Firewall, Proxy & SSH Tunnel

When DbSchema cannot reach your database, a network device is usually in the way. Find your symptom below and go straight to the fix.

What you seeWhat blocks itThe fix
The connection times out, or the port is refusedA firewall on the server or in the cloudOpen the database port, or use an SSH tunnel
The database is private, and only a jump host is reachableThe network design, on purposeConnect through an SSH tunnel
Driver downloads, updates, registration or AI failA company proxySet the proxy
Certificate or PKIX errors on downloads or registrationA proxy that inspects TLSTrust your company's certificate
Could not establish a secure connection to an old SQL Server or MySQLThe server only speaks TLS 1.0 or 1.1Allow legacy TLS
DbSchema Settings with Network open: the Proxy, SSL Certificates and SSH pages, and the System Proxy set to Default Automatic

The proxy, certificate and SSH settings live in Edit → Settings → Network.

Check what answers

Before you change anything, find out how far the connection gets. Run these from the computer where DbSchema runs:

ping dbserver.example.com                                  # the server answers at all
telnet dbserver.example.com 5432                           # the database port is open
openssl s_client -connect dbserver.example.com:5432        # the port speaks TLS

If ping answers but telnet does not, a firewall blocks the port. For a download or registration that fails, run check network <url> in DbSchemaCLI. It prints the proxy and the certificates in use, tries the URL, and explains what went wrong.

Open the database port

A firewall on the database server may refuse connections from other computers. Open the port your database listens on. The usual ports are:

DatabasePort
PostgreSQL5432
MySQL, MariaDB3306
SQL Server1433
Oracle1521
MongoDB27017

If your database uses another port, put that number in the commands below. Allow only the addresses that need the database, rather than the whole internet.

Windows, in a Command Prompt opened as Administrator:

netsh advfirewall firewall add rule name="PostgreSQL 5432" dir=in action=allow protocol=TCP localport=5432

Linux, with the firewall tool of your distribution:

sudo ufw allow 5432/tcp                                                       # Ubuntu, Debian
sudo firewall-cmd --permanent --add-port=5432/tcp && sudo firewall-cmd --reload  # RHEL, Fedora

Cloud databases, such as Amazon RDS, Azure SQL or Google Cloud SQL, have their own firewall. Add an inbound rule for your IP address in the provider's security group or network settings.

The database must also listen for remote connections. PostgreSQL sets this with listen_addresses, and MySQL with bind-address.

Connect through an SSH tunnel

An SSH tunnel reaches a database that only a jump host can talk to. DbSchema connects to the SSH server, and the SSH server connects to the database. The database port stays closed to everyone else.

  1. Open the connection dialog, and its Advanced tab.
  2. Press the pencil next to Configuration, under SSH Tunnel.
  3. Press +, then type a Name, the SSH server's Host and its Port.
  4. Choose how to sign in: Password authentication, Public key authentication, SSH agent authentication or No authentication.
  5. Press Test Tunnel, then Close.
  6. Choose the configuration in the Configuration list.
The SSH configuration Office bastion: host bastion.example.com, port 22, Public key authentication with user deploy and a private key file

On the Connection tab, type the database host and port as the SSH server sees them. That is often localhost, when the database runs on the SSH server itself. The connection page explains each sign-in method.

DbSchema forwards the database through a port on your own computer. That port is the Local Port in Edit → Settings → Network → SSH. Change it if another program already uses it.

DbSchema Settings, Network, SSH: the Local Port set to 3373

Connect through a company proxy

A proxy is a server that your company's internet traffic goes through. DbSchema uses the proxy for everything it does online: driver downloads, update checks, registration, AI, Git and bug reports.

  1. Choose Edit → Settings → Network → Proxy.
  2. Press the pencil next to System Proxy.
  3. Press + to add a configuration, and type a Name.
  4. Choose Auto-detect proxy settings or Manual proxy configuration, and fill in its fields.
  5. Press Close, choose the configuration in System Proxy, and press OK.
The proxy configuration Company proxy: Manual proxy configuration, HTTP, host proxy.example.com, port 80, and three No proxy for patterns
  • Auto-detect proxy settings takes the proxy from your operating system or the usual proxy environment variables. Use automatic configuration URL takes it from a PAC file instead.
  • Manual proxy configuration takes a Protocol (HTTP or SOCKS), a Host name and a Port number.
  • Proxy authentication holds the Login and Password, if the proxy asks for them.

Automatic detection and PAC files carry no login. If your proxy asks for one, configure it manually.

Bypass the proxy for internal hosts

No proxy for lists the hosts DbSchema reaches directly, one pattern per line. Internal database servers usually belong here, so their traffic never leaves your network.

PatternMatches
example.com, .example.comthat domain and every subdomain of it, never notexample.com
*.example.comthe subdomains of example.com, but not example.com itself
db*.example.** stands for any characters, dots included
*every host
<local>every host whose name has no dot and is not an IP address
10.1.2.3, ::1that address, however it is written
10.0.0.0/8, fd00::/8every address in that block
any of the above, plus :8080the same, only for connections to that port

Matching ignores letter case. An address pattern matches only a host that is already written as an IP address.

Trust your company's certificate

Some proxies open encrypted traffic to inspect it. They replace each site's certificate with one of their own, signed by your company. DbSchema refuses that certificate until you tell it to trust your company.

  1. Choose Edit → Settings → Network → SSL Certificates.
  2. Keep Custom Trust selected, and tick the sources to trust.
  3. Press OK, and restart DbSchema.
DbSchema Settings, Network, SSL Certificates: Custom Trust with Trust JVM and Trust OS ticked, Trust All Certificates, and Allow Legacy TLS Algorithms
  • Trust JVM: the certificate authorities bundled with DbSchema.
  • Trust OS: the authorities your operating system trusts. A company certificate installed on your computer is usually here already.
  • Trust Custom Certificates: certificate files you add with +. Use it when you have the company certificate only as a file.
  • Trust All Certificates accepts every certificate, an attacker's too. Use it only for a short test.

Allow an old server's TLS

TLS is the encryption of a connection. Old servers, such as SQL Server 2012 without its updates, speak only TLS 1.0 or 1.1, which DbSchema refuses.

The best fix is to update the server so that it speaks TLS 1.2. If you cannot, tick Allow Legacy TLS Algorithms on the same page and restart DbSchema. It lowers the security of every connection DbSchema makes, so turn it on only for such a server.

Common problems

DbSchema still fails after I opened the firewall

The usual causes are a wrong host or port, a database that listens only on localhost, a user that may not connect from your computer, or a cloud firewall that still blocks the traffic. Check them in that order.

Does the proxy apply to my database connections too?

It applies to every connection that asks Java for a proxy, the JDBC drivers included. A driver that opens its own network connections ignores it. For a database that must stay private, use an SSH tunnel.

My SOCKS proxy rejects the password

A detected proxy has no place for a login, so the proxy answers as if the password were wrong. Configure the proxy manually and tick Proxy authentication.

Next steps