Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

RealVNC and multiple users with a firewall

Posted on 2004-09-13
6
Medium Priority
?
523 Views
Last Modified: 2013-11-21
I'm a typical network rookie so this question maybe an easy one:

A few users at work want to access server-based programs from home. I told them that they can remote in using remote desktop. They don't have Windows XP Professional though and I resorted to using RealVNC. Since RealVNC connects using ports 5900+N, how would I set up the firewall/VPN/router so that the connection is:

a) secure
b) multiple users can all connect at once (do I assign each person their own VNC port? eg User1 is 5901, User2 is 5902, etc)

Then when I connect using the RealVNC client do I type in the IP address with the port at the end? (xxx.yyy.zzz.fff:port)

Same goes for Remote Desktop for users that actually have Windows XP Pro on the network. How do they access their own computer on the network from home using that?
0
Comment
Question by:lchyi
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
6 Comments
 
LVL 15

Expert Comment

by:Yan_west
ID: 12047041
1st, if you are not using VPN to connect to your network, forget RealVNC.. RealVNC does not encrypt the connection. If you do it through VPN, then it is secure.

If you do it through a VPN, you wont have to assign multiple port for VNC because each person will connect to a different computer from a seperate ip.
You would only have to configure multiple port if you would connect through your router to your workstation using port fowarding.

for Remote desktop, they have to 1st establish a VPN connection, then only type in the remote IP of their machine, and voila, they are connected.
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12047057
Btw, remote desktop encrypt connections by default..
0
 

Accepted Solution

by:
danjensen earned 120 total points
ID: 12047791
Not QUITE sure what you're trying to do.

Everybody tagging the mainframe (or other shared machine) via VNC at once:  Won't work - VNC only takes one incoming call at a time.  And frankly, you don't want it.  Five people connected, moving the mouse five different ways trying to get five things done at a time.  Ugh.

Everybody connecting to their individual desktops over the VPN:  Just have them connect to their individual IPs on the default port for VNC.  Very low maint, and probably the best way to get this done if RDP won't work.  (There is a remote desktop client available for 2000 - scour around Microsoft's site for it - I think that's where I got it.)

Everybody connecting to their individual desktops in the office from home, when the router's the only machine facing the internet:  Trickier, but doable: a little port forwarding would be in order.  Assign each user a port number, then set up a rule on the router that says to forward that user's connection to his desktop and configure their VNC to listen on their assigned port number..

Alice's desktop at work is 192.168.0.100.  She gets assigned port 5800.  Tell her to connect to http://router.yourcompany.com:5800.
Set up the router to forward incoming connections on port 5800 to 192.168.0.100, then set up VNC on her machine to listen on 5800.
Bob's at 192.168.178.101, so you assign him port 5900.  He gets the same address, but should only connect on port 5900.  Set the router up with a new rule in the same fashion:  5900 forwards to ...101, and set up the VNC client on Bob's machine to listen on 5900.

You really should encrypt this traffic if you're not using a VPN, but if you're not concerned, that ought to work.
0
Are You Ready for GDPR?

With the GDPR deadline set for May 25, 2018, many organizations are ill-prepared due to uncertainty about the criteria for compliance. According to a recent WatchGuard survey, a staggering 37% of respondents don't even know if their organization needs to comply with GDPR. Do you?

 

Author Comment

by:lchyi
ID: 12049263
Great answer Dan! With the VPN, is it possible to not do port forwarding since they're already on the network? I mean, would their 192.168.0.80 be the 192.168.0.80 on the remote server while connecting via VPN or would it be their own local 192.168.0.80?
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12049492
if you are on a VPN no port fowarding is necessary because you are already on the network! it'S just like you would connect to the computer just next to you in your office..
0
 
LVL 15

Expert Comment

by:Yan_west
ID: 12049707
hey, no points for me? :)
0

Featured Post

Fill in the form and get your FREE NFR key NOW!

Veeam® is happy to provide a FREE NFR server license to certified engineers, trainers, and bloggers.  It allows for the non‑production use of Veeam Agent for Microsoft Windows. This license is valid for five workstations and two servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
This month, Experts Exchange’s free Course of the Month is focused on CompTIA IT Fundamentals.
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question