LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 02-05-2014, 02:53 PM   #1
mxmaniac
LQ Newbie
 
Registered: Feb 2014
Posts: 26

Rep: Reputation: Disabled
How do I configure VNC to only accept localhost connections? And not open up ports?


I am new to VNC, and wondering how I go about configuring a VNC server to only allow localhost connections?

The idea is I only want to connect via ssh tunneling. I do not want to inadvertently be opening up ports like 5901 to other machines in the network.

I've tried tightVNC vnc4server, and realvnc, but none of them seem to make the option how to do this clear. I saw one man page somewhere where you could use a -localhost flag, however I'd rather be able to have this permanently in a config file, to reduce the chance of accidentally forgetting that flag one day and inadvertently opening up a port I didn't want to.

PS: Would be nice to save other settings like the "geometry" setting in the config file too if that's possible.
 
Old 02-05-2014, 04:22 PM   #2
Ser Olmy
Senior Member
 
Registered: Jan 2012
Distribution: Slackware
Posts: 3,334

Rep: Reputation: Disabled
I'm not really familiar with VNC, but the best (pretty much fool proof) way to prevent external connections to a service, is to bind it to 127.0.0.1.
 
Old 02-06-2014, 06:59 AM   #3
strick1226
Member
 
Registered: Feb 2005
Distribution: Arch, CentOS, Fedora, macOS, SLES, Ubuntu
Posts: 327

Rep: Reputation: 63
If you configure your firewall to block all incoming traffic except SSH (i.e. including 5901 etc.) would that not suffice? That way, you could still SSH into the box, then run VNC through the established SSH tunnel.

If you want to explicitly set VNC only to listen to the localhost interface, then you would need to edit the VNCserver conf file (/etc/sysconfig/vncservers on CentOS; /etc/vncserver/vncservers.conf on Debian/Ubuntu (I think)).

Edit the VNCSERVERARGS line and add "-localhost" within the quotes, save, restart the vnc server and you should be good to go.

Last edited by strick1226; 02-06-2014 at 07:05 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Open port# 9171 on a Linux OEL5.5 server to accept connections Hiroshi Linux - Networking 3 02-20-2011 08:39 AM
SSH will not accept connections after trying to get VNC working with gdm on fedora 11 seemeinhi Linux - Server 16 08-04-2009 05:42 PM
How to determine which ports are open for outbound connections? mpmackenna Linux - Security 14 04-25-2008 01:59 PM
proftpd: cannot accept connections lievendp Linux - Software 1 01-24-2006 08:41 AM
rh9: configure ports to accept remote connection for azureus bleachie Linux - Software 0 02-16-2004 02:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 09:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration