FAQs for On-Prem Management Console (OPC)

Follow

This page answers the most common questions about the RealVNC Connect On-Prem Management Console and its optional On-Prem Zone component. For full setup instructions, see Getting Started with the On-Prem Management Console.

What is the On-Prem Management Console?

The On-Prem Management Console is a core component of RealVNC Connect On-Prem. It gives you a browser-based console for centrally managing an offline (on-premises) deployment of RealVNC Connect. As a self-hosted solution, it needs no internet access to set up or run, so your network stays locked down and your data stays on-site.

From the console, administrators can see account-level information such as licensed device capacity and user numbers, review connection logs for auditing, and access deployment tools including a dedicated licensing panel and download packages.

Who can access the On-Prem Management Console?

The On-Prem Management Console is available with the Enterprise subscription. Access, including testing and adoption, is coordinated through your Account Manager. If you don't see the installer in your RealVNC Connect Portal, please contact your Account Manager for assistance.

Within the console itself, there are two user roles: Administrators, who can access the full console and RealVNC Viewer, and Users, whose access is restricted to the Devices page for Web Viewer connections plus linked RealVNC Viewer use.

What is On-Prem Zone, and do I need it?

On-Prem Zone is an optional component of the On-Prem Management Console for customers with more complex network topologies. Each installed zone acts as a broker for communication between RealVNC Viewer/RealVNC Server and the central On-Prem Management Console, so devices in a zone only need a network path to their zone rather than to the console itself. VNC traffic itself still travels directly between RealVNC Viewer and RealVNC Server - only On-Prem Management Console traffic is routed through the zone.

You only need On-Prem Zone if your network topology requires it. See Getting Started with On-Prem Zone for full setup steps.

What are the system requirements for the On-Prem Management Console?

On-Prem Management Console has the following system requirements.

Operating System

On-Prem Management Console is designed to run on Windows Server 2022 and later.

Software

  • .NET Framework 4.7.2 or later installed
  • Postgres 17
    (installed automatically by the On-Prem Management Console installer)
  • Java Runtime JRE
    (installed automatically by the On-Prem Management Console installer)

Hardware

Requirement Type CPU RAM Disk
Minimum (Dev/Test) 1–2 cores 4 GB 20 GB
Baseline Production 2 cores 8 GB 50–100 GB
Recommended Production 4–8 cores 16–32 GB 50–100 GB

 

How do I install the On-Prem Management Console?

Download the MSI installer from the RealVNC Connect Portal (or ask your Account Manager to provide it manually), then work through the installer: set the domain URL, configure your SSL certificates, choose whether to enable HTTP endpoints, set the HTTPS/HTTP port values, optionally install Coturn for Web Viewer, and set your PostgreSQL administrator credentials.

Before you start, create a DNS entry for the domain your console will use, so RealVNC Viewer and RealVNC Server can reach the console URL. Full step-by-step instructions, including screenshots of every installer screen, are in Getting Started with the On-Prem Management Console.

What is the Join Token used for?

The Join Token is used the first time you configure a RealVNC Server to join your deployed environment. You'll find and can edit it in the Deployment section of the On-Prem Management Console. Once a server is registered, the join token isn't needed again for future updates to that server.

Can I use the RealVNC Connect v8 All-in-one application with the On-Prem Management Console?

No. The RealVNC Connect v8 All-in-one application is not compatible with the On-Prem Management Console. Install RealVNC Viewer and RealVNC Server as separate applications instead. Compatible versions are RealVNC Viewer 7.15.0 and later, RealVNC Connect Viewer 8.3.0 and later, and RealVNC Server 7.15.0 and later.

What SSL certificate do I need for the On-Prem Management Console?

You need a password-protected .p12 file containing the SSL private and public keys in PKCS12 format, plus a root or intermediate certificate from the issuing certificate authority in .PEM format. The .p12 file is used during installation of the console; the .PEM file is then distributed to every RealVNC Viewer and RealVNC Server that connects to the console.

You can reuse an existing internal SSL certificate, purchase one from a recognised provider, or create your own (for example with OpenSSL or Active Directory Certificate Services). Whichever route you choose, keep track of the expiry date - the certificate must be renewed before it expires or the console will stop working correctly. See On-Prem Management Console - Certificate Requirements for the full key and certificate parameters, plus helper scripts for generating a self-signed certificate chain.

Can I generate my own certificates during installation?

