republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies


jaynick
lit up
Premium
join:2001-02-06
Sterling Heights, MI
kudos:2

reply to StuartMW

Re: How to secure VNC and port 5900

I just thought I see the word attempt or blocked or something like that instead of just LAN access. Wasn't sure what to make of it. Any way I'll use one of the other suggested approaches.


StuartMW
Who Is John Galt?
Premium
join:2000-08-06
Galt's Gulch
kudos:2
Reviews:
·CenturyLink

The only thing I can think of, offhand, is to

• Enable port forwarding for 5900.

• Create a firewall rule to block (or only allow) port 5900 accesses from the internet for a single or small range of IP's.

Of course you'd have to know what internet IP(s) you may have (i.e. what are you). The firewall will prevent any port scanners from even reaching your LAN while you'll get through.
--
Don't feed trolls--it only makes them grow!



jaynick
lit up
Premium
join:2001-02-06
Sterling Heights, MI
kudos:2
Reviews:
·Comcast

said by StuartMW:

Of course you'd have to know what internet IP(s) you may have (i.e. what are you). The firewall will prevent any port scanners from even reaching your LAN while you'll get through.

Yes, that's the problem with that.


StuartMW
Who Is John Galt?
Premium
join:2000-08-06
Galt's Gulch
kudos:2
Reviews:
·CenturyLink

said by jaynick:

Yes, that's the problem with that.

Yup. Well port forwarding is just a limited workaround to NAT. The intended purpose is to allow servers to appear as though they're directly on the internet (i.e. open to all comers).

Again if you secure VNC (or whatever) then any bad guys won't be able to get into your LAN box although any and all requests will get to that box (and rejected if you have good authentication).

The choice is up to you.
--
Don't feed trolls--it only makes them grow!


jaynick
lit up
Premium
join:2001-02-06
Sterling Heights, MI
kudos:2

Bottom line is that all those entries were probes and attempts but not actual access. Correct? and a 63 char random password like I use for my wireless key would be as secure as it could get other than using other ways like mentioned above?



StuartMW
Who Is John Galt?
Premium
join:2000-08-06
Galt's Gulch
kudos:2
Reviews:
·CenturyLink

said by jaynick:

Bottom line is that all those entries were probes and attempts but not actual access. Correct?

Correct.

As for passwords it really depends if all 63 chars are being used as angussf See Profile pointed out.
--
Don't feed trolls--it only makes them grow!

dave
Premium,MVM
join:2000-05-04
not in ohio
kudos:8

reply to jaynick

said by jaynick:

I just thought I see the word attempt or blocked or something like that instead of just LAN access. Wasn't sure what to make of it. Any way I'll use one of the other suggested approaches.

You are confusing layers. A TCP connection was successfully established. We presume they were not able to log in, but that's not your router's concern.


jaynick
lit up
Premium
join:2001-02-06
Sterling Heights, MI
kudos:2
Reviews:
·Comcast

said by dave:

said by jaynick:

I just thought I see the word attempt or blocked or something like that instead of just LAN access. Wasn't sure what to make of it. Any way I'll use one of the other suggested approaches.

You are confusing layers. A TCP connection was successfully established. We presume they were not able to log in, but that's not your router's concern.

Thanks, dave See Profile, yes I got it now and headed to different solution for remote access(ssh).

Saturday, 25-May 16:02:56 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics