MySQL Port 3306: Check the Listener, Test Access, and Connect Safely
MySQL Port 3306: Check the Listener, Test Access, and Connect Safely
A successful connection to TCP port 3306 tells you that something accepted a network connection. It does not prove that the service is MySQL, or that your database username and password will work. Port 3306 is the default TCP port for MySQL’s classic client-server protocol, and MariaDB commonly uses it too. Here’s how to check each layer when a database connection fails—and how to reach a remote database without exposing it broadly.
成功连接到 TCP 3306 端口仅说明有程序接受了网络连接,但这并不能证明该服务就是 MySQL,也不能保证您的数据库用户名和密码有效。3306 端口是 MySQL 经典客户端-服务器协议的默认 TCP 端口,MariaDB 也通常使用该端口。以下是如何在数据库连接失败时检查每一层的方法,以及如何在不广泛暴露数据库的情况下访问远程数据库。
Start with the right port and protocol. A typical MySQL client connects to a host on TCP port 3306: mysql --protocol=TCP -h db.example.net -P 3306 -u app_user -p. The capital -P selects the TCP port. The lowercase -p prompts for a password. Adding —protocol=TCP makes the transport explicit, which is useful when diagnosing connections that might otherwise use a local socket. Port 3306 is not a guarantee about what’s running there. MySQL can be configured to use a different port, and another process can occupy 3306. MySQL’s X Protocol commonly uses TCP port 33060 when enabled; it’s a separate protocol, not a port every installation necessarily listens on.
从正确的端口和协议开始。典型的 MySQL 客户端通过 TCP 3306 端口连接到主机:mysql --protocol=TCP -h db.example.net -P 3306 -u app_user -p。大写的 -P 用于指定 TCP 端口,小写的 -p 用于提示输入密码。添加 --protocol=TCP 可以明确传输方式,这在诊断可能默认使用本地套接字的连接时非常有用。3306 端口并不能保证运行的一定是 MySQL,因为 MySQL 可以配置为使用其他端口,而其他进程也可能占用 3306 端口。MySQL 的 X 协议在启用时通常使用 TCP 33060 端口;这是一个独立的协议,并非每个安装实例都会监听该端口。
Check the server before changing firewall rules. On the database server, inspect whether a process is listening on port 3306: sudo ss -ltnp 'sport = :3306'. If ss doesn’t show process details, and lsof is installed, try: sudo lsof -nP -iTCP:3306 -sTCP:LISTEN. Pay attention to the local address. A listener on 127.0.0.1:3306 accepts connections only through the server’s IPv4 loopback interface. A listener on 0.0.0.0:3306 is bound to all IPv4 interfaces, but that alone does not mean it’s reachable from the internet: firewalls and network rules still apply. IPv6 listeners may appear separately. If you’re unfamiliar with interpreting listening sockets, this Linux guide to checking open ports explains what the output can—and can’t—tell you. On Windows, check local listening connections in PowerShell with: Get-NetTCPConnection -State Listen -LocalPort 3306. A missing listener is a server-side problem to investigate: confirm the database is running, check its configured port, and inspect its bind address. Opening a firewall rule won’t start MySQL or make a loopback-only listener reachable remotely.
在更改防火墙规则之前先检查服务器。在数据库服务器上,检查是否有进程正在监听 3306 端口:sudo ss -ltnp 'sport = :3306'。如果 ss 未显示进程详细信息且已安装 lsof,请尝试:sudo lsof -nP -iTCP:3306 -sTCP:LISTEN。请注意本地地址。监听在 127.0.0.1:3306 的服务仅接受通过服务器 IPv4 回环接口的连接。监听在 0.0.0.0:3306 的服务绑定到所有 IPv4 接口,但这并不意味着它可以从互联网访问:防火墙和网络规则依然适用。IPv6 监听器可能会单独显示。如果您不熟悉如何解读监听套接字,这份 Linux 检查开放端口的指南可以解释输出结果的含义。在 Windows 上,可以使用 PowerShell 检查本地监听连接:Get-NetTCPConnection -State Listen -LocalPort 3306。如果找不到监听器,则需要排查服务器端问题:确认数据库正在运行、检查其配置的端口并查看其绑定地址。仅仅打开防火墙规则并不能启动 MySQL,也无法让仅限回环访问的监听器实现远程连接。
Test network access separately from login. From a Windows client, test whether the host accepts a TCP connection on 3306: Test-NetConnection db.example.net -Port 3306. On Linux or macOS, if Netcat is available: nc -vz db.example.net 3306. These checks test the network path, not database authentication. For an end-to-end login test, use the MySQL client: mysql --protocol=TCP -h db.example.net -P 3306 -u app_user -p. On Unix-like systems, a MySQL client connecting to localhost may use a Unix socket instead of TCP. If you specifically need to test local TCP, use 127.0.0.1 and —protocol=TCP: mysql --protocol=TCP -h 127.0.0.1 -P 3306 -u app_user -p. That distinction helps avoid treating a socket connection as proof that a TCP listener is available.
