TigerVNC vs TightVNC vs NoMachine: Choosing a Remote Desktop

TigerVNC vs TightVNC vs NoMachine: comparison of three remote desktop tools for sysadmins

TigerVNC, TightVNC and NoMachine all give you a graphical session on another machine, but they are built for different jobs. The short answer: choose TigerVNC for virtual desktops on Linux servers, TightVNC for quick, silently deployed remote support on Windows PCs on a LAN, and NoMachine when you need smoother video and audio, or one tool across Windows, macOS, Linux and Raspberry Pi and can accept that it is no longer free on the server side.

Side-by-side comparison

FeatureTigerVNCTightVNCNoMachine
LicenceFree, open source (GPL-2.0)Free, open source (GPL-2.0); commercial source licence for developers onlyShareware (conditionally free): the free edition ended with version 10; the client-only player is free
ProtocolVNC (RFB)VNC (RFB)NX
Server platformsLinux/Unix; Windows server is a secondary part of the projectWindows only (current 2.x)Windows, macOS, Linux, Raspberry Pi
Viewer platformsLinux, Windows, macOSWindowsWindows, macOS, Linux; Android and iOS
EncryptionTLS and X.509 security types, SSH tunnel via -viaPassword exchange only; use SSH or a VPN for the sessionBuilt into the NX connection
File transferNot in the protocol; use SFTP/SCPYes, from the viewer toolbarYes, from the in-session menu
Virtual desktop per user on LinuxYes (Xvnc)NoServer products only
Latest version we checked1.16.2 (26 March 2026)2.8.9010.2.3 (6 October 2026)

TigerVNC: virtual desktops on Linux

TigerVNC’s Xvnc starts a complete X desktop per user without a monitor or GPU, which makes it the usual way to give people a GUI on a headless Linux box. x0vncserver shares an existing physical X11 display, and the 1.16 series added w0vncserver for Wayland desktops.

A minimal setup on RHEL, Rocky or Fedora:

  1. Install the packages: dnf install tigervnc-server plus a desktop environment.
  2. Map a display to a user in /etc/tigervnc/vncserver.users: :1=alice.
  3. Set session=gnome and localhost in /etc/tigervnc/vncserver-config-defaults.
  4. As that user run vncpasswd, then systemctl enable --now vncserver@:1. Display :1 listens on TCP 5901.

Because localhost restricts the server to local connections, reach it through SSH: vncviewer -via alice@server.example.com localhost:1. The viewer builds the tunnel for you.

TightVNC: fast Windows deployment

TightVNC is a small MSI that registers the server as a Windows service. Its strength is mass rollout: the official MSI guide documents properties for passwords, ports, firewall exceptions and IP access rules, so one msiexec /i ... /quiet line can configure a whole fleet through your deployment tool. Version 2.8.88 hardened the server’s control channel and 2.8.90 fixed a viewer bug when handling invalid Tight-encoded data, so keep both ends updated.

The trade-off is security. Only the password exchange is protected; the rest of the session is not encrypted. Never forward TCP 5900 from a router. Enable the loopback-only option and connect through a VPN or ssh -L 5900:localhost:5900 admin@gateway. If you only need VNC, also disable the built-in web access on TCP 5800.

NoMachine: performance and mixed environments

NoMachine uses its own NX protocol, aimed at smooth video and low latency, and runs on Windows, macOS, Linux and Raspberry Pi. It supports audio, file transfer, printer and USB forwarding, and since version 10 it can open remote terminal sessions. NoMachine’s own page says version 10 discontinued the free edition in favour of a commercial Personal Edition, so it counts as shareware (conditionally free) here. The standalone client, now called NoMachine Player (formerly Enterprise Client), is described as free and connects to any machine running Personal Edition or an Enterprise product.

On Linux the server installs under /usr/NX/; check it with sudo /usr/NX/bin/nxserver --status. NX uses TCP and UDP port 4000 by default, so allow both, or sessions fall back to slower TCP-only mode. As with VNC, do not expose the port to the internet; keep it behind a VPN.

Which one should you pick?

  • Headless Linux server, several users, open source only: TigerVNC.
  • Windows help desk, many PCs, silent install, LAN or VPN: TightVNC.
  • Mixed Windows/macOS/Linux, video or audio matters: NoMachine, if a licence for the servers is acceptable.
  • Many hosts using several protocols: add mRemoteNG as a single tabbed console for VNC, RDP and SSH. It opens VNC sessions to either VNC server above.

The viewers are interchangeable across the two VNC servers, since both speak standard RFB. For monitoring the machines you reach this way, see server monitoring and logging tools.

Security checklist for any of the three

  1. Keep the listening port (5900+N for VNC, 4000 for NX) closed on the internet-facing firewall and reach the host through a VPN or an SSH tunnel.
  2. Use a separate view-only password where the tool offers one, so a colleague who only needs to watch cannot control the machine. TightVNC supports separate full-control and view-only passwords.
  3. Restrict who may connect. TightVNC has IP access rules, and TigerVNC can be bound to localhost so only the tunnel reaches it.
  4. Update on release. TightVNC’s two latest releases are security and stability fixes, and NoMachine keeps releasing updates for its older branches next to the newest one.
  5. Treat remote-access hosts as sensitive servers and harden them like the rest; see the backup and server hardening guide.

Limitations

  • TigerVNC and TightVNC have no NAT traversal, relay or address-book service; you need direct network access, a VPN or SSH.
  • VNC password authentication uses at most 8 characters in both products, so rely on TLS, SSH or a VPN for real protection.
  • TightVNC’s current releases are Windows-only; its old Unix version is no longer developed.
  • TigerVNC virtual desktops use software rendering, so 3D and video-heavy work is slow.
  • NoMachine is closed source, and Personal Edition servers need a licence tied to a NoMachine account.

FAQ

Is TigerVNC free for commercial use?

Yes. TigerVNC is open source under GPL-2.0 and can be used in a business without a licence fee.

TigerVNC vs TightVNC: which is better?

TigerVNC is better on Linux and when you need encryption. TightVNC is simpler for Windows-to-Windows support with file transfer. Their viewers can connect to each other’s servers.

Is TightVNC free for commercial use?

Yes, under GPL-2.0. Only developers who want to embed the code in closed-source products need the separate commercial source licence.

Is there TigerVNC or TightVNC for Mac?

TigerVNC has a universal macOS viewer, but no macOS server. Current TightVNC versions are Windows-only; use any VNC viewer on a Mac to reach a TightVNC server.

How do I exit full screen in TightVNC?

Press Ctrl+Alt+Shift+F in the viewer. In TigerVNC 1.16 and later the shortcut is Ctrl+Alt+Enter.

Is NoMachine still free?

Not on the server side. Version 10 discontinued the free edition, though the standalone client is still free to use.

Last updated: 11 October 2026 · ITForgePro editorial team. Licence, version and platform details are checked against each developer's official documentation.

Other articles

Submit your application