Next configure that route to be a vpn server and you connect into it whenever you want. Once connected you can read the logs and check your sons internet habits and you can access the rest of the network to fix their machin. One is to look for alternative remote desktop software that does work.

This is a job fo IPsec tunnels. OpenVPN could also do the job. NetBSD can do it too. Easily achieved with Cisco hardware read that enterprise class but can't swear to it via PfSense. PfSense will do a few flavors of VPN, but I've never tried to get it working with any sort of logic to flag which traffic should bring the tunnel up and which should go out unencrypted. Cisco devices have a feature called VTI - virtual tunnel interface.

Then you just set up your routing rules. Policy-based routing will allow you make decisions based on the source IP. They both have OpenVPN built in, so use that. Then you have a NAS for centralized backups because if you're managing remotely you want to make sure they're stuff is backed up, right?

Win win situation. If you get creative, you can even cross-replicate the NAS's so you have a true offsite backup. First, as others have mentioned here you can use TeamViewer to do remote desktop support, and it's free. No need to upgrade to Windows 7 Ultimate or anything else for that matter.

I've supported family and friends I don't do that job any more,. It's Cox. Top tier used to be soft-capped at Gigs which my household alone was pegging every month until they decided to raise all their caps. Now it's a 2TB cap that we barely use a quarter of. I agree that the MicroTik routers are powerful. I have been using one for several years. My biggest complaint with it is the confusing documentation or documentation that's out of date.

I had a hard time figuring out things like traffic management QoS and shaping though now that it's working it's quite powerful. I also have had a lot of confusion on how to set up the firewall so I can VPN in with various operating systems.

If he's going to be using my or my Parents' network resources and the government says I'm responsible for what he does until he's 18, you bet your ass I'm going to do checks to make sure he isn't doing anything that will warrant a visit from the Feds. Beyond that, he has a pretty good amount of freedom and leeway on the web. Windows Remote Assistance was working for a.

It takes less than a minute. Get new users downloading your project releases today. I have no problem with how to build three or four separate networks in each location and make them route over the internet. My weakness is in trying to setup a VPN for a secured two-way connection between location A and location B, both mixed OS environments, with the requirement that all of the internet traffic on B gets routed through A first.

I have no problem with how to build three or four separate networks in each location and make them route over the internet. My weakness is in trying to setup a VPN for a secured two-way connection between location A and location B, both mixed OS environments, with the requirement that all of the internet traffic on B gets routed through A first. I've already looked at some boxed solutions, such as LogMeIn Hamachi, but there hasn't been much in the way of mixed environment support.

Re: Score: 2. Instead of 2 cheap routers, I would use pfsense. It will do everything he is asking for. It will do captive portal, so I can cap bandwidth per user or device. It will give him logs and show per device usage. If he configures it, he can filter with several different plug-ins. It will also act as an openvpn client or server. I've done pfsense and routerOS, pfsense is way easier and the documentation is clearer. If you do it right, with an embedded box, electricity is a wash.

If you throw it on a virtual server you are already running, you probably come out ahead. If you're after filtering rather than tracking, OpenDNS has worked well for me in the past, can be installed on the router at location B, and has built-in filtering categories. Also, it's free but you'll need to make an account to use the filtering. I concur on TeamViewer. I use it to support several hundred clients and it's very reliable, as long as your parents don't close it or uninstall it because they don't know what it is.

Share twitter facebook. Once all is set up, it's easy to maintain. Agree completely, I did the exact same thing with my parents home network: was going to set up OpenVPN for my parents home network for exactly the same reason as the OP - found OpenSSH was more than sufficient via tunneling and ssh keypairs, works with everything and the only requirements are having a router that can do port-forwarding to an alternate not default ssh port, your choice of dynamic dns and whatever old desktop or r-pi as a linux server to do the ssh-server and local logging.

My only wish i. Openvpn Score: 4 , Informative. Bennett writes: on Tuesday July 14, PM Re: Score: 3. Understanding the requirements is the hard part. I second this recommendation. I use OpenVPN for this purpose as well. Associate of Science in Networking Score: 2. If he can't figure out how to set up VPN in an mixed environment, he should go back to school to get his bachelor's degree. A BS in networking is always valuable, especially in doing consultant work. No amount of college coursework will fix someone being too lazy to use Google.

Or Amazon. There were Linksys models in doing that for less than bucks in money.. They suffered from stability problems due to insentient power supply bricks - some were 6 volts, some were 9, 12, or 19 volts. What I would do these days is get a good router tha. Use openVPN and call it done. Something like pfsense supports logging and all sorts of filtering. Re:Associate of Science in Networking Score: 5 , Insightful.

