Hi everyone,
I'm struggling to understand what is the best way to harding a VNC connection.
I have a fedora machine within a local WiFi network (WPA2 encryption), and I installed a RealVNC server on it. On the one hand, I looking for high speed connection within the lan. On the other hand, I willing to secure to outcome connection from the wan (brute force and sniffing).
I thought about 2 solutions:
1. Relay on the VNC internal encryption, and publish the vnc's ports to the outer world - 5800 5900. Also, configure iptables rules for dropping brute force attacks on the ports.
2. Disable all the VNC internal encryption. The outer world beyond the router will be able to connect my VNC only with a SSH tunnel, which accept only public keys authentication. Within the lan, the iptables will allow connection to the vnc's ports.
what you propose me to do?
TNX!!!
