Skip to content
English

VNC graphical connections

VNC desktops reached in the browser. The backend performs the handshake and injects the credential, and the frontend touches nothing in the clear. The RFB protocol has no file channel of its own, so when files need to move the system opens a separate SFTP sidecar channel to the same host, sharing the audited path with RDP uploads.

  • A target host running the VNC service (port 5900 by default).
  • For file transfer, the SSH service on the same host, plus an account and password for the sidecar.

Choose VNC as the protocol when creating the asset, which fills in port 5900. VNC uses a password only, so there is no username field.

To turn on file transfer, switch on “SFTP file transfer” in the asset form and fill in:

  • The SFTP port.
  • The SFTP account: the SSH username on the target host.
  • The SFTP password: when editing an asset that already has one, leaving it empty keeps the stored password.

The sidecar channel always targets this asset’s host address, and the frontend cannot point it elsewhere. Uploads land in the home directory of that SSH account. While it is off, the file transfer entrance stays off the toolbar.

Display size negotiation and the bidirectional clipboard behave as they do for RDP, over the same graphics channel.

The RFB protocol carries no encryption option, so a VNC asset always shows a transmission risk badge in the asset list. The badge appears at every policy level, so that the nature of the channel is visible before you choose to connect. To bring connections like this under enforcement, see Transmission security policy.

  • Recording: the same native format as RDP, played back on the session detail page.
  • Clipboard content is kept, with its direction and content.
  • An upload over the sidecar leaves a file transfer record naming the channel it used.
  • When policy turns uploads off, a stopped transfer leaves a record all the same, with its status marked as refused.
  • The screen carries a watermark.