SSH & Terminal Access

Securing MySQL Access with SSH Tunnels: A Guide for Popular SQL Clients Across Different Operating Systems

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (8 sections)

To use MySQL Workbench, DBeaver, HeidiSQL or another desktop SQL client with a database on Domain India shared hosting, you connect through an SSH tunnel. Port 3306 is closed to outside connections on our shared servers, so the client reaches MySQL through your SSH login on port 22 instead. This page gives the exact settings for each popular client on Windows, macOS and Linux.

The full tunnel guide

For how a tunnel works, the manual ssh -L command and troubleshooting, see Securing MySQL access with SSH tunnels: a comprehensive guide.

Key takeaways

Ask support to enable jailed SSH on your hosting account: it is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo) and is off by default. SSH login uses a key, not a password, so add your public key first. In your SQL client, choose the SSH tunnel option: SSH host = your server IP, port 22, your hosting username and your private key file; MySQL host = 127.0.0.1, port 3306, with your database user and password.

1. What you need before you start

  1. Jailed SSH enabled.
    Ask support by live chat or a ticket at /client/support/new. Windows (Plesk) hosting has no SSH, so this guide does not apply to it.
  2. An SSH key added to your account.
    Password login over SSH is switched off on our cPanel and DirectAdmin servers, and you should use a key on Webuzo too. See how to generate SSH keys and SSH key authentication setup.
  3. Your SSH details.
    Your hosting username and server IP are on the Access tab: open /client/services/hosting, click Manage and open Access.
  4. Your database details.
    Database name, user and password, including the account prefix (for example acme_shop). See how to connect to the MySQL database.

Adding your IP address under Remote Database Access does not open port 3306 in the server firewall, so it does not replace the tunnel.

2. The settings every client needs

PartFieldValue
SSHHostYour server IP from the Access tab
SSHPort22
SSHUsernameYour hosting (control panel) username
SSHAuthenticationPublic key: your private key file, and its passphrase
MySQLHost127.0.0.1
MySQLPort3306
MySQLUsername and passwordYour database user, with prefix, and its password

The MySQL host is 127.0.0.1 because, once the tunnel is open, the connection arrives at MySQL from the server itself.

3. MySQL Workbench (Windows, macOS, Linux)

  1. Click + next to MySQL Connections and give the connection a name.
  2. Set Connection Method to Standard TCP/IP over SSH.
  3. SSH Hostname: your server IP followed by :22. SSH Username: your hosting username. SSH Key File: your private key.
  4. MySQL Hostname: 127.0.0.1, MySQL Server Port: 3306, Username: your database user.
  5. Click Test Connection, enter the database password (and your key's passphrase if asked), then save.

Workbench works best with an OpenSSH-format key. If you only have a PuTTY .ppk file, export an OpenSSH copy in PuTTYgen with Conversions › Export OpenSSH key.

4. DBeaver (Windows, macOS, Linux)

  1. Choose New Database Connection, then MySQL.
  2. On the Main tab, set Server Host to 127.0.0.1, Port to 3306, and enter your database name, user and password.
  3. Open the SSH tab and tick Use SSH Tunnel. Enter your server IP, port 22 and your hosting username, set Authentication Method to Public Key and select your private key file.
  4. Click Test Connection, then Finish.

5. HeidiSQL (Windows)

  1. Click New to create a session and set Network type to MySQL (SSH tunnel).
  2. On the Settings tab, set Hostname / IP to 127.0.0.1, port 3306, and enter your database user and password.
  3. On the SSH tunnel tab, enter your server IP, port 22, your hosting username and your private key file. HeidiSQL runs an external SSH program for the tunnel: plink.exe from PuTTY, or ssh.exe in recent versions. Point it at one if asked; with plink.exe, use a .ppk key.
  4. Click Open.

6. Any other client: open the tunnel yourself

If your client has no SSH option, open the tunnel from a terminal and leave it running:

bash
ssh -N -L 3307:localhost:3306 yourusername@your-server-ip

This works in Terminal on macOS and Linux and in PowerShell on Windows 10 and 11. Then connect the client to host 127.0.0.1, port 3307. Using 3307 locally avoids a clash with any MySQL server on your own computer. In PuTTY, add the same tunnel under Connection › SSH › Tunnels: source port 3307, destination localhost:3306, then Add. Press Ctrl+C or close PuTTY to end the tunnel.

Close the tunnel when you finish

Do not set a tunnel to start automatically every time you open a terminal. An open tunnel is an open path from your computer to the database. Open it when you need it and close it afterwards. Never add % under Remote Database Access; a tunnel does not need it.

7. Quick troubleshooting

  • SSH step fails with "Permission denied (publickey)": SSH is not enabled yet, the public key is not on the account, or the client is using the wrong key file or username.
  • SSH works but MySQL says "Access denied": the database user, password or prefix is wrong. Check them by logging in to phpMyAdmin.
  • "Address already in use" with a manual tunnel: pick another local port, such as 3308.
  • Direct connection to port 3306 times out: that is expected. Use the tunnel.

8. Where Domain India fits

Every cPanel, DirectAdmin and Webuzo plan includes MySQL databases, phpMyAdmin and jailed SSH on request, so any of them works with these clients. Prices on the card are live and exclude 18% GST.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

If you need MySQL open to other servers or full control of the database server, a VPS gives you root access.

How do I connect MySQL Workbench to Domain India shared hosting?

Use the Standard TCP/IP over SSH connection method. The SSH part uses your server IP on port 22, your hosting username and your private key file; the MySQL part uses 127.0.0.1, port 3306 and your database login. SSH must first be enabled on your account by support.

Why can't I connect directly to port 3306?

Port 3306 is closed to outside connections on our shared servers. Adding your IP under Remote Database Access does not open it. Connect through an SSH tunnel on port 22 instead.

Can I use a password for the SSH part of the tunnel?

No. Password login over SSH is switched off on our cPanel and DirectAdmin servers. Choose public key authentication and select your private key file.

Which host and port do I enter for MySQL in the client?

127.0.0.1 and port 3306 when the client builds the tunnel itself. If you open the tunnel yourself with ssh -L 3307:localhost:3306, connect to 127.0.0.1 on port 3307.

Does this work with Windows hosting?

No. Domain India's Windows (Plesk) hosting has no SSH, so there is nothing to tunnel through.

Ready to connect? Ask support to enable jailed SSH on your account, then follow the comprehensive SSH tunnel guide if you need more detail.

Want SSH enabled for a database tunnel?

Tell us your domain and that you need an SSH tunnel to MySQL. Support switches on jailed SSH for your account and confirms when it is ready.

Ask support to enable it

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app