Skip to main content
Contributor III
September 11, 2007
Question

VNC Through Fortigate

  • September 11, 2007
  • 3 replies
  • 4015 views
VNC uses TCP ports 5900 and 5800 by default. With that in mind, I have VNC successfully working with the following rules. Wireless to Internal Client Internal Client to Wireless Ports 1-65535 Source and 5900 Destination Ports 1-65535 Source and 5800 Destination While I do not like having these ports open at all it is a requirement for our developers. Does anybody have any other rule sets that work which may be a bit more locked down?

    3 replies

    doshbass
    New Member
    September 11, 2007
    This seems pretty well locked down to me, you are opening 2 ports only
    rwpatterson
    New Member
    September 11, 2007
    If you combine that with an SSL VPN login, you' re better secured. Create NAT IP ranges for the logins, then create a policy from the external ports using that IP range to the VIP on the same port. Then the only way into those servers would be after a successful login. I did it, so I know it works.
    Hracio
    New Member
    September 11, 2007
    Use 1024-65535 range as source ports, dest 5800-5900, combined with ssl-vpn as rwpatterson says.. Regards, .!
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!