Stage 5 of 6 · Lab · about 15 minutes
Remote desktop
SSH gives you the Pi's terminal from anywhere. VNC gives you its whole desktop: screen, mouse and keyboard over the network. You already opened its door in the firewall; now turn the service on and connect.
SSH or VNC: pick the right tool
SSH · the default
- Terminal work: files, apt, git, running programs
- Fast on any network, works headless
- Copy files with
scp - Everything this course grades can be shown in it
VNC · when you need pixels
- Graphical apps: browser on the Pi, Thonny from Week 4
- Watching a desktop while a program draws windows
- Working without a spare monitor at home
- Slower and heavier; not for quick commands
How a remote desktop works
VNC speaks a simple, honest protocol called RFB, remote framebuffer: the server sends the screen's pixels to the viewer, and the viewer sends your keystrokes and mouse events back. That is the whole trick, and it explains the trade-offs you feel:
- It is heavier than SSH. A terminal session moves a few characters; a desktop moves compressed screen regions continuously. On a slow network the desktop lags while SSH stays instant.
- It is universal. Because only pixels and input travel, any RFB viewer can talk to any RFB server. RealVNC Viewer is on the lab image; TigerVNC is a solid open-source alternative if you prefer one at home.
- It shares a real screen. The server mirrors an actual session rather than inventing a second one, which is why viewer and monitor show the same thing.
One version note worth knowing, because it invalidates many tutorials: the Raspberry Pi OS desktop moved from the X11 display system to Wayland, and with it the built-in VNC server became wayvnc (previously it was RealVNC's own server). The raspi-config switch is unchanged, and RealVNC Viewer still connects; only the machinery underneath is different. Details and alternatives: the official remote access documentation; the server itself lives at wayvnc on GitHub.
Turn VNC on
On the Pi, exactly as in Week 2's raspi-config tour:
$ sudo raspi-config # Interface Options → VNC → Yes → Finish
Or the desktop route: Menu → Preferences → Raspberry Pi Configuration → Interfaces → VNC. Either way the service starts now and at every boot. Confirm it is listening:
$ ss -tlnp | grep 5900
LISTEN 0 128 *:5900 *:* users:(("wayvnc",...))
Connect from the lab PC
-
Get the viewer
Install RealVNC Viewer on the lab PC; the portable version runs without installation. Any VNC viewer works; this one is on the lab image.
-
Connect by hostname
Enter
lastname-pi.local(your hostname). Accept the identity check the first time; it is the VNC equivalent of SSH's fingerprint question. Log in with your Pi username and password. -
Prove it
Move a window, open the Pi's file manager, then close the viewer. Closing the viewer disconnects you; the Pi keeps running. Take the screenshot for the hand-in while connected.
VNC shares the real screen
The current server mirrors the Pi's actual session: what you do in the viewer happens on the Pi's monitor too, and someone at the Pi's keyboard shares control with you. One driver at a time within your pair.
Full reference, including other viewers and options: the official remote access documentation.
Headless resolution
With no monitor connected (typical at home), the desktop needs to be told what size to draw:
$ sudo raspi-config # Display Options → VNC Resolution → 1280x720 (or your screen) → reboot
Symptom that this is missing: the viewer connects but shows a tiny or black desktop. In the lab, with a monitor attached, you never need it.
Old instructions to ignore
VNC tutorials age badly because the server changed. If you see any of these, you are reading something out of date:
- "Enable VNC, then sign in to a RealVNC account." The old RealVNC server offered cloud connections. The current wayvnc setup needs no account of any kind; you connect directly by hostname.
- "Run
vncserver-x11" or "installx11vncortightvncserver." X11-era servers. On the current Wayland desktop the built-in wayvnc, toggled in raspi-config, is the supported path. - "Edit config files to set the VNC password." Log in with your Pi account credentials; there is no separate VNC password to configure here.
- Port numbers like 5901, 5902. Those belong to multi-session X11 setups. The mirrored desktop answers on 5900, the port you allowed in UFW.
No network at home?
The USB gadget-mode fallback from Week 2 still applies on the Pi 4: the Pi pretends to be a network device over one USB cable, and SSH or VNC run over that private link. Setup notes: gadget mode (M. Paquette). Do this at home only; in the lab the class network is simpler.
Checklist for this stage
Check yourself
The viewer says "connection refused". Firewall page in hand, what are the two hypotheses, and which command decides?
ss -tlnp | grep 5900: no listener means enable VNC in raspi-config; a listener means check sudo ufw status for the 5900/tcp rule.