Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To let another machine connect to a MySQL server, four things have to line up: the server must listen on an address the network can reach, the network must pass TCP traffic on the MySQL port from the right source, the MySQL account must match the connecting host, and the connection should be encrypted with TLS. Opening port 3306 to every address is not a fix for a connection problem. It removes the protection the other three layers provide, and it usually hides the real cause of the failure.

The server-side details below follow the MySQL 8.4 Reference Manual as of October 2026. Where a step depends on your operating system or hosting provider, this guide says so and points you to the vendor’s current documentation rather than assuming one platform.

Identify where your MySQL server runs

The steps differ depending on who controls the listener and the firewall. There are two common cases:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Self-managed MySQL. You control the server’s option file, the operating-system firewall, and any network controls in front of the host. Every step in this guide applies directly.
  • Managed database service. The provider controls the listener and exposes network access through its own configuration, such as an allowed-source list or a private network setting. The account, privilege, and TLS concepts still apply, but the places where you change them are different. Use the provider’s current documentation for the exact screens and settings, because the names and locations change between platforms and versions.

Whichever case applies, confirm the version first. Run SELECT VERSION(); from an existing session. The behavior described here is documented for MySQL 8.4. Older releases may differ on some points, especially TLS defaults.

Step 1: Confirm the client uses TCP/IP

A remote connection is a TCP/IP connection. A Unix socket file only works for clients on the same machine, so it cannot carry a connection from another host. The MySQL 8.4 Reference Manual’s page on connection transport protocols states that TCP/IP transport supports connections to local or remote MySQL servers.

On Unix-like systems, the client selects a socket when it sees localhost and no protocol is given. When you connect remotely, use the server’s hostname or IP address. When you are diagnosing a problem, force TCP explicitly with --protocol=TCP, so a socket fallback cannot hide the real result.

Step 2: Configure the server listener

The server listens for TCP/IP connections on the address set by the bind_address system variable. It is read at startup. The MySQL 8.4 system variable reference documents the possible values, and the choice you make determines how widely the listener is exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choosing a bind address

Value What the server listens on Exposure Typical use
A specific address, such as 10.0.0.5 Only that one interface address Narrowest Remote access over a private network where the server has a known address
* (wildcard) All server IPv4 interfaces and, when available, IPv6 interfaces Broad Hosts with several interfaces where firewall rules fully control access
0.0.0.0 All IPv4 interfaces Broad, IPv4 only Rarely needed; prefer a specific address
:: IPv4 and IPv6 interfaces Broad Only when IPv6 access is required and controlled by firewall rules

A specific address is the safest choice for most remote access setups because it removes the listener from every other interface. A wildcard is not wrong by itself, but it means the network policy in the next step becomes the only barrier.

Set the address and restart

Set the value in the option file that your installation reads. The file’s location and the section names depend on how MySQL was packaged on your system, so check your installation’s documentation before editing. A typical entry looks like this:

[mysqld]nbind_address = 10.0.0.5nport = 3306

Restart the MySQL service so the new value takes effect. Then confirm the value the running server is using:

SHOW VARIABLES LIKE 'bind_address';

Keep a local administrative path

Before you narrow the bind address, make sure you still have a way to administer the server. If you change the listener and then lose remote access, a local session is your recovery route. On the server itself, you can connect over the socket with mysql --protocol=SOCKET --user=root -p. Keep this path working while you test remote access. If you are administering the server over SSH, keep that session open until the new listener is confirmed from a client.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 3: Allow only the sources that need access

A reachable listener still has to get past the network. The operating-system firewall on the database host, any firewall or security group in front of it, and any routing between the client and the server all decide whether a packet reaches port 3306.

  • Allow inbound TCP to the MySQL port only from the client address or private subnet that needs access.
  • Do not allow the port from 0.0.0.0/0 or any equivalent “anywhere” source as a convenience step.
  • If the client sits behind NAT, the address the server sees is the translated address. Write the rule for that address, not the client’s internal one.
  • Confirm rules on every layer that applies: host firewall, cloud network policy, and any appliance upstream.

The exact commands and console screens depend on your operating system and provider, and this guide does not assume one. Consult your firewall’s or provider’s current documentation for the rule syntax. A managed database often exposes this step as an allowed-source list or private connectivity option rather than a firewall rule.

Step 4: Create a host-specific account

MySQL does not identify an account by username alone. An account is the pair of a username and a host, written as 'name'@'host'. The server accepts a login only when the username, the host, and the password all match. The MySQL 8.4 access control documentation describes this account model, and the CREATE USER statement reference covers the syntax.

Choose the host part deliberately

Host value Matches Guidance
'10.0.1.25' Only that client address Best when one application server connects
'10.0.1.%' Any address beginning with 10.0.1. Reasonable for a trusted private subnet
'%' Any host Avoid. It accepts the account from every source the firewall lets through

Use the narrowest host value that still matches the real client. Test it with the address the server actually sees, because NAT, proxies, and VPN gateways can change it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Create the account and grant only what it needs

The example below uses documentation-style addresses and placeholder values. Replace them with your own, and do not run the statements with a real password typed on the command line.

CREATE USER 'app_user'@'10.0.1.25'n  IDENTIFIED BY 'replace-with-a-generated-secret'n  REQUIRE SSL;nnGRANT SELECT, INSERT, UPDATE, DELETEn  ON app_database.*n  TO 'app_user'@'10.0.1.25';

A newly created account has no privileges, so the GRANT statement reference is where you define what the account can do. Grant only the statements the application uses, on the database or tables it needs. If an account only reads data, do not grant write privileges.

