17
If you need to change the VNC port number
If you change the VNC port to anything other than 5900, then each VNC viewer
user will need to specify the port address as well as the IP address. For instance,
if you set the VNC port to ‘11590’ and the IP address is ‘192.168.47.10’ then
VNC viewer users will need to enter:
192.168.47.10
::
11590
(Note the double colons that separate the IP address and port number).
The firewall/router would also need to be informed to transfer all traffic to the
new port number through to the AdderView CATxIP 5000.
Addressing
When the AdderView CATxIP 5000 is situated within the local network, you
will need to give it an appropriate local IP address, IP network mask and default
gateway. This is achieved most easily using the DHCP server option which
will apply these details automatically. If a DHCP server is not available on the
network, then these details need to be applied manually in accordance with the
network administrator.
The firewall/router must then be informed to route incoming requests to port
5900 or port 80 (if available) through to the local address being used by the
AdderView CATxIP 5000.
To discover a DHCP-allocated IP address
Once a DHCP server has allocated an IP address, you will need to know it in
order to access the AdderView CATxIP 5000 via a network connection. To
discover the allocated IP address:
1 In network section of either the
local configuration menus
or the
global
configuration pages
, set the ‘Use DHCP’ option to ‘Yes’ and select ‘Save’.
Once the page is saved, the AdderView CATxIP 5000 will contact the DHCP
server and obtain a new address.
2 Re-enter the same ‘Network configuration’ screen where the new IP address
and network mask should be displayed.
DNS addressing
As with any other network device, you can arrange for your AdderView CATxIP
5000 to be accessible using a name, rather than an IP address. This can be
achieved in two main ways:
• For small networks that do not have a DNS (Domain Name System) server,
edit the ‘hosts’ files on the appropriate remote systems. Using the hosts file,
you can manually link the AdderView CATxIP 5000 address to the required
name.
• For larger networks, declare the IP address and required name to the DNS
server of your local network.
Placing AdderView CATxIP 5000 alongside the firewall
The AdderView CATxIP 5000 is built from the ground-up to be secure. It
employs a sophisticated 128bit public/private key system that has been
rigorously analysed and found to be highly secure. Therefore, you can position
the AdderView CATxIP 5000 alongside the firewall and control hosts that are
also IP connected within the local network.
IMPORTANT: If you make the AdderView CATxIP 5000 accessible from the public
Internet, care should be taken to ensure that the maximum security available
is activated. You are strongly advised to enable encryption and use a strong
password. Security may be further improved by restricting client IP addresses,
using a non-standard port number for access.
Ensuring sufficient security
The security capabilities offered by the AdderView CATxIP 5000 are only
truly effective when they are correctly used. An open or weak password or
unencrypted link can cause security loopholes and opportunities for potential
intruders. For network links in general and direct Internet connections in
particular, you should carefully consider and implement the following:
• Ensure that encryption is enabled.
By
local configuration menu
or
global configuration page
.
• Ensure that you have selected secure passwords with at least 8 characters
and a mixture of upper and lower case and numeric characters.
By
global configuration page
.
• Reserve the admin password for administration use only and use a non-
admin user profile for day-to-day access.
• Use the latest Secure VNC viewer (this has more in-built security than is
available with the Java viewer). To
download the viewer
.
• Use non-standard
port numbers
.
• Restrict the range of IP addresses that are allowed to access the AdderView
CATxIP 5000 to only those that you will need to use. To
restrict IP access
.
• Do NOT Force VNC protocol 3.3.
• Ensure that the computer accessing the AdderView CATxIP 5000 is clean
of viruses and spyware and has up-to-date firewall and anti-virus software
loaded that is appropriately configured.
• Avoid accessing the AdderView CATxIP 5000 from public computers.
Security can be further improved by using the following suggestions:
• Place the AdderView CATxIP 5000 behind a firewall and use the port
numbers to route the VNC network traffic to an internal IP address.
• Review the activity log from time to time to check for unauthorised use.
• Lock your server consoles after they have been used.