You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

DigitalOcean Linux服务器Tomcat连接本地Windows MSSQL失败求助

Hey there, let's work through why your DigitalOcean Linux Tomcat server can't connect to your local Windows MSSQL database—since even ping and telnet to port 1433 are failing, this is almost definitely a network accessibility issue, not just a Tomcat or MSSQL config problem. Here's what you need to check and fix step by step:

1. Fix Local Windows Machine's Public Accessibility

Your Windows machine is behind a home/office router, which means it has a private IP (like 192.168.x.x) that's not reachable from the public internet where your DigitalOcean server lives. You need to set up two key things here:

  • Port Forwarding on Your Router

    • First, find your Windows machine's private IP: Open Command Prompt and run ipconfig—look for the IPv4 address under your active network adapter.
    • Next, find your public IP (the one the internet sees): Google "what's my IP" from your Windows machine.
    • Log into your router's admin panel (usually via 192.168.1.1 or similar, check your router's docs). Look for "Port Forwarding" or "Virtual Server" settings.
    • Create a rule to forward TCP port 1433 (MSSQL's default port) to your Windows machine's private IP. Save the settings.
    • Heads up: If your public IP starts with 100., 172.16-31, or 192.168, you're probably on CGNAT (Carrier-Grade NAT). This means your ISP doesn't assign you a true public IP, and port forwarding won't work. You'll need to ask your ISP for a static public IP or use a VPN service to bridge the connection.
  • Allow Incoming Connections in Windows Firewall

    • Even with port forwarding, Windows Firewall will block incoming traffic by default. Open Windows Defender Firewall > Advanced Settings > Inbound Rules.
    • Create a new rule:
      1. Select "Port" > Next
      2. Choose "TCP" and enter "1433" as the specific local port > Next
      3. Select "Allow the connection" > Next
      4. Check Domain, Private, and Public (adjust based on your network setup) > Next
      5. Name it something like "MSSQL Public Access" > Finish
    • Also, confirm MSSQL is listening on all network interfaces: Open SQL Server Configuration Manager > SQL Server Network Configuration > Protocols for [Your Instance] > TCP/IP > Properties. Go to the "IP Addresses" tab, scroll down to "IPAll", set "TCP Port" to 1433, and clear "TCP Dynamic Ports". Restart the SQL Server service after this change.
2. Verify DigitalOcean Server Network Settings
  • Check DigitalOcean Firewall Outgoing Rules
    By default, DigitalOcean firewalls allow all outgoing traffic, but it's worth double-checking:

    • Go to your DigitalOcean Dashboard > Firewalls > Select the firewall attached to your server.
    • Make sure there's an outgoing rule that allows TCP port 1433 to either "Anywhere" or specifically your public IP.
  • Retest Ping and Telnet
    After setting up port forwarding and firewall rules, go back to your Linux server and run these tests:

    • Ping your public IP: ping [your-public-ip] (Note: Some ISPs block ICMP/ping traffic, so if this fails but telnet works, that's normal—ping isn't required for MSSQL connectivity.)
    • Test telnet to port 1433: telnet [your-public-ip] 1433
      • If you get a blank screen with no errors, the network path is open. If you get "Connection refused" or "Timeout", go back to the port forwarding/firewall steps—something's still blocking the connection.
3. Tweak MSSQL Configuration
  • Enable TCP/IP Protocol
    In SQL Server Configuration Manager, make sure the TCP/IP protocol is enabled under "Protocols for [Your Instance]" (it's disabled by default for some installations). Restart the SQL Server service after enabling it.

  • Set Mixed Authentication Mode
    If you're using a SQL username/password to connect (not Windows authentication), ensure MSSQL allows this:

    • Open SQL Server Management Studio, right-click your server > Properties > Security.
    • Select "SQL Server and Windows Authentication mode" > OK.
    • Restart the SQL Server service to apply the change.
4. Double-Check Tomcat Connection String

Once the network is open, make sure your Tomcat JDBC connection string is correctly formatted. Here's an example:

jdbc:sqlserver://[your-public-ip]:1433;databaseName=YourDatabaseName;user=YourSqlUsername;password=YourSqlPassword;encrypt=true;trustServerCertificate=true;

The encrypt=true;trustServerCertificate=true part is crucial if you don't have a valid SSL certificate set up for MSSQL—without it, you might get SSL handshake errors even after fixing network connectivity.

If you've gone through all these steps and still run into issues, share the specific errors from your Tomcat logs or telnet attempts, and we can narrow it down further.


内容的提问来源于stack exchange,提问作者Rama Shankar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:53:11