Solved

RealVNC and multiple users with a firewall

Posted on 2004-09-13
6
515 Views
Last Modified: 2013-11-21
I'm a typical network rookie so this question maybe an easy one:

A few users at work want to access server-based programs from home. I told them that they can remote in using remote desktop. They don't have Windows XP Professional though and I resorted to using RealVNC. Since RealVNC connects using ports 5900+N, how would I set up the firewall/VPN/router so that the connection is:

a) secure
b) multiple users can all connect at once (do I assign each person their own VNC port? eg User1 is 5901, User2 is 5902, etc)

Then when I connect using the RealVNC client do I type in the IP address with the port at the end? (xxx.yyy.zzz.fff:port)

Same goes for Remote Desktop for users that actually have Windows XP Pro on the network. How do they access their own computer on the network from home using that?
0
Comment
Question by:lchyi
  • 4
6 Comments
 
LVL 15

Expert Comment

by:Yan_west
ID: 12047041
1st, if you are not using VPN to connect to your network, forget RealVNC.. RealVNC does not encrypt the connection. If you do it through VPN, then it is secure.

If you do it through a VPN, you wont have to assign multiple port for VNC because each person will connect to a different computer from a seperate ip.
You would only have to configure multiple port if you would connect through your router to your workstation using port fowarding.

for Remote desktop, they have to 1st establish a VPN connection, then only type in the remote IP of their machine, and voila, they are connected.
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12047057
Btw, remote desktop encrypt connections by default..
0
 

Accepted Solution

by:
danjensen earned 30 total points
ID: 12047791
Not QUITE sure what you're trying to do.

Everybody tagging the mainframe (or other shared machine) via VNC at once:  Won't work - VNC only takes one incoming call at a time.  And frankly, you don't want it.  Five people connected, moving the mouse five different ways trying to get five things done at a time.  Ugh.

Everybody connecting to their individual desktops over the VPN:  Just have them connect to their individual IPs on the default port for VNC.  Very low maint, and probably the best way to get this done if RDP won't work.  (There is a remote desktop client available for 2000 - scour around Microsoft's site for it - I think that's where I got it.)

Everybody connecting to their individual desktops in the office from home, when the router's the only machine facing the internet:  Trickier, but doable: a little port forwarding would be in order.  Assign each user a port number, then set up a rule on the router that says to forward that user's connection to his desktop and configure their VNC to listen on their assigned port number..

Alice's desktop at work is 192.168.0.100.  She gets assigned port 5800.  Tell her to connect to http://router.yourcompany.com:5800.
Set up the router to forward incoming connections on port 5800 to 192.168.0.100, then set up VNC on her machine to listen on 5800.
Bob's at 192.168.178.101, so you assign him port 5900.  He gets the same address, but should only connect on port 5900.  Set the router up with a new rule in the same fashion:  5900 forwards to ...101, and set up the VNC client on Bob's machine to listen on 5900.

You really should encrypt this traffic if you're not using a VPN, but if you're not concerned, that ought to work.
0
Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 

Author Comment

by:lchyi
ID: 12049263
Great answer Dan! With the VPN, is it possible to not do port forwarding since they're already on the network? I mean, would their 192.168.0.80 be the 192.168.0.80 on the remote server while connecting via VPN or would it be their own local 192.168.0.80?
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12049492
if you are on a VPN no port fowarding is necessary because you are already on the network! it'S just like you would connect to the computer just next to you in your office..
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12049707
hey, no points for me? :)
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Suggested Solutions

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now