Knowledge Base

Can I tunnel to a different host?

Overview

This article explains how to configure a scan when your database is not on the same machine as your web server. By the end, you will know when tunneling applies, which two addresses you need — the External Database Hostname or IP and the Internal Database Hostname or IP — and how to enter them using the Databases hosted on an internal server? option. It also covers how to confirm the connection works and what to check if it does not. Tunneling here means connecting to the internal database indirectly, through a reachable web server or Secure Shell (SSH) host that acts as the entry point.

What is tunneling to a different host?

Tunneling to a different host means the scan does not connect to your database directly. Instead, it connects to a server that is publicly reachable — your web server or Secure Shell (SSH) host — and that server passes the connection through to the database on your private internal network. This is required when the database has no public address of its own, such as a server on a private range like 10.0.0.1.

Prerequisites

Before you start, make sure you have:

  • The public-facing address of the server that is reachable from the internet — the External Database Hostname or IP.
  • The private address of the database server on your internal network — the Internal Database Hostname or IP.
  • Confirmation from your hosting provider that they configure database connections this way. If you are not sure, contact your hosting provider before continuing.

Steps

Follow these steps in the scan configuration screen.

  1. Open the database connection settings for the scan you want to configure.
  2. Select Databases hosted on an internal server?. Additional address fields appear.
  3. In External Database Hostname or IP, enter the public-facing address of the web server or SSH host.
     
    Figure 1: Database connection settings with the Databases hosted on an internal server option selected

  4. In Internal Database Hostname or IP, enter the private address of the database server, for example 10.0.0.1.
  5. Enter the remaining database connection details as normal, then save the configuration.

    Figure 2: External and Internal Database Hostname or IP fields ready for the two required addresses

How to Verify Success

The configuration is correct when the saved scan connects to the database and returns results instead of a connection error. If the scan reports that the database host is unreachable, the addresses have not been accepted.

Troubleshooting

Issue: The scan cannot reach the database host.

Cause: The external address is not publicly reachable, or the internal address is wrong.

Solution: Confirm both addresses with your hosting provider, then re-enter them in the two fields and save again.

Issue: The Databases hosted on an internal server? option does not produce the expected result.

Cause: The hosting provider does not configure database connections through a web server or SSH host.

Solution: Contact your hosting provider to confirm how your database connection is configured. This method only applies to hosts that use it.

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today