Networking Forums

Networking Forums > Network Hardware > Home Networking > VNC and port forwarding

Reply
Thread Tools Display Modes

VNC and port forwarding

 
 
JTM
Guest
Posts: n/a

 
      10-12-2009, 04:10 PM
I'm away from home a fair bit, but sometimes need to sort out some printing
and other work. So I'm trying to set up VNC

My wife's (xp) wireless netbook has the IP 192.168.1.x (set using DHCP from
the D-Link router)

I've enabled port forwarding on the router for:
'private IP' 192.168.1.20 (the first number),
'all protocols',
'start port 5900',
'end port 5900' (+ the same off-set for each port) and using
'connection PVC0'

This seems to work all right. Is that it? or am I leaving something
vulnerable to attacks?

I wasn't sure what options might go in the 'protocols' setting

TIA

John

--
John Mulrooney
NOTE Email address IS correct but might not be checked for a while.

About 95% of quoted statistics are probably made up
 
Reply With Quote
 
 
 
 
Anthony R. Gold
Guest
Posts: n/a

 
      10-12-2009, 05:49 PM
On Mon, 12 Oct 2009 16:10:22 +0100, JTM <(E-Mail Removed)> wrote:

> I'm away from home a fair bit, but sometimes need to sort out some printing
> and other work. So I'm trying to set up VNC
>
> My wife's (xp) wireless netbook has the IP 192.168.1.x (set using DHCP from
> the D-Link router)
>
> I've enabled port forwarding on the router for:
> 'private IP' 192.168.1.20 (the first number),
> 'all protocols',
> 'start port 5900',
> 'end port 5900' (+ the same off-set for each port) and using
> 'connection PVC0'
>
> This seems to work all right. Is that it? or am I leaving something
> vulnerable to attacks?


If you are using password authentication then that should be as safe as the
strength of the chosen password.

I would nail down the IP address of the netbook by setting it to be fixed
and not rely on it getting the same address each time from DHCP.

Is your home Internet on a fixed IP address or are you using DynDNS etc?

Tony
 
Reply With Quote
 
Bernard Peek
Guest
Posts: n/a

 
      10-12-2009, 06:53 PM
In message <(E-Mail Removed)>, JTM <(E-Mail Removed)> writes

>This seems to work all right. Is that it? or am I leaving something
>vulnerable to attacks?


VNC has a poor reputation for security. One reason is that it sends
passwords as clear text. That may not be an issue if all you keep on the
machine is your own personal data. If you keep any of your employer's
data on the machine you should get their permission and advice.

The usual advice for making VNC more secure is to use SSH tunnelling
using stunnel or similar. The VNC server should then be locked so that
only local users (including those using tunnels) can connect.



--
Bernard Peek
 
Reply With Quote
 
JTM
Guest
Posts: n/a

 
      10-12-2009, 08:09 PM
In article <(E-Mail Removed)>,
Bernard Peek <(E-Mail Removed)> wrote:
> In message <(E-Mail Removed)>, JTM <(E-Mail Removed)> writes


> >This seems to work all right. Is that it? or am I leaving something
> >vulnerable to attacks?


> VNC has a poor reputation for security. One reason is that it sends
> passwords as clear text. That may not be an issue if all you keep on the
> machine is your own personal data. If you keep any of your employer's
> data on the machine you should get their permission and advice.


> The usual advice for making VNC more secure is to use SSH tunnelling
> using stunnel or similar. The VNC server should then be locked so that
> only local users (including those using tunnels) can connect.


Thanks to A R Gold, Alex Fraser and yourself for the replies.

The home address is not fixed, so I'll need grandson or someone to
switch on and tell me what it is. (whatismyip.com?)

I'll have to read up on SSH tunnelling and address Reservation.

So far though, this VNC seems easier than my attemps to set up home
networks for XP, Vista, RISC OS and Mandriva / Kubuntu. Only partially
managed that over the last few years while I seem to have VNC working
within a week!

Tomorrow I get to see if it works from France as well as it has from a
couple of miles away.

Thanks again

John

--
John Mulrooney
NOTE Email address IS correct but might not be checked for a while.

The grave's a fine and private place, but none I think do there embrace
 
Reply With Quote
 
Anthony R. Gold
Guest
Posts: n/a

 
      10-12-2009, 08:46 PM
On Mon, 12 Oct 2009 20:09:20 +0100, JTM <(E-Mail Removed)> wrote:

> The home address is not fixed, so I'll need grandson or someone to
> switch on and tell me what it is. (whatismyip.com?)
>
> I'll have to read up on SSH tunnelling and address Reservation.


http://www.dyndns.com/ is free will allow you to address the home by some
chosen hostname (eg: (E-Mail Removed)) regardless of its changing IP
address, which should be far simpler.

> Tomorrow I get to see if it works from France as well as it has from a
> couple of miles away.


If you need help either opening the free account or installing the DynDNS
client software then ask again.

