How to restrict unauthorized access to my HTML5 VM console in Virtualization Station?
Applicable Products
Virtualization Station
Scenario
Virtualization Station uses the Virtual Network Computing (VNC) protocol for HTML5 console access to virtual machines (VMs). To enhance VM security, the application provides a feature named Restrict VM console access. When enabled, it restricts unauthorized external VNC connections, ensuring console access only through authorized Virtualization Station user accounts via HTML5 VNC.
VM Console Access on Virtualization Station Versions
- Virtualization Station 3.4.4 and later: You might have VMs created before version 3.4.4 that lack the default VNC protection provided by the VM console access restriction feature.
- Virtualization Station 3.3.64 and earlier: All VMs in this environment do not have the VM console access restriction feature enabled by default.
To strengthen VM security, it's highly recommended to manually enable the Restrict VM console access for all VMs, particularly those created or upgraded as mentioned above.
Upcoming Version Updates
Forthcoming Virtualization Station updates from QNAP enforces the Restrict VM console access setting for all VMs by default, regardless of the prior configuration.
Procedure
To restrict access to the VM console, configure the below settings.
- Open Virtualization Station.
- Go to Virtual Machines.
- Select a VM.
- Click Edit.
The General window opens. - Click Others.
- Locate the VM console access setting.
- Enable Restrict VM console access.
- Optional: Assign a VNC password for the VM to remove remote control access.
- Click Apply.
Virtualization Station saves the settings.