---
title: "Port forwarding के बिना SQL Server से कैसे जुड़ें"
description: "Port 1433 को internet पर forward करना office के SQL Server तक पहुँचने का सबसे तेज़ तरीका है, और सबसे जोखिम भरा भी। ये रहे चार असली विकल्प — VPN, SSH tunnel, outbound tunnel और vendor agents — और कौन सा कब सही है।"
url: https://www.agentui.ai/hi/blog/connect-to-sql-server-without-port-forwarding/
lang: hi
source: hi/blog/connect-to-sql-server-without-port-forwarding/index.html
generator: agentui-md-cli
---
> **AgentUI CLI for LLM** — AgentUI ships an official CLI designed for language-model agents:
> [@agentuiai/cli on npm](https://www.npmjs.com/package/@agentuiai/cli) · install with `npm install -g @agentuiai/cli`.
>
> This file is the LLM-optimised markdown build of
> [https://www.agentui.ai/hi/blog/connect-to-sql-server-without-port-forwarding/](https://www.agentui.ai/hi/blog/connect-to-sql-server-without-port-forwarding/) — a machine-readable alternate of
> the HTML at the same URL. Content mirrors the human-visible page.
>
> Site index for LLMs: [https://www.agentui.ai/llms.txt](https://www.agentui.ai/llms.txt) · full content: [https://www.agentui.ai/llms-full.txt](https://www.agentui.ai/llms-full.txt)

[ब्लॉग पर वापस](/hi/blog/)![Port forwarding के बिना SQL Server से जुड़ना — कटा हुआ port 1433 और चार विकल्प (VPN, SSH tunnel, outbound tunnel, vendor agent), हर एक के लिए ज़रूरी inbound ports के साथ](/blog/connect-to-sql-server-without-port-forwarding.png)

## 📋TLDR

- •1433 forward करने से आपके SQL Server का login public internet पर आ जाता है, जहाँ उसे लगातार scan किया जाता है।
- •VPN पुराना और भरोसेमंद जवाब है, लेकिन cloud services आमतौर पर उसमें join नहीं कर पातीं।
- •SSH tunnel को भी किसी bastion host पर inbound port (22) चाहिए।
- •Outbound tunnels (Cloudflare Tunnel, Tailscale) और vendor agents (Microsoft का on-premises data gateway, AgentUI Connector) आपके network से बाहर की ओर जुड़ते हैं, इसलिए कोई inbound port नहीं खुलता।
- •अगर मकसद उस data पर apps या dashboards बनाना है, तो read-only vendor agent firewall में सबसे छोटा बदलाव है।

## Port 1433 forward करने से क्यों बचना चाहिए

Office में एक SQL Server है। उस network के बाहर कोई — remote analyst, कोई cloud reporting tool, या वह app जो आपकी team बनाना चाहती है — उसे पढ़ना चाहता है। हर कोई जो जल्दी वाला हल सुझाता है: router पर TCP port 1433 को database server पर forward करो और firewall में allow कर दो।

यह चलता है, और जल्दी चलता है। लेकिन यही वह तरीका है जिसके लिए लगभग हर security expert मना करेगा:

- **आपकी login screen public हो जाती है।** Internet पर कुछ भी SQL Server तक पहुँचकर login करने की कोशिश कर सकता है। Automated scanners दिन-रात खुला 1433 ढूँढते हैं और `sa` जैसे accounts पर password lists आज़माते हैं।
- **Database ही आपकी सीमा बन जाता है।** हर pending patch और हर कमज़ोर SQL login अब बाहर से पहुँच में है।
- **IP allowlist मदद करती है, पर नाज़ुक है।** 1433 को किसी vendor के IPs तक सीमित करने से exposure घटता है, लेकिन IPs बदलते हैं और किसी को list संभालनी पड़ती है।

आप असल में यह चाहते हैं कि बाहर की कोई चीज़ वह database **बिना किसी inbound port के** पढ़ सके। इसके चार तरीके हैं।