Cisco had wonderful IPsec support in If you had access to it, you can't complain. First thing I was wondering about is what constitutes a "significant amount of training as network administrator" if you have to ask a question like this. Or is an AAS so basic they don't even teach portforwarding has an option to use alternative ports?

I agree - site to site VPN at the router level seems ideal for this challenge. Mikrotik has cheap ones too, that work great. Comment removed based on user account deletion. I always counsel people to stay away from SOHO equipment.

It's not worth the hassle when you can get mikrotik, ubiquiti, or pfsense for the same or less. If you do go with a big name consumer router, at least make sure it supports openwrt. OpenVPN Score: 2. TeamViewer or LogMeIn? Just my 2c worth. If your goal is to make things simple, this isn't Score: 2. Have you tried TeamViewer?

Score: 3. For your main goal of being able to log into your parents' machines, have you tried TeamViewer? Score: 1. Everything else is routing tables. Man, what a trip down memory lane. Easiest solution for your son: plug directly into the modem while you're not there Not quite so easy. You are assuming he won't be able to get past your security without you noticing, which judging by your "Ask Slashdot" question, seems a poor assumption.

My money is on him getting past your security and you not even realising. I'm not super-network talented, but I recently used two Mikrotik RBs to set up a permanent VPN tunnel between two houses for much the same reason. I didn't need the additional routing to make all traffic send through point A, but I know we use that setup at work for our remote workers.

My arrangement ended up being traffic from each house going out it's own connection, but with a permanent IPSEC tunnel between the two for server synchronization and tech support purposes. The Mikrotiks are fantastic lit. Personally I used a small fanless box f.

AutoSSH Score: 3. I use NeoRouter for that Score: 2. They have a free beer version that I used for a couple of year. I'm on the paid version now. I have a similar situation for remote access, but my parents are 12 hours away. IPv6 Score: 3. PFsense could do all of what you want Score: 1.

Using a PFsense with multiple nics you could set up numerous networks and control routing between the networks at that point. Also pfsense can fully intergrate openvpn into the Scheme and has a firewall and filtering to be able to tell where everyone in the network is going. It also allows for port forwarding for you Linux box.

OpenVPN Score: 1. Alternative remote desktop solution Score: 4 , Interesting. Seriously: I would look at it once Having Chrome always running might sound like a great idea until you NEED it, but unless it also works on Chrome Desktop ie: Chrome books, Chrome Boxes, etc it is of questionable use for supporting grandpa and 8yr old Susie.

Keep it simple Score: 2. If I understand you correctly your goals are: 1 To have remote access to machines Linux, Windows, others in few remote networks. I assume you don't have kids. Or work in security, for that matter. Hardware VPN device Score: 2. You could do all of this through software openVPN, etc. I'm getting too old for this crap and just need something that works in the least amount of time and effort required.

Yes, there is an annual cost for support on the device. I'm actually not sure what functionality is lost without maintenance, but I assume it's like most of their other products in that you stop receiving updates but it continues working fine with the last installed version. Is VPN the right solution or is it overkill Softether Score: 1.

Setup a server in the cloud - DigitalOcean is a cheap and excellent host - with Softether. Setup another softether client in your household on an old machine and set the two to do a site-to-site. From the digital ocean installation, ensure that the gateway is whatever you like to be another VPN to work, perhaps? Simplest to maintain Score: 1. Wrong solution Score: 2. Two ways There are two ways of doing this. Networking ? You can pay a couple hundred bucks for a pre-built solution, or you can build a pair of OpenBSD routers to do the job.

You can either use a pair of old machines that you've been too lazy to send for recycling, or you can buy a pair of Raspberry PIs with a second USB ethernet connector, for a low power solution. VPN them together, and set the default route for the router at network 'A" to be through network 'B'. Problem solved. Site to Site VPN? Come on this isn't even a hard one Score: 2. You need two raspberry PI2B computers, dynamic dns, and openvpn.

Beauty is.. I use this to do exactly what you're wanting to do. Works perfectly and it easy to manage. This stuff works great in a SOHO environment. Doesn't scale well, though. Get a NAS THEIR, not they're. Stupid autocorrect. You're Overthinking Score: 2. I know this is old now, but honestly you're overthinking this. Re: Score: 2 , Informative. The bastards have very misleading advertising -- their tv advertisements say things like connect your mobile devices to DSL at home to "Save on Mobile Data" Not as good as the Paid for stuff.