Follow these account rules:

  • Do not use the root account for routine application access. Root has broad privileges that the application does not need.
  • Do not treat '%' as a harmless default for the host part.
  • Do not run FLUSH PRIVILEGES after CREATE USER or GRANT. Use the account-management statements, which update the grant tables for you, rather than editing the grant tables directly.
  • Avoid putting a password in a statement that ends up in logs or history. The CREATE USER documentation notes that cleartext passwords can, in some circumstances, appear in server logs or in the client’s history file. Use a secret store or a generated value, and enter passwords through an interactive prompt where the client supports it.

Step 5: Require encrypted connections

A password does not encrypt the traffic that carries it. Without TLS, queries and results travel over the network in a form that can be read by anyone with access to the path. MySQL supports encrypted connections over TCP/IP, and the guide to configuring encrypted connections explains how the server is set up with certificates.

Choose where encryption is enforced

You can require TLS at three layers. They do different jobs, so pick the one that matches your situation, or combine them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Layer How it is set What it enforces Scope and caveats
Account REQUIRE SSL in CREATE USER or ALTER USER This account must connect encrypted Affects only that account; other accounts are not changed
Server require_secure_transport=ON The server refuses unencrypted connections Server-wide. Check every client before enabling it, or unencrypted applications will fail
Client --ssl-mode=REQUIRED or a stricter mode The client insists on TLS before it sends credentials Protects the client’s side only; it does not change what the server accepts

The reference for command options when connecting to the server lists the --ssl-mode values. REQUIRED makes the client encrypt the connection but does not check the server’s certificate. For stronger assurance, use VERIFY_CA, which checks that the server certificate was issued by a trusted certificate authority, or VERIFY_IDENTITY, which also checks that the certificate matches the hostname you connect to. Both need the CA certificate on the client and a certificate configured on the server.

Supported TLS versions

MySQL 8.4 supports TLSv1.2 and TLSv1.3. TLSv1.0 and TLSv1.1 are not supported. The TLS protocols and ciphers page lists the details. If an older client only supports TLS 1.0 or 1.1, it cannot connect to MySQL 8.4 over encrypted transport, and the fix is to upgrade the client rather than to lower the server’s requirement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Step 6: Connect and verify

Run the checks in this order. Each one isolates a single layer, so a failure tells you which layer to fix.

  1. Confirm the listener. On the server, run SHOW VARIABLES LIKE 'bind_address'; and confirm the value you set. To see which addresses and ports are open on a Linux server, you can use a socket listing command such as ss -ltn, if your distribution includes it.
  2. Confirm network reachability. From the client, check that TCP port 3306 on the server is reachable. On systems with netcat, nc -vz DB_HOST 3306 performs a simple check. A failure here points to routing or firewall rules, not MySQL.
  3. Connect with TCP and TLS. Use a command like the following, replacing the placeholders:
    mysql --protocol=TCP --host=DB_HOST --port=3306 --user=app_user --ssl-mode=REQUIRED -p app_database
  4. Check the identity the server sees. Run SELECT CURRENT_USER();. The result should show the account you intended, with the host part you created.
  5. Confirm encryption is active. Run SHOW SESSION STATUS LIKE 'Ssl_cipher';. A non-empty value confirms that this session is encrypted.
  6. Check privileges. Run SHOW GRANTS FOR CURRENT_USER(); and then attempt one operation the account should not be allowed to perform. A denial confirms that the grants are limited as intended.

Troubleshoot by layer

Most failed remote connections look like one of a few messages. The message tells you which layer rejected the attempt, and the checks that follow isolate it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Symptom Layer most likely at fault What to check
Connection times out, or “Can’t connect to MySQL server” with no response Network path or firewall Client-to-server reachability on TCP 3306, firewall rules on the host and upstream, and whether the source address is allowed
Connection refused immediately Listener Whether the server is running, whether it is listening on the address the client uses, and the value of bind_address
Access denied for user 'app_user'@'...' Account host match or credentials Run SELECT user, host FROM mysql.user WHERE user = 'app_user'; and compare the host with the address the server sees; check the password
SELECT command denied to user ... or a similar privilege error Grants (authorization) Run SHOW GRANTS FOR 'app_user'@'host'; and compare with the statement that failed
An error stating that connections using insecure transport are prohibited Server or account TLS requirement Whether require_secure_transport or REQUIRE SSL applies, and whether the client sets --ssl-mode
TLS handshake or certificate verification failure TLS configuration The CA certificate on the client, the hostname used for VERIFY_IDENTITY, and the TLS version the client supports

The distinction between the second-to-last and last rows matters. An access-denied error at login is about the account and its host. A privilege error after login is about grants. Changing the grants will not fix a host mismatch, and changing the host will not fix a missing privilege.

Managed databases

If your MySQL runs on a managed service, the server-side steps above are handled by the provider. Your work is to choose the allowed-source or private-network setting, create the account in the way the provider documents, and make TLS required where the provider supports it. The account and grant rules still apply, because the database engine enforces them regardless of hosting. Check the provider’s current documentation for the connection endpoint, the TLS certificate it provides, and any restrictions on creating accounts.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.