Skip to content
Back to Blog
Hosting Support8 min read

How to Allow Remote MySQL Connections in cPanel

Learn how to configure remote MySQL access in cPanel by adding trusted IPs, adjusting firewall rules, and testing connectivity with the mysql client.

Written by Abdul AbrorTechnical Hosting Support Engineer
How to Allow Remote MySQL Connections in cPanel
On this page

Allowing remote MySQL connections in cPanel is essential when you need external applications, development environments, or remote servers to connect to your database. By default, MySQL only accepts connections from localhost for security reasons. This guide walks you through the complete process of enabling remote access safely through cPanel's interface, firewall configuration, and connection testing.

Understanding Remote MySQL Access

When MySQL is installed on a cPanel server, it binds to the local network interface and restricts connections to the server itself. This prevents unauthorized access but also blocks legitimate remote connections from your applications, backup systems, or development machines.

Enabling remote access requires three key steps: whitelisting the remote IP address in cPanel, ensuring the firewall permits MySQL traffic, and verifying that MySQL itself is configured to accept remote connections. Skip any of these steps and your connection attempts will fail.

Prerequisites and Security Considerations

Before enabling remote MySQL access, gather the information you'll need:

  • The public IP address of the machine that will connect remotely
  • Your cPanel login credentials
  • Root or sudo access to the server (for firewall changes)
  • The MySQL database name, username, and password

Security best practices:

  • Only whitelist specific IP addresses, never use wildcards or 0.0.0.0
  • Use strong MySQL passwords with mixed case, numbers, and symbols
  • Consider using SSH tunneling instead of direct MySQL connections when possible
  • Regularly audit the Remote MySQL access list and remove unused IPs
  • Enable SSL/TLS for MySQL connections if handling sensitive data
  • Restrict remote user privileges to only the databases they need

Step 1: Add Remote IP in cPanel Remote MySQL

The cPanel Remote MySQL interface is your primary control point for managing which IP addresses can connect to your databases.

Access the Remote MySQL Interface

  1. Log into cPanel using your credentials
  2. Navigate to the Databases section
  3. Click on Remote MySQL®

You'll see a simple interface with a list of currently trusted hosts (if any) and an input field to add new ones.

Add the Trusted Host

In the Add Access Host section:

  1. Enter the IP address in the Host field - For a specific IP: 203.0.113.45 - For a range (not recommended): 203.0.113.%
  2. Optionally add a comment in the Comment field to identify this connection (e.g., "Production app server" or "Development machine")
  3. Click Add Host

The IP address will appear in the Access Hosts list below. cPanel immediately updates the MySQL access control list, though you may need to wait a few seconds for the changes to propagate.

Common Issues at This Stage

Wrong IP address: Make sure you're adding your public IP, not a private network IP. If your remote machine is behind NAT or a corporate network, you need the external IP that the cPanel server sees. Search "what is my IP" from the remote machine to confirm.

IPv4 vs IPv6: cPanel supports both, but make sure you're using the correct protocol. If your remote connection uses IPv6, add the full IPv6 address.

Wildcard usage: While cPanel accepts wildcards like %.example.com or 192.168.1.%, avoid them in production. Each wildcard expands your attack surface significantly.

Step 2: Configure Firewall Rules

Adding an IP in cPanel Remote MySQL updates MySQL's internal access control but doesn't modify the server firewall. Most cPanel servers run either CSF (ConfigServer Security & Firewall) or firewalld, and both block MySQL's default port by default.

For Servers Running CSF

CSF is the most common firewall on cPanel servers. To allow MySQL connections:

  1. Log into WHM (Web Host Manager) as root
  2. Navigate to Plugins → ConfigServer Security & Firewall
  3. Click Firewall Allow IPs
  4. Add the remote IP address with a comment
  5. Click Add

Alternatively, edit the CSF configuration via SSH:

sudo nano /etc/csf/csf.allow

Add a line for your IP:

203.0.113.45 # Production app server MySQL access

Restart CSF to apply changes:

sudo csf -r

For more granular control, you can allow only port 3306 from the specific IP:

sudo nano /etc/csf/csf.conf

Find the TCP_IN line and ensure 3306 is listed, then add a custom rule:

sudo nano /etc/csf/csf.allow

Add:

tcp|in|d=3306|s=203.0.113.45 # MySQL from production server

For Servers Running firewalld

Some newer cPanel installations use firewalld:

sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="203.0.113.45" port protocol="tcp" port="3306" accept'
sudo firewall-cmd --reload

Verify the rule was added:

sudo firewall-cmd --list-rich-rules

For Servers Running iptables Directly

If you're managing iptables manually:

sudo iptables -I INPUT -p tcp -s 203.0.113.45 --dport 3306 -j ACCEPT
sudo service iptables save

Verify the rule:

sudo iptables -L -n | grep 3306

Step 3: Verify MySQL Network Configuration

MySQL must be configured to listen on a network interface accessible to remote connections. On most cPanel servers, this is already configured correctly, but it's worth verifying.

Check the MySQL bind address:

sudo grep bind-address /etc/my.cnf

You should see either:

bind-address = 0.0.0.0

Or the line may be commented out or absent entirely, which means MySQL listens on all interfaces by default.

