firewall rule preventing user login

orville wright 0 Reputation points
2026-09-30T16:28:53.53+00:00

I have a sql database "LIMLdb" running on "apgsystems01" sql server running on a virtual machine. I need to be able to have my users log in from different locations. When they try the are assigned a new ip and cannot log in until I go into security/networking and add the client address as it is a firewall rule. Is there a way this rule can be removed, is there another way the can authenticate ?

SQL Server Database Engine
0 comments No comments

2 answers

Sort by: Oldest
  1. Erland Sommarskog 137.6K Reputation points MVP Volunteer Moderator
    2026-09-30T20:44:03.2066667+00:00

    What is the environment here? Is this VM in an organisation, and the users are in the same organisation on the same corporate network? In that case, I would discuss that you talk with your IT department.

    Or are the users connecting from all over internet? For this situation, I would recommend that you arrange for some VPN solution that your users can use. This means work and installation on their side as well. If this is not feasible, I don't think you have much choice but to open firewall ports on case-by-case basis, as open SQL Server for anyone on the whole wide internet is an extremely bad idea.

    Is this a VM on-prem, or is this something in Azure or another cloud?

    Was this answer helpful?

    0 comments No comments

  2. Maksood Ahmed 15 Reputation points Microsoft External Staff Moderator
    2026-10-01T12:34:32.6033333+00:00

    Hi @orville wright ,

    Since your SQL Server is running on a virtual machine, I would not recommend removing or disabling the firewall. The firewall is protecting the SQL Server from unauthorized network access.

    Instead, configure SQL Server to use a fixed TCP port and create a firewall rule that allows that port only from the networks that should access the database.

    If your users receive different IP addresses frequently, maintaining a separate firewall rule for every client IP can become difficult. In that case, consider having the users connect through a controlled network such as your organization’s VPN, and allow the appropriate network range instead of individual changing public IP addresses.

    Also verify that TCP/IP is enabled in SQL Server Configuration Manager and confirm which TCP port the SQL Server instance is actually using. Named SQL Server instances can use dynamic ports unless a fixed port is configured.

    So, in short:

    • Do not remove the firewall.
    • Enable TCP/IP for remote SQL Server connections.
    • Configure a fixed SQL Server TCP port if needed.
    • Allow that port only from trusted networks.
    • If users' public IP addresses frequently change, consider VPN/private connectivity rather than continuously adding individual IP addresses.

    FYR:

    Configure Windows Firewall for SQL Server Database Engine access

    Configure SQL Server to listen on a specific TCP port

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.