Restrict access to VNC ports 5900 through 6050 in ZStack Cloud
Applicable scenario
- Product:
ZCF - Component:
Cloud - Versions:
4.8.x, 4.6.x - Operating system:
H84r - Deployment topology: dual management nodes
- Trigger: After a server hosts more than
100VMs, VNC ports increase from5900, with exposure extending beyond6000; range blocking and whitelist hardening are required.
Symptoms
- VNC ports increase from
5900with the VM count. - The range to restrict is:
5900 ~ 6050
- Customer access addresses
172.16.xmust be retained, and all relevant cluster nodes must also be allowed.
Determination method
Sign in to view the rest of this article, plus more troubleshooting and solution know-how.
Sign in