If you see bind-address = 127.0.0.1, MySQL only accepts local connections. Change it to 0.0.0.0 or comment it out:

sudo nano /etc/my.cnf

Find and modify:

# bind-address = 127.0.0.1
bind-address = 0.0.0.0

Restart MySQL:

sudo systemctl restart mysql

Or on older systems:

sudo service mysql restart

Verify MySQL is listening on the correct port:

sudo netstat -tlnp | grep 3306

You should see output like:

tcp        0      0 0.0.0.0:3306            0.0.0.0:*               LISTEN      12345/mysqld

If you see 127.0.0.1:3306 instead of 0.0.0.0:3306, MySQL is still bound to localhost only.

Step 4: Test the Remote Connection

Now test connectivity from your remote machine. The mysql command-line client is the most reliable tool for verification.

Install MySQL Client

If the mysql client isn't installed on your remote machine:

On Ubuntu/Debian:

sudo apt update
sudo apt install mysql-client

On CentOS/RHEL:

sudo yum install mysql

On macOS:

brew install mysql-client

Connect from Remote Machine

Use this syntax:

mysql -u username -p -h server-ip-or-hostname database_name

Example:

mysql -u myuser -p -h 198.51.100.10 mydb

You'll be prompted for the password. If the connection succeeds, you'll see the MySQL prompt:

mysql>

Run a test query:

SHOW TABLES;

If you can see tables and run queries, remote access is working correctly.

Troubleshooting Connection Failures

Connection timeout or "No route to host":

  • Firewall is still blocking port 3306
  • Verify firewall rules are active
  • Check if a network firewall or security group (on cloud hosts) is blocking traffic

"Access denied for user":

  • The IP wasn't added correctly in cPanel Remote MySQL
  • Check the username and password are correct
  • Verify the MySQL user has privileges on the specific database
  • MySQL user may be restricted to specific databases only

"Can't connect to MySQL server":

  • MySQL isn't listening on the external interface
  • Check bind-address configuration
  • Verify MySQL service is running: sudo systemctl status mysql

"Host is not allowed to connect":

  • The IP address is definitely not in the Remote MySQL whitelist
  • Double-check the IP cPanel sees versus your actual public IP
  • Remember to add the IP without any subnet notation unless intentional

Test with Telnet

If mysql client connections fail, test raw TCP connectivity:

telnet server-ip 3306

If you see connection refused or timeout, the problem is network-level (firewall). If you see a connection and gibberish characters (MySQL's handshake), the network path is clear and the issue is authentication or MySQL configuration.

Managing Remote Access Users

For better security, create dedicated MySQL users for remote access with limited privileges.

Create a Remote-Only User

Log into MySQL locally on the cPanel server:

mysql -u root -p

Create a user restricted to the remote IP:

CREATE USER 'remoteuser'@'203.0.113.45' IDENTIFIED BY 'strong_password_here';

Grant privileges on a specific database:

GRANT SELECT, INSERT, UPDATE, DELETE ON mydatabase.* TO 'remoteuser'@'203.0.113.45';

For read-only access:

GRANT SELECT ON mydatabase.* TO 'remoteuser'@'203.0.113.45';

Apply changes:

FLUSH PRIVILEGES;

This approach means even if credentials are compromised, the attacker can only connect from the whitelisted IP and only access the specified database with limited permissions.

Audit Existing Access

Regularly review who has remote access:

SELECT user, host FROM mysql.user WHERE host != 'localhost';

Remove users that no longer need access:

DROP USER 'olduser'@'203.0.113.45';

Alternative: SSH Tunneling

For maximum security, consider SSH tunneling instead of direct MySQL access. This encrypts all traffic and doesn't require opening MySQL ports on the firewall.

From your remote machine:

ssh -L 3306:localhost:3306 [email protected]

Then connect to MySQL via localhost:

mysql -u username -p -h 127.0.0.1 database_name

The connection is encrypted through SSH, and MySQL only needs to accept connections from localhost (its default secure state). This approach is ideal for development environments or occasional administrative access.

Conclusion

Enabling remote MySQL access in cPanel requires three coordinated steps: whitelisting the remote IP in cPanel Remote MySQL, configuring firewall rules to allow port 3306 traffic, and verifying MySQL's network binding. Test thoroughly with the mysql client, and follow security best practices by limiting access to specific IPs and granting only necessary privileges. For sensitive environments, SSH tunneling provides an additional layer of encryption without exposing MySQL directly to the network. Regular audits of remote access lists and MySQL users ensure your database remains secure while providing the connectivity your applications need.

FAQ

How do I allow multiple IPs?

Add each IP individually in cPanel Remote MySQL. There's no limit to the number of trusted hosts. For firewall rules, add multiple entries or rules for each IP address.

Can I use a domain name instead of an IP?

cPanel Remote MySQL accepts domain names, but this is less reliable because MySQL resolves the hostname at connection time. If DNS changes or fails, connections break. IP addresses are more dependable.

Will this work with applications like WordPress?

Yes, if WordPress is hosted on a separate server from your MySQL database. Update wp-config.php with the remote database host, username, and password. Ensure the application server's IP is whitelisted.

Does remote access slow down MySQL?

Network latency will be higher than localhost connections, but the performance impact depends on your query patterns and network quality. For high-traffic applications, keep MySQL and the application on the same server or use connection pooling.

How do I remove remote access for an IP?

In cPanel Remote MySQL, click the Delete icon next to the IP address in the Access Hosts list. Also remove the corresponding firewall rule to fully close access.

Is remote MySQL access secure?

It's as secure as your configuration. Use strong passwords, whitelist only specific IPs, grant minimal privileges, and consider SSL/TLS for MySQL connections. For maximum security, use SSH tunneling instead of direct access.