Firewall, Proxy & SSH Tunnel
When DbSchema cannot reach your database, a network device is usually in the way. Find your symptom below and go straight to the fix.
| What you see | What blocks it | The fix |
|---|---|---|
| The connection times out, or the port is refused | A firewall on the server or in the cloud | Open the database port, or use an SSH tunnel |
| The database is private, and only a jump host is reachable | The network design, on purpose | Connect through an SSH tunnel |
| Driver downloads, updates, registration or AI fail | A company proxy | Set the proxy |
| Certificate or PKIX errors on downloads or registration | A proxy that inspects TLS | Trust your company's certificate |
| Could not establish a secure connection to an old SQL Server or MySQL | The server only speaks TLS 1.0 or 1.1 | Allow legacy TLS |
The proxy, certificate and SSH settings live in Edit → Settings → Network.
Check what answers
Before you change anything, find out how far the connection gets. Run these from the computer where DbSchema runs:
ping dbserver.example.com # the server answers at all
telnet dbserver.example.com 5432 # the database port is open
openssl s_client -connect dbserver.example.com:5432 # the port speaks TLS
If ping answers but telnet does not, a firewall blocks the port.
For a download or registration that fails, run check network <url> in DbSchemaCLI.
It prints the proxy and the certificates in use, tries the URL, and explains what went wrong.
Open the database port
A firewall on the database server may refuse connections from other computers. Open the port your database listens on. The usual ports are:
| Database | Port |
|---|---|
| PostgreSQL | 5432 |
| MySQL, MariaDB | 3306 |
| SQL Server | 1433 |
| Oracle | 1521 |
| MongoDB | 27017 |
If your database uses another port, put that number in the commands below. Allow only the addresses that need the database, rather than the whole internet.
Windows, in a Command Prompt opened as Administrator:
netsh advfirewall firewall add rule name="PostgreSQL 5432" dir=in action=allow protocol=TCP localport=5432
Linux, with the firewall tool of your distribution:
sudo ufw allow 5432/tcp # Ubuntu, Debian
sudo firewall-cmd --permanent --add-port=5432/tcp && sudo firewall-cmd --reload # RHEL, Fedora
Cloud databases, such as Amazon RDS, Azure SQL or Google Cloud SQL, have their own firewall. Add an inbound rule for your IP address in the provider's security group or network settings.
The database must also listen for remote connections.
PostgreSQL sets this with listen_addresses, and MySQL with bind-address.
Connect through an SSH tunnel
An SSH tunnel reaches a database that only a jump host can talk to. DbSchema connects to the SSH server, and the SSH server connects to the database. The database port stays closed to everyone else.
- Open the connection dialog, and its Advanced tab.
- Press the pencil next to Configuration, under SSH Tunnel.
- Press +, then type a Name, the SSH server's Host and its Port.
- Choose how to sign in: Password authentication, Public key authentication, SSH agent authentication or No authentication.
- Press Test Tunnel, then Close.
- Choose the configuration in the Configuration list.
On the Connection tab, type the database host and port as the SSH server sees them.
That is often localhost, when the database runs on the SSH server itself.
The connection page explains each sign-in method.
DbSchema forwards the database through a port on your own computer. That port is the Local Port in Edit → Settings → Network → SSH. Change it if another program already uses it.
Connect through a company proxy
A proxy is a server that your company's internet traffic goes through. DbSchema uses the proxy for everything it does online: driver downloads, update checks, registration, AI, Git and bug reports.
- Choose Edit → Settings → Network → Proxy.
- Press the pencil next to System Proxy.
- Press + to add a configuration, and type a Name.
- Choose Auto-detect proxy settings or Manual proxy configuration, and fill in its fields.
- Press Close, choose the configuration in System Proxy, and press OK.
- Auto-detect proxy settings takes the proxy from your operating system or the usual proxy environment variables. Use automatic configuration URL takes it from a PAC file instead.
- Manual proxy configuration takes a Protocol (HTTP or SOCKS), a Host name and a Port number.
- Proxy authentication holds the Login and Password, if the proxy asks for them.
Automatic detection and PAC files carry no login. If your proxy asks for one, configure it manually.
Bypass the proxy for internal hosts
No proxy for lists the hosts DbSchema reaches directly, one pattern per line. Internal database servers usually belong here, so their traffic never leaves your network.
| Pattern | Matches |
|---|---|
example.com, .example.com | that domain and every subdomain of it, never notexample.com |
*.example.com | the subdomains of example.com, but not example.com itself |
db*.example.* | * stands for any characters, dots included |
* | every host |
<local> | every host whose name has no dot and is not an IP address |
10.1.2.3, ::1 | that address, however it is written |
10.0.0.0/8, fd00::/8 | every address in that block |
any of the above, plus :8080 | the same, only for connections to that port |
Matching ignores letter case. An address pattern matches only a host that is already written as an IP address.
Trust your company's certificate
Some proxies open encrypted traffic to inspect it. They replace each site's certificate with one of their own, signed by your company. DbSchema refuses that certificate until you tell it to trust your company.
- Choose Edit → Settings → Network → SSL Certificates.
- Keep Custom Trust selected, and tick the sources to trust.
- Press OK, and restart DbSchema.
- Trust JVM: the certificate authorities bundled with DbSchema.
- Trust OS: the authorities your operating system trusts. A company certificate installed on your computer is usually here already.
- Trust Custom Certificates: certificate files you add with +. Use it when you have the company certificate only as a file.
- Trust All Certificates accepts every certificate, an attacker's too. Use it only for a short test.
Allow an old server's TLS
TLS is the encryption of a connection. Old servers, such as SQL Server 2012 without its updates, speak only TLS 1.0 or 1.1, which DbSchema refuses.
The best fix is to update the server so that it speaks TLS 1.2. If you cannot, tick Allow Legacy TLS Algorithms on the same page and restart DbSchema. It lowers the security of every connection DbSchema makes, so turn it on only for such a server.
Common problems
DbSchema still fails after I opened the firewall
The usual causes are a wrong host or port, a database that listens only on localhost, a user that may not connect from your computer, or a cloud firewall that still blocks the traffic.
Check them in that order.
Does the proxy apply to my database connections too?
It applies to every connection that asks Java for a proxy, the JDBC drivers included. A driver that opens its own network connections ignores it. For a database that must stay private, use an SSH tunnel.
My SOCKS proxy rejects the password
A detected proxy has no place for a login, so the proxy answers as if the password were wrong. Configure the proxy manually and tick Proxy authentication.