iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To let another machine connect to a MySQL server, four things have to line up: the server must listen on an address the network can reach, the network must pass TCP traffic on the MySQL port from the right source, the MySQL account must match the connecting host, and the connection should be encrypted with TLS. Opening port 3306 to every address is not a fix for a connection problem. It removes the protection the other three layers provide, and it usually hides the real cause of the failure.
The server-side details below follow the MySQL 8.4 Reference Manual as of October 2026. Where a step depends on your operating system or hosting provider, this guide says so and points you to the vendor’s current documentation rather than assuming one platform.
Identify where your MySQL server runs
The steps differ depending on who controls the listener and the firewall. There are two common cases:
- Self-managed MySQL. You control the server’s option file, the operating-system firewall, and any network controls in front of the host. Every step in this guide applies directly.
- Managed database service. The provider controls the listener and exposes network access through its own configuration, such as an allowed-source list or a private network setting. The account, privilege, and TLS concepts still apply, but the places where you change them are different. Use the provider’s current documentation for the exact screens and settings, because the names and locations change between platforms and versions.
Whichever case applies, confirm the version first. Run SELECT VERSION(); from an existing session. The behavior described here is documented for MySQL 8.4. Older releases may differ on some points, especially TLS defaults.
#1 Best Overall
Step 1: Confirm the client uses TCP/IP
A remote connection is a TCP/IP connection. A Unix socket file only works for clients on the same machine, so it cannot carry a connection from another host. The MySQL 8.4 Reference Manual’s page on connection transport protocols states that TCP/IP transport supports connections to local or remote MySQL servers.
On Unix-like systems, the client selects a socket when it sees localhost and no protocol is given. When you connect remotely, use the server’s hostname or IP address. When you are diagnosing a problem, force TCP explicitly with --protocol=TCP, so a socket fallback cannot hide the real result.
Step 2: Configure the server listener
The server listens for TCP/IP connections on the address set by the bind_address system variable. It is read at startup. The MySQL 8.4 system variable reference documents the possible values, and the choice you make determines how widely the listener is exposed.
Choosing a bind address
| Value | What the server listens on | Exposure | Typical use |
|---|---|---|---|
A specific address, such as 10.0.0.5 |
Only that one interface address | Narrowest | Remote access over a private network where the server has a known address |
* (wildcard) |
All server IPv4 interfaces and, when available, IPv6 interfaces | Broad | Hosts with several interfaces where firewall rules fully control access |
0.0.0.0 |
All IPv4 interfaces | Broad, IPv4 only | Rarely needed; prefer a specific address |
:: |
IPv4 and IPv6 interfaces | Broad | Only when IPv6 access is required and controlled by firewall rules |
A specific address is the safest choice for most remote access setups because it removes the listener from every other interface. A wildcard is not wrong by itself, but it means the network policy in the next step becomes the only barrier.
Rank #2
Set the address and restart
Set the value in the option file that your installation reads. The file’s location and the section names depend on how MySQL was packaged on your system, so check your installation’s documentation before editing. A typical entry looks like this:
[mysqld]nbind_address = 10.0.0.5nport = 3306
Restart the MySQL service so the new value takes effect. Then confirm the value the running server is using:
SHOW VARIABLES LIKE 'bind_address';
Keep a local administrative path
Before you narrow the bind address, make sure you still have a way to administer the server. If you change the listener and then lose remote access, a local session is your recovery route. On the server itself, you can connect over the socket with mysql --protocol=SOCKET --user=root -p. Keep this path working while you test remote access. If you are administering the server over SSH, keep that session open until the new listener is confirmed from a client.
Free tools Windows power users keep installed
One-click scans. No signup required.
Step 3: Allow only the sources that need access
A reachable listener still has to get past the network. The operating-system firewall on the database host, any firewall or security group in front of it, and any routing between the client and the server all decide whether a packet reaches port 3306.
- Allow inbound TCP to the MySQL port only from the client address or private subnet that needs access.
- Do not allow the port from
0.0.0.0/0or any equivalent “anywhere” source as a convenience step. - If the client sits behind NAT, the address the server sees is the translated address. Write the rule for that address, not the client’s internal one.
- Confirm rules on every layer that applies: host firewall, cloud network policy, and any appliance upstream.
The exact commands and console screens depend on your operating system and provider, and this guide does not assume one. Consult your firewall’s or provider’s current documentation for the rule syntax. A managed database often exposes this step as an allowed-source list or private connectivity option rather than a firewall rule.
Step 4: Create a host-specific account
MySQL does not identify an account by username alone. An account is the pair of a username and a host, written as 'name'@'host'. The server accepts a login only when the username, the host, and the password all match. The MySQL 8.4 access control documentation describes this account model, and the CREATE USER statement reference covers the syntax.
Choose the host part deliberately
| Host value | Matches | Guidance |
|---|---|---|
'10.0.1.25' |
Only that client address | Best when one application server connects |
'10.0.1.%' |
Any address beginning with 10.0.1. | Reasonable for a trusted private subnet |
'%' |
Any host | Avoid. It accepts the account from every source the firewall lets through |
Use the narrowest host value that still matches the real client. Test it with the address the server actually sees, because NAT, proxies, and VPN gateways can change it.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsCreate the account and grant only what it needs
The example below uses documentation-style addresses and placeholder values. Replace them with your own, and do not run the statements with a real password typed on the command line.
