Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > What's the most secure configuration for Remote Access from a PC to OS X ?

What's the most secure configuration for Remote Access from a PC to OS X ?
Thread Tools
Fresh-Faced Recruit
Join Date: Sep 2000
Status: Offline
Reply With Quote
Feb 21, 2007, 09:29 AM
 
Hi all,

I am hoping to set up my Mac and AirPort Extreme so I can connect to it from my office that is running a Windows machine. Currently the AirPort network is closed and I have set it up with WEP passwords. I can connect between my iMac and iBook using VNC which works fairly well although a bit slow at times; but, hey, it's free.

What would you all recommend as the best way and most secure method to set up my Network so I can remotely access it from a Windows machine at my office?

Thanks for any help.

Ed
     
Professional Poster
Join Date: Mar 2002
Location: Smallish town in Ohio
Status: Offline
Reply With Quote
Feb 22, 2007, 05:54 AM
 
Just use VNC and a good alpha-numerical password. It's a tried and true protocol. Open up the necessary port on the Airport firewall to let traffic pass through to your VNC Mac.
     
Mac Elite
Join Date: May 2001
Location: Vancouver
Status: Offline
Reply With Quote
Feb 22, 2007, 08:43 AM
 
If you really are concerned about security, tunnel VNC over SSH to properly encrypt the traffic.
Macbook (Black) C2D/250GB/3GB | G5/1.6 250GBx2/2.0GB
Free Mobile Ringtone & Games Uploader | Flickr | Twitter
     
eyost  (op)
Fresh-Faced Recruit
Join Date: Sep 2000
Status: Offline
Reply With Quote
Feb 22, 2007, 09:45 AM
 
Thanks all.

I assume I would need to use Port Forwarding since the Airport is currently acting as a firewall and the IP Address of my Macs are using 10.0.1.0?

Regarding using the tunnel, what would be the best way to configure VNC through the tunnel?

Thanks for everyone's help.

Ed
     
Administrator
Join Date: Apr 2001
Location: San Antonio TX USA
Status: Offline
Reply With Quote
Feb 22, 2007, 05:20 PM
 
Honestly, if you're interested in security, ditch WEP and go with WPA first!
Glenn -----
OTR/L, MOT, Tx
     
Senior User
Join Date: Jul 2003
Location: Asia
Status: Offline
Reply With Quote
Feb 25, 2007, 08:09 AM
 
Great info on this here:

HOWTO Use Your Mac From Anywhere
     
Clinically Insane
Join Date: Mar 2001
Location: yes
Status: Offline
Reply With Quote
Feb 25, 2007, 11:30 AM
 
Originally Posted by eyost View Post
Thanks all.

I assume I would need to use Port Forwarding since the Airport is currently acting as a firewall and the IP Address of my Macs are using 10.0.1.0?

Regarding using the tunnel, what would be the best way to configure VNC through the tunnel?

Thanks for everyone's help.

Ed

I don't agree with the advice that suggested tunneling the entire connection. Once you have authenticated, the information transmitted is simply "move the mouse pointer here and click" - there is nothing to secure, your data is not being transferred over the connection, just screenshots basically, and it would be extremely difficult to pick apart the useful screenshots out of the entire data stream. VNC passwords are hashed, so your password is not sent in the clear.

If you really want security, what I'd recommend doing is setting up public/private SSH keys with a passphrase. You can use SSH Keychain (which is a GUI for ssh-agent) so that you don't have to type in your passphrase each time you connect. Once you are able to SSH to your machine, I would manually startup your VNC server whenever you want to connect, and then close it down when you are done. However, most people just leave their VNC server running, which is probably fine.

You should probably learn a lot of command line tricks so that you don't have to use VNC though, because it can be slow over a WAN, and many times not even necessary.

What sorts of things do you need to be able to do remotely?
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 05:04 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2