Maybe, but it doesn't explicitly cover VNC, which Jeremey needs. I'm pretty sure he doesn't know *which* ports to allow through for VNC.
At least he needs to add 5900:tcp for DISPLAY :0, and add 1 for each succeeding DISPLAY that he wants to be available....
It's a way..You are right you have to know the port number.
I have no FC2 on this machine now.I remind about possibility to select a trusted/server/application too(instead of port).
If he ran VNC like service perhaps he could use this feature.am I right?