I also use LogmeIn for general purposes, and I stongly recomend to use join. Here is my exhaustive additional list of remote control and presentation software in lieu of TeamViewer:. Google www. Citrix www. Microsoft www. I go into setup and assign the password on the client end instead of having TeamViewer randomly generate one. We are working with UltraVNC. We have the Free Version. Working Fine but still have some issue on Win7!

This topic has been locked by an administrator and is no longer open for commenting. To continue this discussion, please ask a new question. I know that's very general, but I've been having a relatively hard time finding any IT related job that isn't basic help desk level one things. I work in a fairly high level position doing mostly EDI and Salesforce maintenance. I am very willing to work h Do you guys think that the definition of "Entry Level" has been lost to these recruiters?

I mean I have seen some job postings asking for crazy requirements and I was under the impression that entry-level was a job for people with little to no experience Today I get to announce the new Spiceworks virtual community, coming to our community soon. The hallway will be lined with doors, each corresponding to the communi Your daily dose of tech news, in brief.

You need to hear this. Windows 11 growth at a standstill amid stringent hardware requirements By now if you haven't upgraded to Windows 11, it's likely you may be waiting awhile. Adoption of the new O What is a Spicy Sock Puppet? Originally, a Spicy Sock Puppet was used as an undercover identity during online fraudulent activities.

You could pretend to be a fictitious character and no one would ever know. Now, to make Online Events. Log in Join. Posted by Brian Thorp Solved. General Windows. Brian Thorp. Kendall This person is a verified professional. Verify your account to enable IT peers to see that you are a professional. You could try Gencontrol, its free and works well.

I have use Mikogo. New contributor poblano. OP Brian Thorp. Have you tried Dameware? Its a great admin tool, it will let you do anything remotely flag Report. Air Jimi. Paul J. Carmen This person is a verified professional. Robert This person is a verified professional. Robert, I think that join. Kendall wrote: Robert, I think that join. I use LogMeIn for my family and friends - free version. RealVNC has a free version I think. I use Dameware and love it.

CE Harden This person is a verified professional. Kendall Do you have issues with join.

We then hide our application while the viewer application is running and, after it exits, we perform any necessary cleanup on the tunnels. So, these new security options for VNC sound great, but you aren't sure how to configure your server for them? Well, thankfully, it's pretty easy. First, you have to decide which protocol you want to tunnel your VNC data through.

Personally, I prefer SSH because you get authentication for free on a Windows machine because of the fact that, when providing a username and password, it hooks into the NT authentication framework. There's an excellent guide on Cygwin sshd setup here. Once you have Stunnel installed, you can add an entry to the stunnel. This tells Stunnel to listen on port the :0 display port for VNC and forward data it receives to port You'll then have to configure the VNC server to listen on port Once the tunnel configuration is done, all that remains is to set a few configuration options for the VNC server.

These instructions are for TightVNC, which is the implementation that I use, but they should be fairly similar for other implementations. First, double-click the VNC icon in your system tray, and then click the "Advanced" button. Check the "Allow loopback connections" checkbox and the "Allow only loopback connections" checkbox. This ensures that VNC can now only be accessed by a process running on the local machine i.

Once this configuration is done, open the necessary ports in your firewall and give it a shot! Sign in Email. Forgot your password? Search within: Articles Quick Answers Messages. Tagged as. Stats Secure VNC Viewer. Luke Stratman Rate me:. Please Sign up or sign in to vote. Download application - KB Download source code - KB Introduction While VNC is a great, cross-platform remote desktop protocol, it is inherently insecure, and relies on the system administrator that installs it to tunnel it through another secure communication protocol if the VNC server is to be publicly accessible.

Background You might be wondering, why bother with VNC? Implementation details Configuration One of my favorite improvements in. For example: XML. Copy Code. Luke Stratman. I'm a software architect in the truest sense of the word: I love writing code, designing systems, and solving tough problems in elegant ways. I got into this industry not for the money, but because I honestly can't imagine myself doing anything else.

NET 1. I've made a name for myself and have risen to my current position by being able to visualize and code complex systems, all while keeping the code performant and extensible. Both inside and outside of work, I love researching new technologies and using them sensibly to solve problems, not simply trying to force the newest square peg into the round hole. From emerging Microsoft projects like AppFabric to third party or open source efforts like MongoDB, nServiceBus, or ZeroMQ, I'm constantly trying to find the next technology that can eliminate single points of failure or help scale my data tier.

