# Addressable Terminators

**URL:** <https://openziti.discourse.group/t/addressable-terminators/5692>\
**Category:** General Questions\
**Created:** [March 11, 2026, 10:04am UTC](https://openziti.discourse.group/t/addressable-terminators/5692 "2026-03-11T10:04:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![montwepa](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@montwepa](https://openziti.discourse.group/u/montwepa)\
**Post date:** [March 11, 2026, 10:04am UTC](https://openziti.discourse.group/t/addressable-terminators/5692/1 "2026-03-11T10:04:06Z")

</div>

Hey,

I’ve been looking into **Addressable Terminators** and trying to understand whether they can be used together with **ZDEW** , specifically for a _remote desktop–style use case_.

From examples, I understand that Addressable Terminators allow a client to dial a **specific service host** when multiple hosts provide the same service. For example, the `chat-p2p` sample highlights that addressable terminators let clients dial a particular host even when several identities are bound to the same service. [chat-p2p](https://github.com/openziti/sdk-golang/tree/main/example/chat-p2p)

What I want to achieve is something like this:

- Several machines run an RDP–style service through OpenZiti
- Each machine has their own identity.
- From my client machine, I want to choose which host to connect to.

### **My questions:**

1. **Does ZDEW support Addressable Terminators?**  
Can I choose a specific identity when dialing?

### **My goal / use case**

The idea is to have a single service that multiple desktop machines “bind” to, and then allow the user to select which machine to remote into by specifying the identity name.

---

<div class="post-metadata">

**Author:** ![rcsoleng](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rcsoleng/32/842_2.png) [@rcsoleng](https://openziti.discourse.group/u/rcsoleng)\
**Post date:** [March 11, 2026, 6:33pm UTC](https://openziti.discourse.group/t/addressable-terminators/5692/2 "2026-03-11T18:33:40Z")

</div>

Hi @montwepa:

You can do something like below which would allow you to dial the endpoint by identity name by matching the names to ziti DNS URLS.  
So the identities both bind and dial on the same service and using ziti dns hostname to identity name conversion. If you can split the bind and dials if some will only be dialers and some will be serving e.g. #WINNET\_DIALERS, #WINNET\_LISTENERS. The below assumes symmetrical dial and bind modify as needed.

Identity 1 Name : [client1.ziti.net](http://client1.ziti.net) : “roleAttributes”: [“WINNET”]  
Identity 2 Name : [client2.ziti.net](http://client2.ziti.net) : “roleAttributes”: [“WINNET”]

```auto
{
"name": "addressable-service.intercept.v1",
"configTypeId": "g7cIWbcGg",
"data": {
"portRanges": \[
{
"high": 8000,
"low": 8000
}
\],
"addresses": \[
"\*.ziti.net"
\],
"dialOptions": {
"identity": "$dst_hostname"
},
"protocols": \[
"tcp"
\]
},
"tags": {}
}

{
"name": "addressable-service.host.v1",
"configTypeId": "NH5p4FpGR",
"data": {
"protocol": "tcp",
"address": "127.0.0.1",
"forwardPort": true,
"allowedPortRanges": \[
{
"high": 8000,
"low": 8000
}
\],
"httpChecks": [],
"listenOptions": {
"identity": "$tunneler_id.name"
},
"portChecks": []
},
"tags": {}
}

{
"name": "addressable-service",
"roleAttributes": [],
"configs": \[
"3LWQRbt4o6qzYy7BwwG7RA",
"3jCq6ijiqnQVbs2i8VeMPD"
\],
"encryptionRequired": true,
"terminatorStrategy": "smartrouting",
"tags": {}
}

{
"name": "addressable-service.bind",
"appData": "",
"serviceRoles": \[
"@6rbpqOTppibWKgT5LAuBj1"
\],
"identityRoles": \[
"#WINNET"
\],
"postureCheckRoles": [],
"semantic": "AnyOf",
"type": "Bind",
"tags": {}
}

{
"name": "addressable-service.dial",
"appData": "",
"serviceRoles": \[
"@6rbpqOTppibWKgT5LAuBj1"
\],
"identityRoles": \[
"#WINNET"
\],
"postureCheckRoles": [],
"semantic": "AnyOf",
"type": "Dial",
"tags": {}
}

```

---

<div class="post-metadata">

**Author:** ![montwepa](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@montwepa](https://openziti.discourse.group/u/montwepa)\
**Post date:** [March 23, 2026, 11:34am UTC](https://openziti.discourse.group/t/addressable-terminators/5692/3 "2026-03-23T11:34:45Z")

</div>

Hey @rcsoleng thanks for the answer!

I was able to get this working with the examples you provided, but when I tried it on a clustered setup I wasn't able to get it to work.

Any ideas if this should work in a clustered setup? I double and triple checked and everything should match my non clustered setup where I was able to get it to work.
