The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Is it better to allow external incoming TCP connections to MySQL 3306 or not?

Discussion in 'Security' started by Smaily, Jul 19, 2013.

  1. Smaily

    Smaily Well-Known Member

    Joined:
    Sep 19, 2011
    Messages:
    46
    Likes Received:
    0
    Trophy Points:
    6
    cPanel Access Level:
    Root Administrator
    I have webserver offering domains, apache, mysql, mail.
    Now some clients are interested in getting feature to be able to connect another server into my MySQL server.

    I have no clue if that would eventually be a bad decision to allow TCP incoming to 3306 through firewall or not.

    By my experience it has been a bad idea to do so. Any good or bads are welcome to discuss here?
     
  2. quizknows

    quizknows Well-Known Member

    Joined:
    Oct 20, 2009
    Messages:
    940
    Likes Received:
    55
    Trophy Points:
    28
    cPanel Access Level:
    DataCenter Provider
    On cPanel systems, even if 3306 is open, remote connections are denied by MySQL itself unless you explicitly allow the remote IP permissions to access MySQL.

    Usually I recommend keeping the port closed unless your host acts as a dedicated database server. Also, remote MySQL will be very slow unless the servers are connected together on a private network in the same data center.
     
  3. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,678
    Likes Received:
    652
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    Allowing inbound connections to port 3306 will allow remote servers to access MySQL on your system as long as their IP address is authorized. Sometimes end-users will need to access their database remotely if they are using a third-party application on their desktop, or if their website is hosted on another server.

    Thank you.
     
Loading...

Share This Page