Core component of SQL Server for storing, processing, and securing data
Hi @orville wright ,
Since your SQL Server is running on a virtual machine, I would not recommend removing or disabling the firewall. The firewall is protecting the SQL Server from unauthorized network access.
Instead, configure SQL Server to use a fixed TCP port and create a firewall rule that allows that port only from the networks that should access the database.
If your users receive different IP addresses frequently, maintaining a separate firewall rule for every client IP can become difficult. In that case, consider having the users connect through a controlled network such as your organization’s VPN, and allow the appropriate network range instead of individual changing public IP addresses.
Also verify that TCP/IP is enabled in SQL Server Configuration Manager and confirm which TCP port the SQL Server instance is actually using. Named SQL Server instances can use dynamic ports unless a fixed port is configured.
So, in short:
- Do not remove the firewall.
- Enable TCP/IP for remote SQL Server connections.
- Configure a fixed SQL Server TCP port if needed.
- Allow that port only from trusted networks.
- If users' public IP addresses frequently change, consider VPN/private connectivity rather than continuously adding individual IP addresses.
FYR:
Configure Windows Firewall for SQL Server Database Engine access