办公网络无法访问远程MySQL(3306端口),外网可正常访问
Let's break down why your remote MySQL database works fine outside your office network but fails when you're on the office LAN, using the nmap results you shared as a starting point.
Your Nmap Scan Results
Office Network Scan:
nmap -p 3306 <hostname> Host is up (0.0020s latency). PORT STATE SERVICE 3306/tcp closed mysql
External Network Scan:
nmap -p 3306 <hostname> Host is up (X.Xs latency). PORT STATE SERVICE 3306/tcp open mysql
Step-by-Step Troubleshooting
1. Check Remote Host Firewall/Security Group Rules
The most likely issue is that your remote MySQL server's firewall (or cloud security group, if hosted on AWS/Azure/GCP) only allows connections from non-office IP ranges.
- Log into your remote server or cloud console, and review the inbound rules for port 3306.
- Verify if your office network's public IP (or internal IP range, if applicable) is included in the allowed list. If it's missing, add it to permit traffic from your office.
2. Verify Office Network Outbound Restrictions
Many companies block outbound traffic to common database ports (like 3306) as a security measure to prevent unauthorized external connections.
- Reach out to your company's network administrator and ask:
- Is there an outbound firewall rule blocking traffic to port 3306?
- Has the remote MySQL server's IP been added to a blocked list?
- If this is the case, you might need to request an exception, or use a approved VPN/tunnel to bypass the restriction.
3. Check DNS Resolution Discrepancies
Office networks often use internal DNS servers that resolve hostnames to local IPs instead of public ones. This would make you attempt to connect to a local machine (without MySQL on 3306) instead of the remote server.
- On your office machine, run:
ping <hostname> nslookup <hostname> - Compare the returned IP address with the one you get from an external network. If they don't match, your office DNS is hijacking the hostname—use the direct public IP of the MySQL server, or ask your admin to fix the DNS record.
4. Diagnose Routing/NAT Issues
Complex office network setups (with routing or NAT) can sometimes block or misdirect traffic to external servers.
- Use traceroute (Linux/macOS) or tracert (Windows) to track your traffic's path:
- Linux/macOS:
traceroute <hostname> -p 3306 - Windows:
tracert -d <hostname>
- Linux/macOS:
- Compare this output with results from an external network. If the office trace stops at a company router/gateway, that's likely where traffic is being blocked.
5. Double-Check MySQL User Permissions (Less Likely)
While your nmap "closed" status points to a network-level issue, it's worth confirming your MySQL user isn't restricted to specific external IPs.
- Log into your MySQL server and run:
SELECT user, host FROM mysql.user; - Ensure your user has a host value of
%(allowing any IP) or includes your office network's IP range. If not, update permissions with:GRANT ALL PRIVILEGES ON your_database.* TO 'your_user'@'office_ip_range' IDENTIFIED BY 'your_password'; FLUSH PRIVILEGES;
Start with steps 1 and 2 first—those are the most probable causes for the "closed" port status in your office network. Once you rule those out, move on to the other checks.
内容的提问来源于stack exchange,提问作者Deepika Rathore