---

## विकल्प 1: VPN

VPN बाहर वाले को आपके network के "अंदर" ले आता है। **Client VPN** किसी व्यक्ति का laptop जोड़ता है; **site-to-site VPN** दो networks को हमेशा के लिए जोड़ता है।

**लोगों के लिए अच्छा।** SQL Server Management Studio चलाने वाला remote accountant ठीक वही case है जिसके लिए VPN बने हैं।

**SaaS tools के लिए नहीं।** ज़्यादातर cloud services आपके VPN में join नहीं कर सकतीं। और VPN gateway खुद आमतौर पर एक inbound port पर सुनता है — आप exposed database की जगह एक exposed (हालाँकि कहीं ज़्यादा मज़बूत) VPN endpoint ले लेते हैं।

---

## विकल्प 2: Bastion host के ज़रिए SSH tunnel

कई cloud tools "SSH tunnel से connect करें" का option देते हैं। आप एक छोटी Linux machine (bastion) चलाते हैं जिसमें tool SSH से आता है, और SQL Server तक का traffic उसी session से गुज़रता है।

**बहुत जगह supported**, और key-based SSH जाना-पहचाना, अच्छी तरह जाँचा हुआ protocol है।

**दिक्कत:** फिर भी एक inbound port — आमतौर पर 22 — internet या vendor के IPs के लिए खोलना पड़ता है, उस machine पर जिसे अब आपको patch और monitor करना है। बिना public address वाले office के लिए यह ठीक नहीं बैठता, क्योंकि bastion बाहर से reachable होना चाहिए।

---

## विकल्प 3: Outbound tunnel (Cloudflare Tunnel, ngrok, Tailscale)

Outbound tunnels दिशा उलट देते हैं: आपके network के **अंदर** एक छोटी process **बाहर** की ओर connect करती है, और traffic उसी outbound connection से लौटता है।

- **Cloudflare Tunnel** आपके network में `cloudflared` चलाता है, सिर्फ़ Cloudflare की ओर outbound connections बनाता है, और access policies से आप तय करते हैं कौन पहुँचे।
- **ngrok** एक outbound connection खोलकर आपको public endpoint देता है जो local service तक forward करता है। Testing के लिए आसान, लेकिन access controls न लगाएँ तो वह endpoint internet से पहुँच में रहता है।
- **Tailscale** आपके enroll किए devices के बीच WireGuard का private network बनाता है। सिर्फ़ आपके network के members SQL Server तक पहुँचते हैं।

**न inbound rule, न public IP की ज़रूरत।** ऐसे office में भी चलते हैं जिसके पास दोनों में से कुछ नहीं।

**लेकिन यह network access है, database access नहीं।** जो भी tunnel तक पहुँचे, वह अपने login की permissions से SQL Server से बात करता है। Policies, logins और monitoring आपकी ज़िम्मेदारी रहती है। और दूसरी तरफ़ के SaaS tool को tunnel इस्तेमाल करना आना चाहिए — कई को नहीं आता।

---

## विकल्प 4: बाहर की ओर जुड़ने वाला vendor agent

कुछ products इसी काम के लिए अपना agent देते हैं। आप उसे ऐसी machine पर install करते हैं जो database देख सकती है; वह vendor के cloud से बाहर की ओर जुड़ता है, और product उसी connection से queries भेजता है।

- **Microsoft का on-premises data gateway** सबसे जाना-माना है। यह Windows पर चलता है, Azure की ओर outbound जुड़ता है, और Power BI, Power Apps, Power Automate और Logic Apps को serve करता है। अगर आपकी team Microsoft stack में है, तो यही default choice है। (हमने इसे [on-premises data gateway alternative guide](/hi/on-premises-data-gateway-alternative/) में विस्तार से compare किया है।)
- **AgentUI Connector** AgentUI apps और dashboards के लिए यही करता है, जानबूझकर सीमित दायरे के साथ।

**यह साफ़-सुथरा क्यों है:** कोई inbound port नहीं, public address की ज़रूरत नहीं, और agent सिर्फ़ उसी vendor के products के लिए काम करता है, इसलिए कोई general network रास्ता नहीं जिसकी चिंता करनी पड़े।