Yes. The installer can generate SSL certificates for you as an alternative to providing your own. This is acceptable for testing or small-scale deployments, but we recommend using certificates from a trusted certificate authority or third party for production, as this is more secure. If you use installer-generated certificates, you'll need to register them as a trusted Certificate Authority after installation.

How do I register an installer-generated certificate as trusted?

How you gather the certificate depends on whether your console or zone is using an HTTP endpoint for certificate retrieval:

  • If HTTP is enabled, go to the certificate set-up page at your console's or zone's domain URL plus /certificate-setup (for example, http://managementconsole.com/certificate-setup) to download the certificate and see registration instructions.
  • If HTTP is not enabled, download the certificate from the Deployment page while logged in to the console or zone, then distribute it to the devices that need access.

Once downloaded, register the certificate in the trusted certificate store for the relevant operating system (Windows, macOS, Linux) or browser (Chrome/Edge, Firefox), then restart the browser. Full step-by-step instructions for each OS and browser are in Registering a SSL Certificate as a Trusted Certificate Authority.

Can I create a certificate using Active Directory Certificate Services (ADCS)?

Yes. You duplicate the built-in Webserver template in ADCS, configure it to meet the On-Prem Management Console's certificate requirements (2048-bit key, SHA-256 request hash, Server Authentication and Digital Signature extensions, and so on), publish it on your Certificate Authority, then enrol for and export the certificate as both a .p12 file (with private key) and a .pem file (public certificate only). See Creating a certificate for the On-Prem Management Console with Active Directory Certificate Services (ADCS) for the full walkthrough.

Should I enable HTTP endpoints?

HTTP traffic is not encrypted, which increases exposure to cyberattacks. Only enable HTTP endpoints if you're confident in the security of your internal network. Enabling HTTP endpoints lets the console's SSL certificate be downloaded from an unencrypted endpoint.

What is Active Directory integration, and which version do I need?

Active Directory (AD) integration lets you manage user access to the On-Prem Management Console through your organisation's existing Active Directory, instead of through user accounts added directly to the console. It was introduced in On-Prem Management Console 4.0.0 - you must be running version 4.0.0 or later to use it.

Only a user with the ADMIN role can configure the integration, from the Active Directory tab in the console.

What information do I need before setting up Active Directory integration?

Before you start, make sure LDAPS (LDAP over SSL) is configured in your Active Directory, then have the following to hand:

  • The fully qualified domain names (FQDNs) of your Domain Controller(s).
  • The LDAPS port shared by all Domain Controllers (for example, 636).
  • The username and password for an Active Directory service account - this must be a regular account, not a Managed Service Account.
  • The Base Distinguished Name (DN) for your AD domain.
  • The public key for the certificate authority (CA) that signed your LDAPS SSL certificate(s), in .pem or base64-encoded format.

If you want to narrow the security group search to specific folders, you can also provide a Group Search Base, User Search Base and User ID Attribute - these are optional. If you're unsure of any value, ask your organisation's IT Windows Administrator; the fields are found in Active Directory's Attribute Editor, as described in Integrating Active Directory with the On-Prem Management Console.

What happens to existing local user accounts when I enable Active Directory integration?

Once you select Proceed after a successful connection test, all locally added user accounts (users added via Add User or a bulk upload) are disabled and any active sessions they hold are revoked.

The Super Admin account - the account created when the Management Console is first installed - is not affected by AD integration and keeps its standard credentials login.

Be aware that once you configure the first security group mapped to the ADMIN role, session token revocation is enabled for all active sessions. If you're not logged in as the Super Admin, or the ADMIN security group you configure doesn't include you, your own session may end - if this happens, log back in as the Super Admin or as an admin from the configured security group.

How do I disable or remove the Active Directory integration?

To temporarily stop it, select Disable Integration in the Active Directory tab and confirm. This blocks new logins using Active Directory credentials until you select Enable Integration again.

To remove it completely, open the edit configuration page and select Delete Configuration, then confirm.

Deleting the configuration cannot be undone. It removes all Active Directory details from the Management Console and returns you to the first-time configuration page - you'll need to reconfigure your Active Directory details from scratch to use the integration again.

How do I set up an On-Prem Zone?

