I have set up a SSH tunnel between two servers A and B. B has MySQL server, and this works:
mysql -h localhost -P 3306 -u user -p
While this doesn't:
mysql -h 127.0.0.1 -P 3306 -u user -p
Although my.cnf has these lines:
bind-address = 127.0.0.1
# Next addr differs slightly, but anyway
bind-address = 99.99.99.99
Now about the tunnel. It connects the following:(A) localhost(9989) -> (B) localhost(3306)
But when (on A, with ports forwarded) I do
mysql -v -h 127.0.0.1 -P 9989 -u user userdb -p
I get ERROR 2013 (HY000): Lost connection to MySQL server at 'reading initial communication packet', system error: 0
And when I do
mysql -v -h localhost -P 9989 -u user userdb -p
I get ERROR 1045 (28000): Access denied for user 'user'@'localhost' (using password: YES)
What might be the reason? What am I doing wrong?
There are three issues here.
1 - Forget about the SSH tunnel for now
You cannot bind MySQL to more than one specific IP. The first
bind-address
clause is overridden (therefore, ignored) by the second one. Your server only listens to99.99.99.99
.The reason why you can connect with
-h localhost
but not with-h 127.0.0.1
is that in the first form, you do not actually connect through TCP/IP, but through a local socket.Look in your
my.cnf
for asocket
clause.Remove one redundant
bind-address
clause. You may want to usebind-address=0.0.0.0
, which instructs MySQL daemon to listen to all network interfaces.2 - Let's setup your SSH tunnel
The reason for you error
ERROR 2013 (HY000): Lost connection to MySQL server at 'reading initial communication packet', system error: 0
is not obvious to me. I suspect SSH tunnel is actually established only when it receives a connection request (in your case, when you run themysql
client). Since your server does not listen to 127.0.0.1 (see previous paragraph), the SSH tunnel cannot be established, connection fails, and your client interprets it as a network failure.3 - Why
mysql -v -h localhost -P 9989 -u user userdb -p
failsPlease post the output of
[edit : just added
...OR host LIKE 'localhost'
below, as this might be relevant for troubleshooting purposes](replace
'user'
, after theLIKE
clause, with the actual user name if necessary)MySQL access control checks both the username/password (
user
) and the origin of the connection (host
) to identify a user. You probably did not create a user'user'@'localhost'
.N.B.: mysql.com being unreachable from my location at this time, I cannot link to the relevant manual pages.
I just encountered this very problem.
In my case MySQL server is configured with
bind-address: 192.168.4.4
. I originally setup an SSH tunnel with a commonly mentioned-L 3306:localhost:3306 user@server
string and from my computer connect withmysql -h 127.0.0.1
.This does not work because MySQL no longer listens on 0.0.0.0 or even
"localhost"
(aka 127.0.0.1), only192.168.4.4
.The correct tunnel string should be
-L 3306:192.168.4.4:3306 user@server
. This will tell the remote tunnel end to connect to MySQL using the IP MySQL actually listens on.A simple step worked for me... I'll share this, so maybe some of you can be spared a headache.
MY SETTING
In my particular case, I have a Percona server running on Ubuntu, connected to MySQL Workbench (in a Windows VM) through SSH; the server ran fine for several days before spitting an error 10060 while processing a query.
WHAT WORKED FOR ME
I found in a forum from Acquia.com that in some cases the Workbench won't accept '127.0.0.1' as host, so you must change it to 'localhost'. I did it, and it worked (oddly, the Workbench asked for the passwords again, even if they were already stored, but worked nevertheless).
STEP-BY-STEP SSH TUNNELING
--- SERVER SIDE ----
in target machine (that can be addresed by IP or a domain hosted) there is config file /etc/mysql/my.cnf having a line
confirmed with console
which means mysql server will respond only to request from the localhost
--- CLIENT SIDE ----
you have an account (eventualy a ssh-key) to log using cygwin,putty or a linux_shell
create SSH TUNNEL
which means hey ssh create a permanent connection from port 1000 on the machine that I type (client) to remote host_name:3306 .... 127.0.0.1 means here the remote (host_name) and should not be replaced with localhost word because this will make the connection on unix (named) socket not by IP ... You'll get 'ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysql.sock' (2)' when trying co connect mysql
-f = go in background -N = no excution
both -f -N kind of nohoop - you can close console and tunnels persist
--- SERVER SIDE ---
which means there is a permanent connection through shh protocol
--- CLIENT SIDE ---
now your (client side) mysql client is conected to remote mysql server ... here 127.0.0.1 is client machine
same for workbench, heidiSQL
how to kill ssh tunnels
In my case, a configuration in the SSH daemon was blocking the tunnel. AllowTcpForwarding should be enabled.
I did have the same proble (
"Lost connection..."
) on Windows (while using ssh tunnel via Putty). I got 2 issues here:Putty: Connection > SSH > Tunnels > Local ports accept connections from other hosts