如何轻松实现CentOS下MySQL远程连接,提升工作效率?

更新于
2026-09-29 13:21:03
2阅读来源:SEO基础
  • 内容介绍
  • 文章标签
  • 相关推荐
其实,

在 CentOS 程序下配置 MySQL 远程连接。明明是个基础操作,却常让人“栽”得体无完肤。最近工作中就遇到这个需求,**足足折腾了一个多小时**才把远程连接搞定——明明只是改个配置、开个端口、建个使用者,偏偏每一步都暗藏坑:配置文件里的 bind-address 不改不行。防火墙不放行连不上,用 root 账号直连又被拒之门外生产环境还得时刻提心吊胆端口安全…,

别再让这些“小问题”偷走你的宝贵时间了!

如何轻松实现CentOS下MySQL远程连接,提升工作效率?

再看痛点直击,为什么你的远程连接总“不成功”?其实,

  • 默认“闭门造车”: MySQL 默认只监听 127.0.0.1。外部 IP 压根连不进来。
  • 防火墙“拦路虎”: CentOS 自带 firewalld/iptables 默认封锁 3306 端口,不开放等于白搭。
  • 权限“硬伤”: 账号只允许本地登录,远程访问直接报错 Access denied 或 Host not allowed
  • 安全“隐患”: 生产环境直接暴露 root 账号和默认端口?那是裸奔,事后忘记关端口更是后患无穷。

再看第一步先,修改 MySQL 配置——打开“大门”的钥匙

主要痛点:"配置文件到底在哪?bind-address 改成啥?改完咋不生效,"

  1. /etc/my.cnf或/etc/mysql/mysql.conf.d/mysqld.cnf`。怎么说呢,执行 `vim /etc/my.cnf`打开。
  2. li找到 区域下的 bind-address 行: pre class="config-snippet"># 默认可能是 bind-address = localhost 或 bind-address =::ffff:127 .0..0..1 # 若找不到该行。请在 区域下手动添加: bind-address =::ffff::ffff::ffff::ffff /pre li强调说明 :设为

h2接下来的观点是,防火墙放行——别让数据包“撞墙”/h pstrong主要痛点 :"到底是用 firewalld 呢还是 iptables? 规则加了为啥重启就没了,"/pp目前主流 CentOS 均使用 firewalld。建议使用永久生效规则:/p ol class="steps" li打开&永久生效&标签打开3306/tcp端口: pre class="cmd-snippet">sudo firewall-cmd --permanent --zone=public --add-port=3306/tcp success # 提示 success sudo firewall-cmd --reload /pre /li li若服务器仍用 iptables: pre class="cmd-snippet">iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport3306 -j ACCEPT service iptables save # 持久化 /pre /li strong安全警醒 :生产环境建议仅授信特定 IP 段,而非全网放行!按理说,从命令示例来看,pre class="cmd-snippet">sudo firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="YOUROFFICEIP/24" port protocol="tcp" port="3306" accept' sudo firewall-cmd --reload /pre /ol

如何轻松实现CentOS下MySQL远程连接,提升工作效率?

usertd刚创建的专用账号/trpassword强密码勿泄露SERVERIP-u remoteuser-pEnter password: yourpasswordmysqlSHOW DATABASES;exit,prelip成功看到数据库列表即大功告成!

.article-container{max-width:900px;margin:auto,font-family:-apple-systemBlinkMacSystemFont"Segoe UI"RobotoHelveticaNeueArial sans-serif;line-height:.8color:#d} h{color:#b;老实说,border-bottom:solid px #ee;padding-bottom:.rem;margin-top:.rem}h{color:#44;margin-top:.5rem} intro-section{background:#fffbeb;border-left:px solid #fb;按理说,padding:.rem;margin-bottom:.rem;不过,border-radius:.rem} pain-points{background:#fefr;padding:.rem;老实说,border-radius:.remborder:solid px #fecaca} pain-points li{margin-bottom:.rem} steps{padding-left:.rem} steps li{margin-bottom:.5rem} cmd-snippetconfig-snippet{background:#fdpadding:.remborder-radius:.removerflow-x:autofont-size:.9remfont-family:"Fira Code""Consolas""Monospace"} cmd-snippet code{background:none;padding:inheritfont-family:inheritcolor:#e9c}.comparison-table{width:%border-collapse:collapsemargin-top:.remfont-size:.9r}.comparison-table th.comparison-table td{border:solid px #eepadding:.5retext-align:left}.comparison-table th{background:#fafafa}.conclusion{background:#fdfdfpadding:border-radius:border:solid px #bbbtmargin-top:r}`;

标签:CentOS
其实,

在 CentOS 程序下配置 MySQL 远程连接。明明是个基础操作,却常让人“栽”得体无完肤。最近工作中就遇到这个需求,**足足折腾了一个多小时**才把远程连接搞定——明明只是改个配置、开个端口、建个使用者,偏偏每一步都暗藏坑:配置文件里的 bind-address 不改不行。防火墙不放行连不上,用 root 账号直连又被拒之门外生产环境还得时刻提心吊胆端口安全…,

别再让这些“小问题”偷走你的宝贵时间了!