将网络访问测试与登录测试分开。在 Windows 客户端上,测试主机是否接受 3306 端口的 TCP 连接:Test-NetConnection db.example.net -Port 3306。在 Linux 或 macOS 上,如果安装了 Netcat,可以使用:nc -vz db.example.net 3306。这些检查测试的是网络路径,而非数据库身份验证。若要进行端到端的登录测试,请使用 MySQL 客户端:mysql --protocol=TCP -h db.example.net -P 3306 -u app_user -p。在类 Unix 系统上,连接到 localhost 的 MySQL 客户端可能会使用 Unix 套接字而非 TCP。如果您明确需要测试本地 TCP,请使用 127.0.0.1 和 --protocol=TCP:mysql --protocol=TCP -h 127.0.0.1 -P 3306 -u app_user -p。这种区分有助于避免将套接字连接误认为是 TCP 监听器可用的证据。
Read the failure as a clue. The error usually tells you which layer to inspect next: Connection refused: Nothing may be listening at that address and port, or the host rejected the connection. Check the service, port, and bind address. Connection timed out: The request may be blocked, routed incorrectly, or sent to the wrong host. Check the destination and network or cloud firewall rules. Access denied: The connection reached MySQL, but authentication or authorization failed. Check the account, password, host-based grants, and database permissions. Address already in use: A process already owns that local port, or another database instance is trying to bind to it. Identify the listener before stopping anything; it may be the instance you need. A listening socket, a reachable TCP port, and a successful database login are three different checks. Testing them separately makes troubleshooting much faster.
将故障视为线索。错误信息通常会提示您下一步检查哪一层:连接被拒绝(Connection refused):该地址和端口可能没有监听程序,或者主机拒绝了连接。请检查服务、端口和绑定地址。连接超时(Connection timed out):请求可能被拦截、路由错误或发送到了错误的主机。请检查目标地址以及网络或云防火墙规则。访问被拒绝(Access denied):连接已到达 MySQL,但身份验证或授权失败。请检查账户、密码、基于主机的授权和数据库权限。地址已被使用(Address already in use):某个进程已占用了该本地端口,或者另一个数据库实例正尝试绑定它。在停止任何进程前,请先确认监听者身份;它可能正是您需要的实例。监听套接字、可达的 TCP 端口和成功的数据库登录是三个不同的检查项。分别测试它们可以大大加快故障排除速度。
Reach a remote database without exposing 3306. If you can SSH to the database server, you can forward a local port through that SSH connection. This example maps local port 3307 to port 3306 on the SSH server: ssh -L 3307:127.0.0.1:3306 user@db.example.net. Keep that session open. In another terminal, connect your database client to the local end: mysql --protocol=TCP -h 127.0.0.1 -P 3307 -u app_user -p. The client connects to local port 3307; SSH carries the traffic to 127.0.0.1:3306 as seen from the SSH server. The database still requires valid credentials and permissions. This approach can avoid making MySQL’s port directly reachable from the public internet. For more on how local forwarding works, see this guide to SSH tunnels and port forwarding. For remote access, prefer a private network or a narrowly restricted source address over broad public exposure. Changing MySQL’s port alone is not an access control. If you do change it, update the server configuration and clients separately: the client’s -P option chooses where it connects; it does not change the server’s listening port.
在不暴露 3306 端口的情况下访问远程数据库。如果您可以通过 SSH 连接到数据库服务器,则可以通过该 SSH 连接转发本地端口。此示例将本地 3307 端口映射到 SSH 服务器上的 3306 端口:ssh -L 3307:127.0.0.1:3306 user@db.example.net。保持该会话开启。在另一个终端中,将数据库客户端连接到本地端口:mysql --protocol=TCP -h 127.0.0.1 -P 3307 -u app_user -p。客户端连接到本地 3307 端口;SSH 会将流量传输到 SSH 服务器所见的 127.0.0.1:3306。数据库仍然需要有效的凭据和权限。这种方法可以避免让 MySQL 端口直接暴露在公共互联网上。有关本地转发工作原理的更多信息,请参阅 SSH 隧道和端口转发指南。对于远程访问,建议优先使用私有网络或严格限制的源地址,而不是广泛的公共暴露。仅更改 MySQL 端口并不能起到访问控制的作用。如果您确实更改了端口,请分别更新服务器配置和客户端:客户端的 -P 选项仅决定其连接位置,并不会更改服务器的监听端口。