Plesk/Nginx/Ubuntu 16环境下外部MySQL连接被拒,需排查额外设置
Great question! Even after opening port 3306 in your firewall, there are two critical steps you need to complete to enable external MySQL connections in your Plesk/Ubuntu 16/Nginx environment, plus an optional Plesk-specific check for extra security:
By default, MySQL is locked down to only listen on the local loopback address (127.0.0.1), which means it won't accept connections from outside your server. Here's how to fix that:
- On Ubuntu 16.04, the primary MySQL configuration file lives at
/etc/mysql/mysql.conf.d/mysqld.cnf - Open it with a terminal editor (e.g.,
sudo nano /etc/mysql/mysql.conf.d/mysqld.cnf) - Find the line starting with
bind-address— it'll look like this:bind-address = 127.0.0.1 - Change its value to
0.0.0.0to allow MySQL to listen on all network interfaces:bind-address = 0.0.0.0 - Save the file and restart MySQL to apply the change:
sudo systemctl restart mysql
Even if MySQL is listening for external connections, your database user is probably only authorized to connect from localhost (the server itself). You need to update their privileges to allow external access:
- Log into MySQL as a root user (you can do this via Plesk's Database Management interface, or run
mysql -u root -pin the terminal and enter your root password) - Run this SQL command to grant full access from any IP address (replace
your_usernameandyour_passwordwith your actual user details):GRANT ALL PRIVILEGES ON *.* TO 'your_username'@'%' IDENTIFIED BY 'your_password';- For better security, replace
%with a specific IP address (e.g.,'192.168.1.100') if you only need to allow connections from one source
- For better security, replace
- Flush the privileges to make the change take effect right away:
FLUSH PRIVILEGES;
Plesk sometimes adds an extra layer of restriction for remote database access. To check:
- Log into your Plesk panel
- Go to Tools & Settings > Database Servers
- Select your MySQL server and click Settings
- Ensure "Allow remote connections from any host" is enabled (if you want open access)
- If you prefer restricted access, add specific IP addresses to the "Allowed hosts" list here instead of using the
%wildcard in your MySQL grant
After completing these steps, you should be able to connect to your MySQL server from an external client using your server's public IP, the authorized username, and password.
内容的提问来源于stack exchange,提问作者popkutt

