RE: VNC over VPN, security considerations?

"Andrew Prince" <[email protected]>
Newsgroups gmane.comp.security.vpn
Organization Trinity Security Services
Message-ID <001001c3c3af$f3b78690$0201a8c0@Phobos>
John,
 
I don't see a problem that cannot bee over come - I can think of two ways:-
 
1) Use SSH tunnelling to your VNC server
2) Don't worry - if you are using the Cisco VPN client, it comes in built
with Zone LABS firewall, this will stop any other machine trying to connect
to the remote user while on the VPN.  As long as you have configured you
firewalls & VPN concentrator to only allow VNC traffic from specific remote
hosts/subnets (Which will be encrypted) you should be OK.
 
HTH,
Andy.
-----Original Message-----
From: [email protected]
[mailto:[email protected]] On
Behalf Of Galeotos, John
Sent: 15 December 2003 17:56
To: [email protected]
Subject: [VPN] VNC over VPN, security considerations?




        Hello, 

        Well again normally I just sit back and read what you all have to
say, but I've 
        got another question. For the most part our VPN is up and functional
without 
        anything more for me to do except load the cisco client software on
to the 
        machines of the converts. Recently however I have been looking at
uses I could 
        have for the VPN aside from answering my Emails on my days off. 

        One of the software products I use on occasion is VNC for remote
control access 
        and installs of patches, and the like. It looks as if when I do a
search for ports 
        and VNC I get as many hits telling me that ports 5800 and
5900+display# are the 
        ones used as I get "VNC port firewall, viren, hackertools, and
exploits." This does 
        not give me a warm fuzzy about opening those ports so that I could
use VNC 
        over the VPN. 

        So my question is simply: "What are the considerations and
mitigating steps 
        that I could take if we decided to open these ports up? Or...is it
simply a very 
        bad idea? 

        Thanks for your time. I'll go back to reading for the most part
again. 

        John Galeotos

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.