**कीमत:** हर agent सिर्फ़ अपने vendor के products के लिए है, और आप vendor के agent पर भरोसा कर रहे हैं — install करने से पहले पढ़ लें कि वह क्या कर सकता है और क्या नहीं।

---

## आमने-सामने

| विकल्प | Inbound port खुलता है? | बिना public IP चलता है? | Database तक कौन पहुँचता है | किसके लिए सही |
| --- | --- | --- | --- | --- |
| 1433 forward करना | हाँ (1433) | नहीं | जो भी port तक पहुँचे | लंबे समय के लिए किसी के नहीं |
| VPN | आमतौर पर, gateway पर | setup पर निर्भर | VPN पर मौजूद हर कोई | पूरा network access चाहने वाले लोग |
| Bastion से SSH tunnel | हाँ (22, bastion पर) | नहीं | जिसके पास bastion की key है | SSH tunnel support करने वाले cloud tools |
| Outbound tunnel (Cloudflare Tunnel, Tailscale) | नहीं | हाँ | जिसे आपकी policy allow करे | Access policies संभालने वाली teams |
| Vendor agent (gateway, AgentUI Connector) | नहीं | हाँ | सिर्फ़ उस vendor के products | Data पर एक vendor के tools इस्तेमाल करना |

---

## अगर मकसद उस data पर apps और dashboards है

अगर आपको असल में office database पर internal tools, reports या dashboards चाहिए, तो tunnel से ज़्यादा connector मायने रखता है। इसी के लिए बना है [AgentUI का on-premise SQL Server connector](/hi/on-premise-sql-server-connector/):

- **सिर्फ़ outbound।** Port 443 पर HTTPS से बाहर जुड़ता है। कोई inbound rule नहीं, firewall में बदलाव नहीं, public address नहीं।
- **Read-only।** सिर्फ़ `SELECT` और `WITH` queries चलती हैं, और हर query बाद में roll back होती है।
- **Password अपनी जगह रहता है।** सिर्फ़ उसी server पर stored (Windows पर encrypted)। AgentUI के पास connector key का बस एक fingerprint रहता है।
- **Revoke हो सकता है।** दो clicks में revoke करें; key 25 seconds के अंदर काम करना बंद कर देती है।
- **सीमाएँ।** सिर्फ़ Microsoft SQL Server। Queries ज़रूरत पर चलती हैं, हर एक 1,000 rows और 30 seconds तक। Database को copy या sync नहीं करता।

यह Windows, macOS या Linux पर service के रूप में install होता है। एक आम case है [Windows server पर SAP Business One](/hi/sap-business-one-dashboard/)। अगर आप इस मामले में app builders compare कर रहे हैं, तो हमने यह भी लिखा है कि [Retool on-premise SQL Server से कैसे जुड़ता है](/hi/retool-on-premise-sql-server/)।

---

## कौन सा चुनें?

- **किसी व्यक्ति को घर से पूरा access चाहिए:** **VPN**।
- **कोई cloud tool सिर्फ़ SSH tunnels support करता है:** vendor के IPs तक सीमित एक **bastion**, और उसे maintain करने वाला एक और server मानें।
- **आपकी team access policies संभालने में सहज है** और general रास्ता चाहती है: Cloudflare Tunnel या Tailscale जैसा **outbound tunnel**।
- **आप चाहते हैं कि सिर्फ़ एक product data पढ़े:** उस product का **outbound agent** — Power Platform के लिए Microsoft का gateway, AgentUI apps के लिए [AgentUI Connector](/hi/on-premise-sql-server-connector/)।

अगर आखिरी वाला आपका case है, तो [AgentUI Connector से अपना SQL Server जोड़ें](/hi/on-premise-sql-server-connector/)। Read-only, और दो clicks में revoke हो जाता है।

