Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Software - Troubleshooting and Discussion > macOS > Securing VNC over VPN with Mac OS X

Securing VNC over VPN with Mac OS X
Thread Tools
~bash $
Forum Regular
Join Date: Feb 2007
Status: Offline
Reply With Quote
Dec 18, 2007, 09:02 PM
 
I am wondering how I can effectively have access control on the VNC service in Mac OS X (10.5.1). Any ideas how this might work in OS X?

This is easy to do with ssh control, for instance, which secures port 22 to only accept connections. So various solutions might include port forwarding a VNC port over ssh, or some kind of access control restriction similar to 'hosts.allow'. But I'm unfamiliar with the details and do not want to run a vnc server that can be accessed from anywhere.

Any help would be greatly appreciated. Thanks.
     
mduell
Posting Junkie
Join Date: Oct 2005
Location: Houston, TX
Status: Offline
Reply With Quote
Dec 18, 2007, 09:54 PM
 
Do you want VPN or ssh?
     
Steve Bosell
Mac Enthusiast
Join Date: May 2001
Status: Offline
Reply With Quote
Dec 19, 2007, 12:00 PM
 
The command to tunnel it over SSH is:
ssh -L 1202:localhost:5900 remote-host

then from "Connect to server", use vnc://localhost:1202
     
~bash $  (op)
Forum Regular
Join Date: Feb 2007
Status: Offline
Reply With Quote
Dec 20, 2007, 05:33 PM
 
Hey, thanks for the tunneling command! It always gives me a headache. How do I secure the server side so that no one can connect to it outside of the tunnel?

Regarding the VPN/SSH question: Over ssh is ideal, as obviously fewer people have access to ssh to my remote machine. My ssh is currently set up only to allow people within the VPN space, so it does get confusing for me. Anyway, setting up VNC via ssh would be the way I want to go.

Thanks ...
     
besson3c
Clinically Insane
Join Date: Mar 2001
Location: yes
Status: Offline
Reply With Quote
Dec 20, 2007, 06:26 PM
 
Will you be connecting from a static IP or a static subnet?
     
~bash $  (op)
Forum Regular
Join Date: Feb 2007
Status: Offline
Reply With Quote
Dec 22, 2007, 07:07 PM
 
Static subnet.
     
   
Thread Tools
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 03:15 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,