How to Connect to Your VPS with VNC
A complete guide to using VNC for graphical access to your VPS — the right tool when SSH isn't enough, when the network is broken, or when you need to watch the boot screen.
SSH is the everyday workhorse for managing a VPS, but it's text-only. When you need to see a graphical login screen, fix a misconfigured firewall that has locked SSH out, watch the OS boot, or use a Windows desktop, you reach for VNC. This article covers how VNC works, when to use it, how to connect from your laptop, and how to lock it down so you're not handing the keys to the internet.
What VNC actually is
VNC (Virtual Network Computing) is a screen-sharing protocol. A small server runs on the VPS and streams its display to a viewer on your computer; your keyboard and mouse events go back the other way. The protocol is called RFC — Remote Framebuffer — and the default port is 5900 for display :0, 5901 for :1, and so on.
Two flavours show up on a VPS:
- Out-of-band VNC — provided by us through the client area. It connects to the virtual console of the hypervisor, so it works even when the OS is broken, the firewall is wrong, or the network is down. Use this for rescue scenarios.
- In-OS VNC — you install a VNC server inside the OS to expose a desktop session. Use this for day-to-day graphical work, for Windows servers without RDP, or for shared GUI workflows.
Pick a VNC client
Any RFB-compatible client works. Three reliable options:
| Client | Platforms | Best for |
|---|---|---|
| TigerVNC Viewer | Windows, macOS, Linux | Free, fast, no account — recommended default. |
| RealVNC Viewer | Windows, macOS, Linux, iOS, Android | Mobile clients are excellent. |
| Remmina | Linux | Unified manager for VNC + RDP + SSH connections. |
1Connect through the client area (out-of-band)
This is the path for rescue work. Nothing has to be installed on the VPS — you're talking directly to the hypervisor's virtual console.
- Sign in to your client area.
- Open My Services and pick the VPS.
- Click VNC Console (or noVNC) in the action sidebar.
- A browser-based viewer opens immediately, or the panel shows you the host, port, and one-time password for an external VNC client.
When to use this method
SSH is broken, the firewall rejects you, the OS won't boot, or you want to watch the boot menu and choose a recovery kernel. The client-area console works in all of these scenarios because it bypasses the guest OS entirely.
2Install a VNC server inside Linux (in-OS)
For a usable graphical desktop, run TigerVNC on the VPS. We'll install a lightweight desktop (XFCE) and bind VNC to localhost only — you'll tunnel through SSH for security.
# Debian / Ubuntu sudo apt update sudo apt install -y xfce4 xfce4-goodies tigervnc-standalone-server tigervnc-common # AlmaLinux / Rocky sudo dnf groupinstall -y "Xfce" "base-x" sudo dnf install -y tigervnc-server # As your normal user (not root), set a VNC password vncpasswd
Now create a per-user systemd unit so VNC starts cleanly on boot and ties its session to the right user.
#!/bin/sh unset SESSION_MANAGER unset DBUS_SESSION_BUS_ADDRESS exec startxfce4
chmod +x ~/.vnc/xstartup # Bind to localhost only — never expose 5901 to the internet directly vncserver :1 -localhost yes -geometry 1920x1080 -depth 24 # Confirm it's listening only on 127.0.0.1 ss -tlnp | grep 590
3Connect from your laptop over an SSH tunnel
Because we bound VNC to localhost, the only way to reach it is through an SSH tunnel. This is exactly what you want — the VNC traffic rides inside SSH's encryption, and there's no extra firewall port to open.
# From your LOCAL machine — forward local 5901 to the VPS's 127.0.0.1:5901 ssh -N -L 5901:127.0.0.1:5901 [email protected] # Leave that terminal open. In your VNC viewer, connect to: # localhost:5901 # Enter the VNC password you set with vncpasswd.
4Windows Server VPS — use built-in RDP instead
On Windows, RDP (Remote Desktop) is faster, more secure, and already installed. Use VNC only for the out-of-band console (step 1) when RDP isn't reachable. For day-to-day access:
- In your client area, find the Administrator password.
- From Windows or macOS, open Microsoft Remote Desktop.
- Add the VPS IP, the username
Administrator, and the password. - Connect on port
3389(open it in the Windows firewall first, restricted to your office IP).
5Troubleshooting the black screen
A frequent first-time issue: you connect, authenticate, and see a black or grey desktop. The culprit is almost always a missing or broken ~/.vnc/xstartup. Check three things:
- The file exists and is executable (
chmod +x ~/.vnc/xstartup). - The last line launches a desktop (
exec startxfce4or similar). - The desktop is actually installed (run
which startxfce4— if it prints nothing, install it).
Check the log if it still misbehaves: ~/.vnc/<hostname>:1.log usually points straight at the problem.
6End the session cleanly
VNC sessions persist until you stop them, so they keep running even after you disconnect the viewer. Stop the display when you're done:
# List running displays vncserver -list # Stop display :1 vncserver -kill :1
Security checklist before you finish
VNC has a long history of weak default passwords and unencrypted sessions. Three rules keep you safe:
- Never expose
5900–5910to the internet. Always bind to127.0.0.1and tunnel through SSH. - Use a strong VNC password — minimum 12 characters, randomly generated. The legacy VNC password is only 8 chars; pair it with the SSH tunnel for real security.
- Stop the server when you're done. A running but unused VNC display is a wide-open authenticated session waiting to be hijacked if the box is ever compromised.
Frequently asked questions
Do I need to install anything on the VPS to use the client-area console?
VNC vs. RDP vs. SSH — which one should I use?
Is VNC encrypted by default?
Can your team set this up for me?
Need graphical access on a new VPS?
Every plan includes a browser-based VNC console out of the box — no extra setup required.
Deploy a VPS Open a Ticket