Outside of work, I'm a rabid DC sports fan and I love the outdoors, especially when I get a chance to hike or kayak. Member 8-Jun Net Nut Aug Luke Stratman Aug Rob Achmann Aug Luke Stratman Jun Luke Stratman 1-Apr Luke Stratman 7-Feb Go to top. Layout: fixed fluid. United States.

First Prev Next. My vote of 4 Member 8-Jun Member Thanks for sharing. I must be missing something Net Nut Aug How do I specify that the ssh port is not the standard 22 but some other random number as well as the internal host and vnc port it seems whatever host I put at extenalhost. Net Nut. Re: I must be missing something Luke Stratman Aug Unfortunately the application doesn't handle this by default, but it's easy enough to add that functionality.

I'd admit the tool is cool. But what if I want to use it cross Internet like access my home pc from office, where the secure is really needed. So to be faster, the VNC packets do not really need to encrypt again. Great library! My SSH server requires a certificate, which I have installed. I would imagine I have to supply it like: session. SetPassword myPasswordString ; But as I watch the connection attempt unfold it looks like it wants to start with a 'method' of keyboard-interactive code in session.

GaltSalt maker of. Net thingys. I'm using Visual Studio 6. I've been reading about the. My goal: I'm working on a project using tighvnc code and would like to add the SSH connection code to provide the secure connection. I've got a working vnc server program but I'm having problems incorporating code from the securevnc package.

Any Tips? Thanks In Advance. Sorry, this is a Visual Studio project, so you won't be able to open it using Visual Studio 6. NET capabilities, so you'll need to upgrade to a more recent version of Visual Studio. Thanks Again!

Why not just use a VPN? I hate to sound stupid, but was wondering I "assume" you're not hanging your home PC on the Internet? You have some router? I personally got tired of having to place inbound port mapping so I could control various hosts at my sites. I have to say though, your code is really nice, and the technique of making it automatically choose an available port, and to use Microsoft's built in SSL function is smart. It's just too bad all the rest of the stuff is external. Great coding!

Also, on Linux the known hosts are kept in. The approach taken here does not allow for that. You start the article by telling us VNC is cross platform, but you leave non Windows users out. For this kind of application, to be cross platform, I recommend Mono and Gtk. It is quite mature. Otherwise, this article is VERY well written and documented.

Great job! Thanks, Vlad. Does this tunneling solution will work with NAT. I doubt that stunnel works with NAT. Is it possible to configure rdp to connect only through the ssl only. If no tool is available is it possible to program it.

Re: rdp connection only through ssh Luke Stratman 1-Apr In principle, it's really no different from what I do here with VNC. Then you just startup a Remote Desktop client instance, point it at localhost:[whatever port STunnel is listening on], and you're off to the races. AFAIK, there's no automated tool to set all of that up for you but you should be able to do it manually with the process outlined above.

Re: rdp connection only through ssh sunhcl1 1-Apr I am sorry for the ambiguos question. Acually in tight VNC there is an option of "Allow only loopback connections". This option makes sure we can connect only through ssl. Direct connection from the remote computer would not be allowed. Can we make sure in rdp too we can connect ONLY through tunnel. I want RDP should be connected only through the tunnel , no user should be able to directly connect to terminal server.

Two examples of this would be Hamachi and Garena. VNC is extremely useful if you need to access your desktop from somewhere else or if you need to access your files securely from another computer. One of the more famous applications of VNC is remote access for support where an IT personnel takes control of the computer to change some settings or to fix a certain problem. Some large companies provide this to their employees as it is a lot faster compared to talking them through the whole procedure or having the IT personnel go to workstation.

VNC can also be used by people who work at home on occasion. With VNC, you can access your work computer and work as if you are right on your desk. VNC utilizes a lot of bandwidth because it constantly sends updates of how the screen appears. If you want to utilize VNC over the internet, you would need to have high speed internet connections at both locations. You would also need to configure things properly, including the router and firewalls, in order to let the connection through.

Having a functional VPN in place makes the whole process a lot easier as it removes the additional steps that needs to be taken in order to ensure that the connection is accepted as it should be. Summary: 1. VPN is a method of creating a private network on top of a larger public network while VNC is software that allows one user on a computer to control another computer over Ethernet 2. Cite APA 7 , l. Difference Between Similar Terms and Objects. MLA 8 , lanceben. Thank you for this very good explanation.

Name required.

