Intransparent VNC implementation – the VM can be reached even without a NIC

Thanks for the clarifying answer!

So, a VNC server can be accessed via TCP/IP.
It is ‘hardwired’ to the instance’s own VGA, keyboard, and mouse.
Therefore, depending on the network layout, if an instance is compromised, the host should still be safe.
Is this correct?


How can I limit access to the VNC server in a multi-NIC scenario?
Is this only achieved by assigning an IP address to the NIC (Bridge, VLAN or Hardware) that will be used for VNC administration?
Is there any chance that users in a different VLAN to the administration VLAN could accidentally gain access to VNC?

Check out Network Configuration for New Instances in TrueNAS SCALE 25.04 Fangtooth - #15 by PackElend for an explanation of what I mean by a multi-NIC scenario.