cPanel has a tool called Remote MySQL, where you type the IP address of whoever may connect to your database. There is one thing the screen does not say: port 3306 on the server is not open from outside. Authorising the address in cPanel, on its own, does not make the connection work. The route that works is an SSH tunnel.
What each piece does
| Piece |
What it does |
Enough to connect from outside? |
| Remote MySQL (cPanel) |
Tells MariaDB that a user may come from a given address. |
No. The port still has to be reachable. |
| Port 3306 on the server |
The port the database listens on. It listens on the server, but is not open to the internet. |
No, while closed. |
| SSH tunnel |
Carries the connection inside the SSH port, and the database sees it as local. |
Yes. The recommended route. |
The route that works
| 3 |
In MySQL Workbench, DBeaver or another client, use 127.0.0.1 and the local port of the tunnel. See MySQL Workbench.
|
|
Never authorise % (any address). That leaves the database at the mercy of anyone who can guess the password, from anywhere in the world. If you use Remote MySQL, type the exact address of whoever needs it. And bear in mind that most home connections change IP from time to time.
|
What if your application, on another server, really needs a direct connection? That is a decision about the server’s firewall, not about your account. Open a ticket, tell us the source address and why, and we will tell you what is possible. We do not promise the port will be opened. In many cases the right answer is to move the database next to the application, or to use the tunnel.
Alternatives that avoid a remote connection
Before insisting on a direct connection, ask whether the other side really needs the whole database. Often a small endpoint on your account that returns only the data the other side needs, protected by a key, is enough. Other times it is enough to export the data from time to time. The tunnel is left for administration. Exposing a database to the internet is the most common way data leaks, and a narrow access gives only what is needed and nothing more.
|
Quick diagnosis: if connecting to the server IP times out (instead of saying Access denied), the packet never reached the database. It is the closed port, not the password. See which ports are open.
|
|
Need an outside connection and the tunnel will not do? Tell us the source address and the reason and we will tell you what is possible.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from £5.28/mo (3-year plan, with coupon) See plans |