RE: VNC over VPN, security considerations?
"Glen L. Bowes" <[email protected]>
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
What am I missing here? Why would there be any need to open ports for VNC through a VPN? As long as the ports aren't blocked at the machine that the VNC server is installed on (which would be pointless) the VNC server should be available to the remote VPN user as they he or she were connected directly to the network. The ports should be available by way of the tunnel rather than by way of open ports on a firewall. Again, what am I missing? ________________________________________ From: [email protected] [mailto:[email protected]] On Behalf Of Andrew Prince Sent: Tuesday, December 16, 2003 3:38 AM To: 'Galeotos, John'; [email protected] Subject: RE: [VPN] VNC over VPN, security considerations? John, I don't see a problem that cannot bee over come - I can think of two ways:- 1) Use SSH tunnelling to your VNC server 2) Don't worry - if you are using the Cisco VPN client, it comes in built with Zone LABS firewall, this will stop any other machine trying to connect to the remote user while on the VPN. As long as you have configured you firewalls & VPN concentrator to only allow VNC traffic from specific remote hosts/subnets (Which will be encrypted) you should be OK. HTH, Andy. -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Galeotos, John Sent: 15 December 2003 17:56 To: [email protected] Subject: [VPN] VNC over VPN, security considerations? Hello, Well again normally I just sit back and read what you all have to say, but I've got another question. For the most part our VPN is up and functional without anything more for me to do except load the cisco client software on to the machines of the converts. Recently however I have been looking at uses I could have for the VPN aside from answering my Emails on my days off. One of the software products I use on occasion is VNC for remote control access and installs of patches, and the like. It looks as if when I do a search for ports and VNC I get as many hits telling me that ports 5800 and 5900+display# are the ones used as I get "VNC port firewall, viren, hackertools, and exploits." This does not give me a warm fuzzy about opening those ports so that I could use VNC over the VPN. So my question is simply: "What are the considerations and mitigating steps that I could take if we decided to open these ports up? Or...is it simply a very bad idea? Thanks for your time. I'll go back to reading for the most part again. John Galeotos