Port 3306: MySQL and MariaDB
What it is, why it matters and how to restrict it.
The default port of MySQL and MariaDB. Databases should rarely be reachable from the whole internet, and automated scanners probe this port constantly.
Secure it
In the server config, the bind-address setting controls which interface listens; many distribution packages default it to 127.0.0.1. Create separate database users limited to specific hosts, and never leave the root account reachable remotely.
Allow only one address on Linux
sudo iptables -I INPUT 1 -p tcp --dport 3306 -j DROP sudo iptables -I INPUT 1 -p tcp -s 203.0.113.5 --dport 3306 -j ACCEPT
The drop rule goes in first and the allow rule is inserted above it, so 203.0.113.5 is matched first. Replace it with your own address. With ufw, the equivalent allow rule is:
sudo ufw allow from 203.0.113.5 to any port 3306 proto tcp
Check from outside
nc -vz SERVER_IP 3306
Run it from an allowed address and from another one. A connection should succeed from the first and fail or time out from the second. Build custom rules with allow a port from specific IPs, or see all common ports.
FAQ
What is port 3306 used for?
Port 3306 is the default TCP port of MySQL and MariaDB.
Should port 3306 be open to the internet?
Usually not. Keep it on localhost, behind a VPN, or limited to specific source IPs.
How do I block port 3306 for everyone except one IP?
Add an ACCEPT rule for that address, then a DROP rule for the port below it. The commands above do this in the correct order.