Tony
 
Reply With Quote
 
Anthony R. Gold
Guest
Posts: n/a

 
      10-12-2009, 08:48 PM
On Mon, 12 Oct 2009 20:46:58 +0100, "Anthony R. Gold"
<not-for-(E-Mail Removed)> wrote:

> On Mon, 12 Oct 2009 20:09:20 +0100, JTM <(E-Mail Removed)> wrote:
>
>> The home address is not fixed, so I'll need grandson or someone to
>> switch on and tell me what it is. (whatismyip.com?)
>>
>> I'll have to read up on SSH tunnelling and address Reservation.

>
> http://www.dyndns.com/ is free will allow you to address the home by some
> chosen hostname (eg: (E-Mail Removed)) regardless of its changing IP
> address, which should be far simpler.


Sorry, that should of course be jtmhome.dyndns.org and not wot i rote b4.

Tony
 
Reply With Quote
 
robert
Guest
Posts: n/a

 
      10-13-2009, 11:01 PM
Anthony R. Gold wrote:
> On Mon, 12 Oct 2009 20:46:58 +0100, "Anthony R. Gold"
> <not-for-(E-Mail Removed)> wrote:
>
>> On Mon, 12 Oct 2009 20:09:20 +0100, JTM <(E-Mail Removed)> wrote:
>>
>>> The home address is not fixed, so I'll need grandson or someone to
>>> switch on and tell me what it is. (whatismyip.com?)
>>>
>>> I'll have to read up on SSH tunnelling and address Reservation.

>> http://www.dyndns.com/ is free will allow you to address the home by some
>> chosen hostname (eg: (E-Mail Removed)) regardless of its changing IP
>> address, which should be far simpler.

>
> Sorry, that should of course be jtmhome.dyndns.org and not wot i rote b4.
>
> Tony

I'm using the free

https://www.no-ip.com

has worked flawlessly for a year on my father's pc.

A good way of getting/checking the IP address of the remote PC is to get
them to send you an email and look at the first received from in the
headers/source - dynamic IP address dont change that often if you leave
the router switched on.

 
Reply With Quote
 
JTM
Guest
Posts: n/a

 
      10-17-2009, 07:40 PM
In article <(E-Mail Removed)>,
JTM <(E-Mail Removed)> wrote:

> Tomorrow I get to see if it works from France as well as it has from a
> couple of miles away.


Well I've been in France for a few days and today needed to try to print
some documents at home in Lancs. Daughter switched wife's netbook on and
grandson looked after the printer in the attic. VNC (ultraVNC actually
'cos realvnc won't work with Vista) did the job and I'm a happy chappy.

Thanks again folks.

John

--
John Mulrooney
NOTE Email address IS correct but might not be checked for a while.

Health is not valued until sickness comes
 
Reply With Quote
 
Philip Herlihy
Guest
Posts: n/a

 
      10-18-2009, 12:25 PM
JTM wrote:
> In article <(E-Mail Removed)>,
> JTM <(E-Mail Removed)> wrote:
>
>> Tomorrow I get to see if it works from France as well as it has from a
>> couple of miles away.

>
> Well I've been in France for a few days and today needed to try to print
> some documents at home in Lancs. Daughter switched wife's netbook on and
> grandson looked after the printer in the attic. VNC (ultraVNC actually
> 'cos realvnc won't work with Vista) did the job and I'm a happy chappy.
>
> Thanks again folks.
>
> John
>


The free version of RealVNC won't work with Vista, you have to use the
Personal Edition, which is about £20. Does UltraVNC have a "listening
client" option? I find that very useful.

Phil, London
 
Reply With Quote
 
JTM
Guest
Posts: n/a

 
      10-18-2009, 02:18 PM
In article <mWCCm.25705$(E-Mail Removed)2>,
Philip Herlihy <(E-Mail Removed)> wrote:

> The free version of RealVNC won't work with Vista, you have to use the
> Personal Edition, which is about £20. Does UltraVNC have a "listening
> client" option? I find that very useful.


> Phil, London


It has UltraVNC viewer listen mode and UltraVNC viewer listen
mode(Encrypted)

--
John Mulrooney
NOTE Email address IS correct but might not be checked for a while.

There are 3 types of people: those who are numerate and those who aren't.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
port tunneling over ssh (not port-forwarding in the traditional sense) C3 Linux Networking 1 07-26-2006 04:44 PM
Port forwarding on Conexant 4 port adsl router Graham Russell Broadband 14 10-24-2003 10:16 PM
Port forwarding on Conexant 4 port adsl router Graham Russell Broadband 1 10-17-2003 12:09 PM
Stupid Question: Port Triggering vs. Port Forwarding Bryce Wireless Internet 3 09-09-2003 06:45 AM
Do I need port forwarding on 25 port to send messages? bu Linux Networking 4 07-17-2003 03:42 PM



1 2 3 4 5 6 7 8 9 10 11