如何轻松实现CentOS下MySQL远程连接,提升工作效率?

再看痛点直击,为什么你的远程连接总“不成功”?其实,

  • 默认“闭门造车”: MySQL 默认只监听 127.0.0.1。外部 IP 压根连不进来。
  • 防火墙“拦路虎”: CentOS 自带 firewalld/iptables 默认封锁 3306 端口,不开放等于白搭。
  • 权限“硬伤”: 账号只允许本地登录,远程访问直接报错 Access denied 或 Host not allowed
  • 安全“隐患”: 生产环境直接暴露 root 账号和默认端口?那是裸奔,事后忘记关端口更是后患无穷。

再看第一步先,修改 MySQL 配置——打开“大门”的钥匙

主要痛点:"配置文件到底在哪?bind-address 改成啥?改完咋不生效,"

  1. /etc/my.cnf或/etc/mysql/mysql.conf.d/mysqld.cnf`。怎么说呢,执行 `vim /etc/my.cnf`打开。
  2. li找到 区域下的 bind-address 行: pre class="config-snippet"># 默认可能是 bind-address = localhost 或 bind-address =::ffff:127 .0..0..1 # 若找不到该行。请在 区域下手动添加: bind-address =::ffff::ffff::ffff::ffff /pre li强调说明 :设为

h2接下来的观点是,防火墙放行——别让数据包“撞墙”/h pstrong主要痛点 :"到底是用 firewalld 呢还是 iptables? 规则加了为啥重启就没了,"/pp目前主流 CentOS 均使用 firewalld。建议使用永久生效规则:/p ol class="steps" li打开&永久生效&标签打开3306/tcp端口: pre class="cmd-snippet">sudo firewall-cmd --permanent --zone=public --add-port=3306/tcp success # 提示 success sudo firewall-cmd --reload /pre /li li若服务器仍用 iptables: pre class="cmd-snippet">iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport3306 -j ACCEPT service iptables save # 持久化 /pre /li strong安全警醒 :生产环境建议仅授信特定 IP 段,而非全网放行!按理说,从命令示例来看,pre class="cmd-snippet">sudo firewall-cmd --permanent --zone=public --add-rich-rule='rule family="ipv4" source address="YOUROFFICEIP/24" port protocol="tcp" port="3306" accept' sudo firewall-cmd --reload /pre /ol

如何轻松实现CentOS下MySQL远程连接,提升工作效率?

usertd刚创建的专用账号/trpassword强密码勿泄露SERVERIP-u remoteuser-pEnter password: yourpasswordmysqlSHOW DATABASES;exit,prelip成功看到数据库列表即大功告成!

.article-container{max-width:900px;margin:auto,font-family:-apple-systemBlinkMacSystemFont"Segoe UI"RobotoHelveticaNeueArial sans-serif;line-height:.8color:#d} h{color:#b;老实说,border-bottom:solid px #ee;padding-bottom:.rem;margin-top:.rem}h{color:#44;margin-top:.5rem} intro-section{background:#fffbeb;border-left:px solid #fb;按理说,padding:.rem;margin-bottom:.rem;不过,border-radius:.rem} pain-points{background:#fefr;padding:.rem;老实说,border-radius:.remborder:solid px #fecaca} pain-points li{margin-bottom:.rem} steps{padding-left:.rem} steps li{margin-bottom:.5rem} cmd-snippetconfig-snippet{background:#fdpadding:.remborder-radius:.removerflow-x:autofont-size:.9remfont-family:"Fira Code""Consolas""Monospace"} cmd-snippet code{background:none;padding:inheritfont-family:inheritcolor:#e9c}.comparison-table{width:%border-collapse:collapsemargin-top:.remfont-size:.9r}.comparison-table th.comparison-table td{border:solid px #eepadding:.5retext-align:left}.comparison-table th{background:#fafafa}.conclusion{background:#fdfdfpadding:border-radius:border:solid px #bbbtmargin-top:r}`;

标签:CentOS