VNC graphical connections
What this page covers
Section titled “What this page covers”VNC desktops reached in the browser. The backend performs the handshake and injects the credential, and the frontend touches nothing in the clear. The RFB protocol has no file channel of its own, so when files need to move the system opens a separate SFTP sidecar channel to the same host, sharing the audited path with RDP uploads.
What you need
Section titled “What you need”- A target host running the VNC service (port 5900 by default).
- For file transfer, the SSH service on the same host, plus an account and password for the sidecar.
How to set it up
Section titled “How to set it up”Choose VNC as the protocol when creating the asset, which fills in port 5900. VNC uses a password only, so there is no username field.
To turn on file transfer, switch on “SFTP file transfer” in the asset form and fill in:
- The SFTP port.
- The SFTP account: the SSH username on the target host.
- The SFTP password: when editing an asset that already has one, leaving it empty keeps the stored password.
The sidecar channel always targets this asset’s host address, and the frontend cannot point it elsewhere. Uploads land in the home directory of that SSH account. While it is off, the file transfer entrance stays off the toolbar.
Display size negotiation and the bidirectional clipboard behave as they do for RDP, over the same graphics channel.
Transmission risk marking
Section titled “Transmission risk marking”The RFB protocol carries no encryption option, so a VNC asset always shows a transmission risk badge in the asset list. The badge appears at every policy level, so that the nature of the channel is visible before you choose to connect. To bring connections like this under enforcement, see Transmission security policy.
What auditors can see
Section titled “What auditors can see”- Recording: the same native format as RDP, played back on the session detail page.
- Clipboard content is kept, with its direction and content.
- An upload over the sidecar leaves a file transfer record naming the channel it used.
- When policy turns uploads off, a stopped transfer leaves a record all the same, with its status marked as refused.
- The screen carries a watermark.