How to Use Remmina to Connect to a VNC Server on Linux

Install Remmina together with its VNC plugin, make a profile with Remmina VNC Plugin as the protocol and <server-host>:1 in Server, and press Save and Connect. If the server only listens on localhost, which is TigerVNC's default on Debian and Ubuntu, switch on the profile's SSH tunnel and Remmina carries the session over port 22 instead.

The examples use a session on display :1, which listens on TCP 5901. Change the display number to match your server; the host, user and subnet are your own.

How Remmina reaches a VNC server

Remmina handles each protocol through a plugin, VNC and SSH among them, and the VNC one ships as a separate package, remmina-plugin-vnc. Without it, Remmina VNC Plugin never shows up in the protocol list.

The plugin connects to port 5900 plus the display number. Type a number under 100 after the colon in Server and Remmina reads it as a display, so <server-host>:1 and <server-host>:5901 both reach 5901. Leave the number off and you get 5900, which is display :0, not the :1 session in these examples.

Whether you can reach that port is the server's call. On Debian and Ubuntu, tigervncserver listens only on localhost unless you start it with -localhost no or with TLS or X509 security types and no *None type. Upstream's service, the one RHEL and Fedora run, listens on every address unless localhost is set in its config. That leaves you two routes:

  • Direct: the server listens on its network address and the firewall lets your client in.
  • SSH tunnel: the server stays on localhost; Remmina logs in over SSH and forwards the session to 127.0.0.1:5901 on the server.

Take the tunnel unless both machines sit on a network you trust. It works with the server's default, needs no extra firewall rule and keeps the VNC traffic inside SSH. To see which route your server allows, run this on the server:

how remmina reaches a vnc server · bash
ss -tln | grep 5901

If the listening socket shows 127.0.0.1:5901, only the tunnel works. 0.0.0.0:5901 or [::]:5901 means a direct connection works once the firewall allows it, and no line at all means nothing is running on display :1.

Install Remmina with the VNC plugin

A laptop with a terminal window, flanked by two connected package route option cards.

On Ubuntu 24.04 and Debian 13, install from the distribution and name the plugin:

install remmina with the vnc plugin · bash
sudo apt install remmina remmina-plugin-vnc
remmina --full-version

--full-version prints the Remmina version, then a table of every loaded plugin; you want a row that reads Remmina VNC Plugin. If a Remmina window is already open, you get the same list in a window instead.

Name the plugin even though the remmina package recommends it: an install with --no-install-recommends leaves VNC out.

The apt install remmina remmina-plugin-rdp remmina-plugin-secret line on the Remmina site is for the project's PPA. It only works after sudo apt-add-repository ppa:remmina-ppa-team/remmina-next, and it doesn't name the VNC plugin either. Reach for the PPA only when you need a newer release than your distribution ships.

Flatpak, Snap and Fedora: what changes

  • Flatpak: add Flathub if the machine doesn't have it, then install and run the app. Profiles live under ~/.var/app/org.remmina.Remmina/data/remmina/ instead of ~/.local/share/remmina/.
flatpak, snap and fedora: what changes · bash
flatpak remote-add --user --if-not-exists flathub https://flathub.org/repo/flathub.flatpakrepo
flatpak install --user flathub org.remmina.Remmina
flatpak run --user org.remmina.Remmina
  • Snap: sudo snap install remmina. The snap can't read ~/.ssh, so copy the keys the tunnel needs into ~/snap/remmina/common/.ssh/. Saved passwords need sudo snap connect remmina:password-manager-service :password-manager-service.
  • Fedora: sudo dnf install remmina remmina-plugins-vnc. Note the plural in remmina-plugins-vnc.

Save a VNC profile and connect

You save each connection as a profile, and only two fields have to be right: Protocol and Server. In the profile file they're protocol and server.

A labeled process diagram showing five steps to save a VNC profile, highlighting the VNC protocol and Server entries.

  1. Click + in the main window. The profile editor opens.
  2. Give it a Name you'll recognise, and pick Remmina VNC Plugin under Protocol.
  3. Put <server-host>:1 in Server.
  4. Leave User password empty to get a prompt on every connect. If you save it, remmina-plugin-secret keeps it in your keyring and the profile only holds a . placeholder.
  5. On a slow link, set Quality to Poor (fastest). The quality values run from Poor (0) through Medium and Good to Best (9).
  6. Make sure Close on connection failure is unticked for the first run. With it ticked, a failed VNC connection closes without an error and you're left guessing.
  7. Click Save and Connect. Unless you saved a password, the new tab asks for it with an "Enter VNC password" prompt.

For the direct route, the server's firewall has to let your client subnet in. On a server running ufw, open only the VNC port and only for your subnet:

save a vnc profile and connect · bash
sudo ufw allow proto tcp from <subnet> to any port 5901

sudo ufw status should then list 5901/tcp as ALLOW with your subnet in the From column. If it prints Status: inactive instead, UFW is off, and Ubuntu ships it disabled: 5901 is already open to every host, and the rule only takes effect once you allow SSH and run sudo ufw enable.

