings in Termark and change Local display accordingly. For example, use 127.0.0.1:1 for display number 1.

Only your local Termark instance needs to connect to VcXsrv. The remote server does not need direct access to Windows port 6000, so do not open a public inbound port for this feature. Termark does not change VcXsrv's access control settings automatically. Because unauthenticated mode allows local programs that can reach the X server to access the display, limit Windows Firewall access to the networks you actually need and do not allow public network access.

Linux: Use Xorg or XWayland ​

Most Linux desktops already provide Xorg or XWayland. Install missing components through your distribution's package repositories rather than building them from source.

Check these values in a terminal on your local desktop:

bash
echo "$DISPLAY"
command -v xauth

A display value such as :0 or :1 usually indicates that an X display is available. If xauth is missing, install it for your distribution:

bash
# Ubuntu / Debian
sudo apt-get update
sudo apt-get install -y xauth

# Fedora
sudo dnf install -y xorg-x11-xauth

If you use a Wayland desktop without XWayland, install it:

bash
# Ubuntu / Debian
sudo apt-get install -y xwayland

# Fedora
sudo dnf install -y xorg-x11-server-Xwayland

Log out and back in after installation, letting the desktop session manage XWayland. You can usually leave Termark's local settings empty: it reads DISPLAY, while xauth uses XAUTHORITY or its default authorization file. Do not assume the file is always ~/.Xauthority.

Installing xauth alone does not create an X server on a computer without a graphical desktop. XWayland also needs a working Wayland desktop environment. This feature forwards X11 applications, not the native Wayland protocol.

2. Check the local configuration in Termark ​

Open Settings → General → X11 forwarding:

  1. Start the X server as described for your operating system. The default configuration normally works without opening Advanced settings.
  2. Open Advanced settings only if automatic detection fails or you use a non-default display address. Windows shows only Local display; macOS and Linux also provide fields for the xauth executable and Xauthority file.
  3. Changes save automatically when you leave an input field; there is no Save button.
  4. Click Check local X server.
  5. Once the check succeeds and shows the local display address, continue with the remote configuration.

This check only verifies the local X server and authentication. It does not confirm that the remote server allows forwarding. These settings stay on the current computer and are not included in asset cloud sync.

3. Configure the remote SSH server ​

Run the following commands on the remote Linux server.

Install xauth and a test application ​

On Ubuntu / Debian:

bash
sudo apt-get update
sudo apt-get install -y xauth x11-apps

xauth handles X11 authorization for SSH, and x11-apps provides test applications such as xclock and xeyes. On other distributions, install the corresponding xauth and test application packages from their repositories.

Allow X11 forwarding ​

Inspect the effective sshd configuration:

bash
sudo sshd -T | grep -E 'x11forwarding|x11uselocalhost'

It should include:

text
x11forwarding yes
x11uselocalhost yes

If forwarding is disabled, set the following in /etc/ssh/sshd_config or the configuration file your system actually uses:

text
X11Forwarding yes
X11UseLocalhost yes

Validate the configuration before reloading the service:

bash
sudo sshd -t

# Ubuntu / Debian: run after the syntax check succeeds
sudo systemctl reload ssh

# Fedora / RHEL: the service is usually named sshd
# sudo systemctl reload sshd

Match rules, DisableForwarding, SSH certificates, and restrictions in authorized_keys can also prohibit X11. If the global configuration allows forwarding but requests are still rejected, check the restrictions that apply to the current user.

4. Enable forwarding and test it ​

  1. Edit your SSH host in Termark, select Enable X11 forwarding in its advanced settings, and save the host.
  2. Disconnect and create a new connection. Temporary SSH connections have the same option in their connection dialog.
  3. Run these commands in the remote terminal:
bash
echo "$DISPLAY"
xclock

DISPLAY usually looks like localhost:10.0. The remote sshd assigns it automatically, so the actual number can differ. A clock window appearing on your local desktop confirms that X11 forwarding is working. Close the window or press Ctrl+C in the terminal to end the test.

Do not manually set DISPLAY=localhost:0 on the remote server or copy your local XQuartz display path to it. The remote and local display addresses serve different purposes.

Connection behavior and permissions ​

  • X11 forwarding is off by default. When it is off, Termark does not check the local X server or request forwarding.
  • When enabled, SSH still connects normally if the local X server is not running, authorization is unavailable, or the remote server rejects forwarding. The terminal displays a warning explaining why X11 was not enabled.
  • An X11 failure does not create another SSH connection or repeat authentication. After starting the local X server or correcting the configuration, reconnect to request forwarding again.
  • Termark currently uses trusted forwarding, with permissions similar to ssh -Y. Authorized remote graphical applications can access your local X display. Enable it only for trusted hosts.
  • Local SSH assets and temporary SSH connections are supported. Restricted shells do not request X11 forwarding.

Troubleshooting ​

SymptomWhat to check
The local check reports an unavailable display or xauth authorizationConfirm the local X server is installed. On macOS or Linux, check the display, xauth path, and authorization file. On macOS, log back in after the first installation
The local check reports a connection or authentication failureStart XQuartz / VcXsrv. On Windows, confirm that Disable access control is selected in VcXsrv and that its display number matches the address in Termark
The terminal says the remote server rejected forwardingCheck the effective sshd configuration, user restrictions, and remote xauth installation
SSH connects but no graphical window appearsLook for an X11 warning in the terminal. Pass the local check, then create a new connection
Remote DISPLAY is emptyConfirm X11 is enabled for this connection and reconnect. Check whether shell startup scripts unset DISPLAY
xclock: command not foundInstall the test application on the remote server; use x11-apps on Ubuntu / Debian
Can't open displayCheck whether the local X server is still running and whether remote DISPLAY was overwritten. Test as the current SSH user first, since switching users can change authorization

Termark · SSH client and terminal workspace