Knowledge BaseSolutionsRestrict access to VNC ports 5900 through 6050 in ZStack Cloud

Restrict access to VNC ports 5900 through 6050 in ZStack Cloud

SolutionsZCF · CloudVersions4.8.x / 4.6.xArticle IDKB-200092Updated2026-09-16

Applicable scenario

  • Product: ZCF
  • Component: Cloud
  • Versions: 4.8.x, 4.6.x
  • Operating system: H84r
  • Deployment topology: dual management nodes
  • Trigger: After a server hosts more than 100 VMs, VNC ports increase from 5900, with exposure extending beyond 6000; range blocking and whitelist hardening are required.

Symptoms

  • VNC ports increase from 5900 with the VM count.
  • The range to restrict is:
  5900 ~ 6050
  • Customer access addresses 172.16.x must be retained, and all relevant cluster nodes must also be allowed.

Determination method

Sign in to view the rest of this article, plus more troubleshooting and solution know-how.

Restrict access to VNC ports 5900 through 6050 in ZStack Cloud | KB-200092 | ZStack Resource Center