Solved

RealVNC and multiple users with a firewall

Posted on 2004-09-13
6
517 Views
Last Modified: 2013-11-21
I'm a typical network rookie so this question maybe an easy one:

A few users at work want to access server-based programs from home. I told them that they can remote in using remote desktop. They don't have Windows XP Professional though and I resorted to using RealVNC. Since RealVNC connects using ports 5900+N, how would I set up the firewall/VPN/router so that the connection is:

a) secure
b) multiple users can all connect at once (do I assign each person their own VNC port? eg User1 is 5901, User2 is 5902, etc)

Then when I connect using the RealVNC client do I type in the IP address with the port at the end? (xxx.yyy.zzz.fff:port)

Same goes for Remote Desktop for users that actually have Windows XP Pro on the network. How do they access their own computer on the network from home using that?
0
Comment
Question by:lchyi
  • 4
6 Comments
 
LVL 15

Expert Comment

by:Yan_west
ID: 12047041
1st, if you are not using VPN to connect to your network, forget RealVNC.. RealVNC does not encrypt the connection. If you do it through VPN, then it is secure.

If you do it through a VPN, you wont have to assign multiple port for VNC because each person will connect to a different computer from a seperate ip.
You would only have to configure multiple port if you would connect through your router to your workstation using port fowarding.

for Remote desktop, they have to 1st establish a VPN connection, then only type in the remote IP of their machine, and voila, they are connected.
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12047057
Btw, remote desktop encrypt connections by default..
0
 

Accepted Solution

by:
danjensen earned 30 total points
ID: 12047791
Not QUITE sure what you're trying to do.

Everybody tagging the mainframe (or other shared machine) via VNC at once:  Won't work - VNC only takes one incoming call at a time.  And frankly, you don't want it.  Five people connected, moving the mouse five different ways trying to get five things done at a time.  Ugh.

Everybody connecting to their individual desktops over the VPN:  Just have them connect to their individual IPs on the default port for VNC.  Very low maint, and probably the best way to get this done if RDP won't work.  (There is a remote desktop client available for 2000 - scour around Microsoft's site for it - I think that's where I got it.)

Everybody connecting to their individual desktops in the office from home, when the router's the only machine facing the internet:  Trickier, but doable: a little port forwarding would be in order.  Assign each user a port number, then set up a rule on the router that says to forward that user's connection to his desktop and configure their VNC to listen on their assigned port number..

Alice's desktop at work is 192.168.0.100.  She gets assigned port 5800.  Tell her to connect to http://router.yourcompany.com:5800.
Set up the router to forward incoming connections on port 5800 to 192.168.0.100, then set up VNC on her machine to listen on 5800.
Bob's at 192.168.178.101, so you assign him port 5900.  He gets the same address, but should only connect on port 5900.  Set the router up with a new rule in the same fashion:  5900 forwards to ...101, and set up the VNC client on Bob's machine to listen on 5900.

You really should encrypt this traffic if you're not using a VPN, but if you're not concerned, that ought to work.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:lchyi
ID: 12049263
Great answer Dan! With the VPN, is it possible to not do port forwarding since they're already on the network? I mean, would their 192.168.0.80 be the 192.168.0.80 on the remote server while connecting via VPN or would it be their own local 192.168.0.80?
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12049492
if you are on a VPN no port fowarding is necessary because you are already on the network! it'S just like you would connect to the computer just next to you in your office..
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12049707
hey, no points for me? :)
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
How to limit traffic to Netscaler 10.5 VIP 3 69
f5 Persistence 14 52
Support licences 3 25
Sonicwall guest user accounts 2 10
Short answer to this question: there is no effective WiFi manager in iOS devices as seen in Windows WiFi or Macbook OSx WiFi management, but this article will try and provide some amicable solutions to better suite your needs.
Know what services you can and cannot, should and should not combine on your server.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question