CREATE USER 'app_user'@'10.0.1.25'n IDENTIFIED BY 'replace-with-a-generated-secret'n REQUIRE SSL;nnGRANT SELECT, INSERT, UPDATE, DELETEn ON app_database.*n TO 'app_user'@'10.0.1.25';
A newly created account has no privileges, so the GRANT statement reference is where you define what the account can do. Grant only the statements the application uses, on the database or tables it needs. If an account only reads data, do not grant write privileges.
Follow these account rules:
- Do not use the
rootaccount for routine application access. Root has broad privileges that the application does not need. - Do not treat
'%'as a harmless default for the host part. - Do not run
FLUSH PRIVILEGESafterCREATE USERorGRANT. Use the account-management statements, which update the grant tables for you, rather than editing the grant tables directly. - Avoid putting a password in a statement that ends up in logs or history. The CREATE USER documentation notes that cleartext passwords can, in some circumstances, appear in server logs or in the client’s history file. Use a secret store or a generated value, and enter passwords through an interactive prompt where the client supports it.
Step 5: Require encrypted connections
A password does not encrypt the traffic that carries it. Without TLS, queries and results travel over the network in a form that can be read by anyone with access to the path. MySQL supports encrypted connections over TCP/IP, and the guide to configuring encrypted connections explains how the server is set up with certificates.
Choose where encryption is enforced
You can require TLS at three layers. They do different jobs, so pick the one that matches your situation, or combine them.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Layer | How it is set | What it enforces | Scope and caveats |
|---|---|---|---|
| Account | REQUIRE SSL in CREATE USER or ALTER USER |
This account must connect encrypted | Affects only that account; other accounts are not changed |
| Server | require_secure_transport=ON |
The server refuses unencrypted connections | Server-wide. Check every client before enabling it, or unencrypted applications will fail |
| Client | --ssl-mode=REQUIRED or a stricter mode |
The client insists on TLS before it sends credentials | Protects the client’s side only; it does not change what the server accepts |
The reference for command options when connecting to the server lists the --ssl-mode values. REQUIRED makes the client encrypt the connection but does not check the server’s certificate. For stronger assurance, use VERIFY_CA, which checks that the server certificate was issued by a trusted certificate authority, or VERIFY_IDENTITY, which also checks that the certificate matches the hostname you connect to. Both need the CA certificate on the client and a certificate configured on the server.
Best Value
Supported TLS versions
MySQL 8.4 supports TLSv1.2 and TLSv1.3. TLSv1.0 and TLSv1.1 are not supported. The TLS protocols and ciphers page lists the details. If an older client only supports TLS 1.0 or 1.1, it cannot connect to MySQL 8.4 over encrypted transport, and the fix is to upgrade the client rather than to lower the server’s requirement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Step 6: Connect and verify
Run the checks in this order. Each one isolates a single layer, so a failure tells you which layer to fix.
- Confirm the listener. On the server, run
SHOW VARIABLES LIKE 'bind_address';and confirm the value you set. To see which addresses and ports are open on a Linux server, you can use a socket listing command such asss -ltn, if your distribution includes it. - Confirm network reachability. From the client, check that TCP port 3306 on the server is reachable. On systems with netcat,
nc -vz DB_HOST 3306performs a simple check. A failure here points to routing or firewall rules, not MySQL. - Connect with TCP and TLS. Use a command like the following, replacing the placeholders:
mysql --protocol=TCP --host=DB_HOST --port=3306 --user=app_user --ssl-mode=REQUIRED -p app_database - Check the identity the server sees. Run
SELECT CURRENT_USER();. The result should show the account you intended, with the host part you created. - Confirm encryption is active. Run
SHOW SESSION STATUS LIKE 'Ssl_cipher';. A non-empty value confirms that this session is encrypted. - Check privileges. Run
SHOW GRANTS FOR CURRENT_USER();and then attempt one operation the account should not be allowed to perform. A denial confirms that the grants are limited as intended.
Troubleshoot by layer
Most failed remote connections look like one of a few messages. The message tells you which layer rejected the attempt, and the checks that follow isolate it.
| Symptom | Layer most likely at fault | What to check |
|---|---|---|
| Connection times out, or “Can’t connect to MySQL server” with no response | Network path or firewall | Client-to-server reachability on TCP 3306, firewall rules on the host and upstream, and whether the source address is allowed |
| Connection refused immediately | Listener | Whether the server is running, whether it is listening on the address the client uses, and the value of bind_address |
Access denied for user 'app_user'@'...' |
Account host match or credentials | Run SELECT user, host FROM mysql.user WHERE user = 'app_user'; and compare the host with the address the server sees; check the password |
SELECT command denied to user ... or a similar privilege error |
Grants (authorization) | Run SHOW GRANTS FOR 'app_user'@'host'; and compare with the statement that failed |
| An error stating that connections using insecure transport are prohibited | Server or account TLS requirement | Whether require_secure_transport or REQUIRE SSL applies, and whether the client sets --ssl-mode |
| TLS handshake or certificate verification failure | TLS configuration | The CA certificate on the client, the hostname used for VERIFY_IDENTITY, and the TLS version the client supports |
The distinction between the second-to-last and last rows matters. An access-denied error at login is about the account and its host. A privilege error after login is about grants. Changing the grants will not fix a host mismatch, and changing the host will not fix a missing privilege.
Managed databases
If your MySQL runs on a managed service, the server-side steps above are handled by the provider. Your work is to choose the allowed-source or private-network setting, create the account in the way the provider documents, and make TLS required where the provider supports it. The account and grant rules still apply, because the database engine enforces them regardless of hosting. Check the provider’s current documentation for the connection endpoint, the TLS certificate it provides, and any restrictions on creating accounts.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

