Cannot connect to WInXP box with UltraVNC

Peter Coulter peter "at"
Sun Mar 7 15:00:01 2004


Thanks for the reply.

I can see where you are coming from and I will give it a try (and report

Yes, GoToMyVNC shows the attempts reach my VNC server on my home network
(behind the Netgear router and NIS 2003 Personal Firewall), and something
bad happens after that. But I get the password screen back on the initiating
PC (on the office network) so traffic gets out from my NIS SW firewall, and
my Netgear router to the originating PC (in the office) to post the password
screen (so something's working!). The password is entered and it is after
that that things go awry. The question is where and why.

I have to take issue with the statement "Aren't the software firewalls just
doing their job?". The answer there is only a qualified Yes. 
Yes the SW firewall is blocking things, but I have configured it to allow
some traffic, and in this case UltraVNC traffic, to pass. So, in my view,
the SW firewall is not doing its job to the fullest extent it should. 

As I see it this could be failing for one of four reasons.

1. The NIS SW firewall is not configured correctly.
NIS is set in Program Control to allow WinVNC.exe full access (in both
Under Advanced / General Rules a rule is specifically set for VNC to allow
TCP/UDP traffic to pass on the ports 5500, 5800 and 5900 in both directions.

So unless UltraVNC is using some other port(s) I am unaware of then as far
as I am concerned NIS is configured correctly (in terms of ports). Input
from anyone on that would be appreciated. 
Currently I also restrict this rule to allow traffic only from the office
sub-net and its proxy server IP addresses, and this could potentially be the
issue if for some reason the incoming (to my home network) IP address is not
in these ranges. But I am pretty sure of these addresses, however I will
tinker with that too.

2. UltraVNS and NIS 2003 are incompatible
I have seen some reports about this and wonder if anyone can confirm.

3. It could be the HW firewall (Netgear router) is the problem. But on the
other hand I have also configured the Netgear to allow all traffic on the
ports identified above to pass in both directions. And the results from
GoToMyVNC seem to show it is operating as expected/required.

4. There is finally the corporate firewall - and obviously I have no control
over that. 
I think one of the key points in my original posting is that the office PC
behind the corporate firewall(s) gives no response to GoToMyVNC. But in this
case I would have thought that using the JM, via IE internet browser, would
have worked; but it didn't and I am puzzled about that. 

In conclusion: 
I am loath to disable the NIS SW firewall. My primary use for the SW
firewall is to block unwanted outgoing traffic from my LAN. The HW firewall
stops unwanted incoming traffic and the SW catches unwanted outbound stuff.
This arrangement has saved my network a couple of times after the kids
unintentionally, or unwittingly (Kazaa I spit upon you!), have downloaded
stuff that has promptly starting making unwanted outgoing connections.

In fact I will not accept - as a long term solution - disabling the SW
firewall just for the wants of a single application; that is much too high a
risk solution. It (NIS) works for other applications; I have no trouble, for
example, running GotoMyPC by appropriate configuration of the HW and SW

So I am still hoping for a solution that allows me to use both HW and SW
firewalls with UltraVNC. 

BTW: what are "AuthHosts settings in your VNC Servers"?


Peter Coulter

