Raspberry Pi: update it, key it, lock it
420-302-VA · WEEK 3 · FALL 2026

Stage 5 of 6 · Lab · about 15 minutes

Remote desktop

SSH gives you the Pi's terminal from anywhere. VNC gives you its whole desktop: screen, mouse and keyboard over the network. You already opened its door in the firewall; now turn the service on and connect.

SSH or VNC: pick the right tool

SSH · the default

  • Terminal work: files, apt, git, running programs
  • Fast on any network, works headless
  • Copy files with scp
  • Everything this course grades can be shown in it

VNC · when you need pixels

  • Graphical apps: browser on the Pi, Thonny from Week 4
  • Watching a desktop while a program draws windows
  • Working without a spare monitor at home
  • Slower and heavier; not for quick commands
RealVNC Viewer on the lab PC connects over the network to the wayvnc service on the Raspberry Pi, through the firewall's port 5900 rule Lab PCRealVNC Viewer Raspberry Piwayvnc service · port 5900 lastname-pi.local : 5900 through the UFW rule you added on the previous page
One service, one door, one viewer. Current Raspberry Pi OS ships wayvnc as its VNC server; RealVNC Viewer connects to it normally.

How a remote desktop works

VNC speaks a simple, honest protocol called RFB, remote framebuffer: the server sends the screen's pixels to the viewer, and the viewer sends your keystrokes and mouse events back. That is the whole trick, and it explains the trade-offs you feel:

  • It is heavier than SSH. A terminal session moves a few characters; a desktop moves compressed screen regions continuously. On a slow network the desktop lags while SSH stays instant.
  • It is universal. Because only pixels and input travel, any RFB viewer can talk to any RFB server. RealVNC Viewer is on the lab image; TigerVNC is a solid open-source alternative if you prefer one at home.
  • It shares a real screen. The server mirrors an actual session rather than inventing a second one, which is why viewer and monitor show the same thing.

One version note worth knowing, because it invalidates many tutorials: the Raspberry Pi OS desktop moved from the X11 display system to Wayland, and with it the built-in VNC server became wayvnc (previously it was RealVNC's own server). The raspi-config switch is unchanged, and RealVNC Viewer still connects; only the machinery underneath is different. Details and alternatives: the official remote access documentation; the server itself lives at wayvnc on GitHub.

Turn VNC on

On the Pi, exactly as in Week 2's raspi-config tour:

$ sudo raspi-config    # Interface Options → VNC → Yes → Finish

Or the desktop route: Menu → Preferences → Raspberry Pi Configuration → Interfaces → VNC. Either way the service starts now and at every boot. Confirm it is listening:

$ ss -tlnp | grep 5900
LISTEN 0  128  *:5900  *:*  users:(("wayvnc",...))

Connect from the lab PC

  1. Get the viewer

    Install RealVNC Viewer on the lab PC; the portable version runs without installation. Any VNC viewer works; this one is on the lab image.

  2. Connect by hostname

    Enter lastname-pi.local (your hostname). Accept the identity check the first time; it is the VNC equivalent of SSH's fingerprint question. Log in with your Pi username and password.

  3. Prove it

    Move a window, open the Pi's file manager, then close the viewer. Closing the viewer disconnects you; the Pi keeps running. Take the screenshot for the hand-in while connected.

VNC shares the real screen

The current server mirrors the Pi's actual session: what you do in the viewer happens on the Pi's monitor too, and someone at the Pi's keyboard shares control with you. One driver at a time within your pair.

Full reference, including other viewers and options: the official remote access documentation.

Headless resolution

With no monitor connected (typical at home), the desktop needs to be told what size to draw:

$ sudo raspi-config    # Display Options → VNC Resolution → 1280x720 (or your screen) → reboot

Symptom that this is missing: the viewer connects but shows a tiny or black desktop. In the lab, with a monitor attached, you never need it.

Old instructions to ignore

VNC tutorials age badly because the server changed. If you see any of these, you are reading something out of date:

  • "Enable VNC, then sign in to a RealVNC account." The old RealVNC server offered cloud connections. The current wayvnc setup needs no account of any kind; you connect directly by hostname.
  • "Run vncserver-x11" or "install x11vnc or tightvncserver." X11-era servers. On the current Wayland desktop the built-in wayvnc, toggled in raspi-config, is the supported path.
  • "Edit config files to set the VNC password." Log in with your Pi account credentials; there is no separate VNC password to configure here.
  • Port numbers like 5901, 5902. Those belong to multi-session X11 setups. The mirrored desktop answers on 5900, the port you allowed in UFW.

No network at home?

The USB gadget-mode fallback from Week 2 still applies on the Pi 4: the Pi pretends to be a network device over one USB cable, and SSH or VNC run over that private link. Setup notes: gadget mode (M. Paquette). Do this at home only; in the lab the class network is simpler.

Checklist for this stage

Check yourself

The viewer says "connection refused". Firewall page in hand, what are the two hypotheses, and which command decides?
Either the service is not running or the firewall rule is missing. On the Pi, ss -tlnp | grep 5900: no listener means enable VNC in raspi-config; a listener means check sudo ufw status for the 5900/tcp rule.
Which credentials does the VNC login want?
Your Pi account's username and password, the same pair as a desktop login. It is a session login, not related to your SSH key.
You close the viewer window in the middle of an apt upgrade you started in a desktop terminal on the Pi. What happens to the upgrade?
It keeps running. The viewer only mirrors the Pi's session; closing it disconnects your view, it does not end programs on the Pi.
At home with no monitor, VNC shows a black or tiny screen. Fix?
Set a headless resolution: raspi-config → Display Options → VNC Resolution, then reboot. With no display attached the desktop otherwise has no size to draw at.