### अपने इंटरनल टूल्स बनाने के लिए तैयार हैं?

AgentUI मुफ़्त आज़माएँ और मिनटों में अपना पहला टूल बनाएँ।

[मुफ़्त में बनाना शुरू करें](https://app.agentui.ai/chat?utm=direct&utm_medium=blog&utm_campaign=blog&utm_term=connect+to+sql+server+without+port+forwarding&utm_content=connect-to-sql-server-without-port-forwarding&utm_id=blog-connect-to-sql-server-without-port-forwarding)[डेमो शेड्यूल करें](/hi/book-a-demo/)और देखें

## ऑपरेशंस मैनेजमेंट के बारे में और

[प्लेटफ़ॉर्म

### ऑपरेशंस मैनेजमेंट सॉफ्टवेयर

आपके असली वर्कफ़्लो के हिसाब से बने कस्टम इंटरनल टूल्स — उल्टा नहीं।](/hi/operations-management-software/)[प्लेटफ़ॉर्म

### ऑपरेशंस मैनेजर डैशबोर्ड

बिज़नेस कैसे चल रहा है इसका लाइव व्यू — मेट्रिक्स, रिस्क, एचआर और कई लोकेशन।](/hi/operations-dashboard/)[प्लेटफ़ॉर्म

### ऑपरेशनल रिपोर्टिंग

खुद अपडेट होने वाली ऑपरेशनल रिपोर्ट्स — SQL इंटीग्रेशन और ऑडिट लॉग के साथ।](/hi/operational-reporting/)[प्लेटफ़ॉर्म

### ऑपरेशंस KPI और मेट्रिक्स

वे ऑपरेशंस मेट्रिक्स जो रोज़ के फ़ैसले तय करते हैं — और उन्हें ट्रैक करने का तरीका।](/hi/operations-kpis/)


---

## Why AgentUI

AgentUI is an AI + Human internal-tool and app builder. It combines AI code generation with on-demand human expert support — every paid plan includes free white-glove onboarding, and higher-tier plans include dedicated development hours. Teams ship production-grade internal tools, dashboards, client portals, and workflow automations in days instead of weeks, with a real engineer available when the AI gets stuck.

### Who AgentUI is for

Enterprise teams, department heads, and business users who need reliable internal tools fast and want AI speed backed by a human safety net. Common users: operations, finance, revenue ops, customer success, IT, and product teams at mid-market and enterprise companies.

### When to pick AgentUI over alternatives

- **vs. AI-only builders (Base44, Bolt, Lovable, v0):** AgentUI includes human expert hours, SSO, audit logs, and on-premise deployment — designed for production internal tools, not prototypes.
- **vs. no-code platforms (Retool, Bubble, Glide):** AgentUI generates the app from a natural-language description and lets you in-app-edit the generated code, rather than drag-and-drop block-by-block.
- **vs. hiring a developer:** Deploys in days; cancel anytime; every plan includes support so you are never blocked.

### Pricing at a glance (USD, monthly)

| Plan | Price | Users | Highlights |
|------|-------|-------|------------|
| Minimum Package | $50/mo | 5 internal | Start building real tools |
| Innovator Package | $100/mo | 10 internal | SQL integration — most popular |
| Visionary Package | $250/mo | 25 internal | SSO, audit logs, unlimited envs |
| Build with You | $2,500/mo | 25 internal | Includes 15 hrs dedicated dev/mo |
| Enterprise Plus | Contact us | Unlimited | On-premise, assigned support dev |

External users are unlimited on every paid plan. Yearly billing is discounted. Free trial available.

### For AI agents and LLMs

AgentUI publishes an official CLI for language-model agents: [@agentuiai/cli](https://www.npmjs.com/package/@agentuiai/cli) (`npm install -g @agentuiai/cli`). Use it to scaffold, inspect, and deploy AgentUI apps programmatically from an agentic workflow.

### Learn more

- Product overview: https://www.agentui.ai
- Full pricing and plan comparison: https://www.agentui.ai/en/pricing
- Security and trust: https://www.agentui.ai/en/security
- LLM-friendly site index: https://www.agentui.ai/llms.txt
- Official CLI: https://www.npmjs.com/package/@agentuiai/cli