For a one-off connection without a saved profile, hand -c a VNC URI:

save a vnc profile and connect · bash
remmina -c vnc://<server-host>:1

Add the SSH tunnel to the profile

The tunnel is set on a tab of the same profile, so Server stays <server-host>:1, and the tunnel turns :1 into 5901 the same way before it forwards. Open the SSH Tunnel tab and set:

  • Enable SSH tunnel.
  • Tunnel via loopback address, when the server listens on 127.0.0.1 only. With it ticked, Remmina tunnels to the loopback address, 127.0.0.1:5901 on the SSH host. Without it, the SSH host connects onward to whatever name is in Server, and a localhost-only listener refuses that.
  • Same server at port 22 for the common case, or Custom with <bastion-host>:22 when SSH lands on a different machine.
  • An authentication type and your SSH username. The choices are password, SSH identity file, SSH agent, public key and Kerberos. On the Snap build, pick the identity file from ~/snap/remmina/common/.ssh/, since the snap can't see ~/.ssh.

Saved, the same tunnel looks like this in the profile file, where ssh_tunnel_auth=2 means SSH agent:

add the ssh tunnel to the profile · ini
[remmina]
name=<server-host> display 1
protocol=VNC
server=<server-host>:1
ssh_tunnel_enabled=1
ssh_tunnel_loopback=1
ssh_tunnel_auth=2
ssh_tunnel_username=<user>

When you want SSH's own errors in front of you, forward the port with ssh -L yourself, turn the tunnel tab off, and point Remmina at your local end:

add the ssh tunnel to the profile · bash
ssh -L 5901:localhost:5901 <user>@<server-host>
remmina -c vnc://localhost:1

That first line leaves you at a shell prompt on the server, and the forward lasts as long as that login does, so open another local terminal for the remmina -c line. Keep the built-in tunnel for profiles you reuse; the hand-built one is for debugging, or for when another tool needs the same forward.

Check the session and end it

Remmina opens a tab with the remote desktop. Click into it and type or move the mouse; if the desktop shows but ignores you, View only is on in the profile. To confirm from the server side, list the established connections on 5901:

check the session and end it · bash
ss -tn | grep 5901

A direct session shows your client's address as the peer. A tunnelled one shows 127.0.0.1, because sshd makes the last hop locally.

To end the session, click Disconnect in the toolbar, which closes the tab. To quit Remmina completely, tray icon included:

check the session and end it · bash
remmina -q

When the session won't open

If the tab disappears without an error, Close on connection failure is still ticked; untick it, reconnect, and work down this list in order:

Symptom Cause Fix
Remmina VNC Plugin is missing from Protocol The VNC plugin isn’t installed sudo apt install remmina-plugin-vnc, then remmina -q and start Remmina again
“Unable to connect to VNC server” on a direct connection The server listens on 127.0.0.1 only, or the firewall drops the port Run ss -tln on the server. If 5901 shows as 127.0.0.1:5901, use the SSH tunnel; otherwise open the port with the ufw rule above
Connection refused with a bare host in Server Remmina went to 5900, and the session is on display :1 Set Server to <server-host>:1
SSH login works, then the VNC connection fails Tunnel via loopback address is off, so the SSH host connects to <server-host>:5901 and the localhost-only listener refuses it Tick Tunnel via loopback address
Snap install can’t find your SSH key The snap can’t read ~/.ssh cp ~/.ssh/<key> ~/snap/remmina/common/.ssh/ and select the copy in the profile
Flatpak install can’t use your SSH agent The sandbox doesn’t see the agent socket flatpak run --filesystem=$SSH_AUTH_SOCK --env=SSH_AUTH_SOCK=$SSH_AUTH_SOCK org.remmina.Remmina

Anything else, open Debugging from the main menu, or quit Remmina and start it from a terminal with GLib debug output switched on, then reconnect and read the last lines:

when the session won’t open · bash
remmina -q
G_MESSAGES_PREFIXED=all G_MESSAGES_DEBUG=all remmina

On the Flatpak, swap the final remmina for flatpak run org.remmina.Remmina.

Find, reuse and remove saved profiles

Remmina writes each connection to its own .remmina file with a generated name, in ~/.local/share/remmina/ for the distribution package. If an old ~/.remmina/ directory exists, Remmina goes back to using that one instead. Find a profile by its server:

find, reuse and remove saved profiles · bash
grep -l '^server=<server-host>' ~/.local/share/remmina/*.remmina

Open it straight from a shell, or change a field without the editor with --set-option and --update-profile:

find, reuse and remove saved profiles · bash
remmina -c ~/.local/share/remmina/<profile>.remmina
remmina --set-option server=<server-host>:2 --update-profile ~/.local/share/remmina/<profile>.remmina

To remove a profile, right-click it in the main window and choose Delete, or delete its file. Either way only the local entry goes; nothing changes on the server.

If you opened 5901 in ufw while you tried the direct route and the tunnel profile now connects, take that rule back out with sudo ufw delete allow proto tcp from <subnet> to any port 5901. The tunnel only needs SSH, so the VNC port can stay closed to everything but localhost.

FAQs

Why doesn't the right Ctrl key reach the remote desktop?

Remmina keeps Right Ctrl for itself as its host key, so the VNC server never sees it. Use the left Ctrl in the remote session, or pick another host key in the Keyboard section of Remmina's preferences. Tapped on its own, Right Ctrl grabs or releases the keyboard; held with F or S, it toggles fullscreen or scaling.

Does Remmina offer a profile setting that prevents password storage?

Yes. Tick Forget passwords after use in the VNC profile. In the profile file that's disablepasswordstoring=1, and Remmina asks for the password on every connection.