  1. Create the zone in the On-Prem Management Console (Zones section > Add a new zone), providing a name, description and access URL. This generates a unique Access Key.
  2. Download the On-Prem Zone MSI installer from the RealVNC Connect Portal.
  3. Run the installer, matching your HTTP/HTTPS configuration to the linked On-Prem Management Console, providing the console's domain details, and setting up SSL certificates for the zone (your own, or installer-generated).
  4. Enter the Access Key generated during zone creation.

Once installed, check the Zones section of the console - your new zone should show as Registered. Full details are in Getting Started with On-Prem Zone.

Do I need different OPCHOST and OPCCERTS values for devices in a zone?

Yes. If your deployment uses On-Prem Zone, configure RealVNC Viewer and RealVNC Server with the OPCHOST and OPCCERTS values of the zone they should register to, not those of the central On-Prem Management Console.

How do I update my On-Prem Management Console to a new version?

If you're on version 2.2.1 or later, download the latest installer from the RealVNC Connect Portal and run it as administrator - it performs an in-place update, showing your current and target version before you confirm. If you're on an older version, follow the uninstall-and-reinstall process in On-Prem Management Console 2.2.X and On-Prem Zone 1.1.X Update Instructions instead.

You'll be asked whether to install Coturn (for Web Viewer) if it isn't already present, then the update runs and the console relaunches automatically using your existing login credentials - no new account or password reset is needed.

How do I renew or update my licence?

In the console's License section, click Import new license key and enter the new licence key, retrieved from the RealVNC Connect Portal or provided manually by RealVNC. This covers both extending the licensed time period and changing the number of provisioned licences.

What usage data is shared with RealVNC at renewal?

From the Usage section, you can click Create Export File to generate an encrypted export for RealVNC as part of the renewal process. This only contains high-level overview data - it doesn't track activity or usage within sessions - and exists to help RealVNC provide the right package at renewal and prevent licence abuse.

Where do I find the OPCHOST, OPCCERTS and ENABLEOPC parameters?

These parameters configure a RealVNC Viewer or RealVNC Server to work with the On-Prem Management Console:

OPCHOST

The URL where RealVNC Viewer or RealVNC Server should find the On-Prem Management Console (or zone). Case-sensitive, and must exactly match the domain name in your SSL certificate. Found in the Deployment section of the console.

OPCCERTS

The location of the certificate RealVNC Viewer or RealVNC Server should use to connect securely to the console. This must point to the .pem root or intermediate certificate, not the .p12 file, and must remain accessible at all times.

ENABLEOPC

Tells RealVNC Viewer or RealVNC Server that they're in a deployed environment and must communicate with the On-Prem Management Console.

For step-by-step deployment commands per platform, see Deploying Viewers and Servers with local certificates.

Why can't RealVNC Viewer or RealVNC Server connect to the On-Prem Management Console?

  • Check that OPCHOST exactly matches the domain name in your SSL certificate - this value is case-sensitive.
  • Check that OPCCERTS points to the .pem certificate file (not the .p12 file), and that the file is accessible from the device at all times.
  • If you're using installer-generated certificates, confirm the certificate has been registered as a trusted Certificate Authority on the device - see Registering a SSL Certificate as a Trusted Certificate Authority.
  • If the device is registered to an On-Prem Zone, check it's using the zone's OPCHOST and OPCCERTS values, not the central console's.
  • If none of the above resolves the issue, contact our Support team.

Can I access devices via the browser?

From On-Prem Management Console 3.0.0, Web Viewer lets you connect to a managed remote device directly from your browser's Devices tab, without opening RealVNC Viewer separately. It requires On-Prem Management Console 3.0.0 or later, RealVNC Server 7.18.0 or later on the remote device, and the Coturn service installed during the console's installation.

From 3.1.0, users with the User role can also launch Web Viewer, in addition to Administrators.

Note: The connect button only appears for devices running RealVNC Server 7.18.0 or later. Check the Server Version column on the Devices page - if it shows an earlier version, update RealVNC Server on that device.

Why does my Web Viewer connection fail or not complete?

If the Requesting connection screen doesn't progress, check that:

  • The remote device is powered on and has recently been seen by the console - check the Last Seen column on the Devices page.
  • The remote device can reach the On-Prem Management Console URL.
  • No firewall rule is blocking the connection between the console and the remote device.

If authentication fails, make sure you're entering the login credentials for the remote device's operating system (or a VNC password configured on RealVNC Server) - not your RealVNC account or On-Prem Management Console account details.

If none of the above resolves the issue, download the session logs from the connection screen and contact our Support team, including the downloaded logs.

Related articles

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.