Access SQL Server Data Source through the NineData Gateway
NineData supports accessing SQL Server data sources through a gateway, allowing you to connect SQL Server instances located in private or dedicated networks to NineData without exposing their public network addresses.
Before you begin
- The host where the gateway is deployed must be in the private network of the SQL Server data source and must be able to access SQL Server.
- The host where the gateway is deployed must have access to the public network. If the host is in a local network and cannot access the public network, deploy a proxy gateway. For more information, see Using Proxy Gateway.
Step 1: Deploy Gateway
Use this step when the gateway host can access the public internet. If the host can access only a local area network, use Proxy Gateway to deploy the gateway.
Sign in to the NineData console on the host where you want to deploy the gateway.
In the left navigation pane, select Datasource > Gateway.
Select Create Gateway.
Configure the following parameters.
Parameter Description Name Enter a gateway name that is easy to search and manage. Manual names are supported. Environment Select the operating system of the gateway host. NineData displays the corresponding gateway installation method. The following operating systems are supported: - Windows(x86_64)
- Linux(x86_64)
- macOS
Access Region Select the region closest to the gateway host to reduce network latency. Advanced No configuration required. Follow the displayed installation method to install and configure the gateway on the deployment host. When the gateway connects successfully, the connection diagram changes from Waiting for the local gateway to launch... to The local gateway is connected successfully.
Select Create Datasource, choose the data source to add in the selection window, and proceed to Step 2.
Step 2: Connect to SQL Server data source
On the Create Datasource page, configure the parameters in the table.
Parameter Description Name Enter the data source name. Use a meaningful name to identify and manage the data source later. Connection Select Gateway. Gateway Select the gateway ID deployed in Step 1. Host Enter the access address and port of the SQL Server data source. - If SQL Server is installed on the local machine, enter
localhostor127.0.0.1on the left side and the actual access port of SQL Server on the right side. - If SQL Server is installed on another host in the private network, enter the private IP address of that host on the left side and the actual access port of SQL Server on the right side.
DB Account Enter the login username of the SQL Server. DB Password Enter the login password of the SQL Server. Access Region Select the region closest to the location of your SQL Server host to effectively reduce network latency. Environment Select the environment that matches the business purpose of the data source. The default provides the PROD and DEV environments, and also supports you to create a custom environment.
Note: In organization mode, the database environment can also be applied to permission policy management. For example, the default Prod Admin role only supports access to data sources in the PROD environment and cannot access data sources in other environments. For more information, see Managing Roles.Encryption Configure SSL encryption for data source access (enabled by default). If the data source requires an SSL encrypted connection, enable this switch, or the connection fails.
Use the switch to enable or disable encrypted transmission. Click > on the left side of Encryption to expand the detailed configuration.- Always trust the server certificate (selected by default): When selected, the client always trusts the server certificate, regardless of whether it was issued by a trusted certificate authority. This simplifies the connection but increases security risk.
- Verify Server Certificate (SSL CA): If SQL Server uses a certificate issued by a self-signed CA, select this option and upload the CA root certificate. NineData verifies the uploaded certificate. If verification fails, the connection is rejected.
- Server Certificate Hostname: Enter the hostname or domain name associated with the certificate issued by the CA. NineData uses it to verify whether the current connection hostname matches the hostname in the certificate. If they do not match, the connection is rejected to help prevent man-in-the-middle attacks.
- If SQL Server is installed on the local machine, enter
After configuring the parameters, click Connection Test next to Create Datasource to verify that NineData can reach the data source. When Connection Successfully appears, click Create Datasource to add the data source. If the test fails, review the connection settings and run the test again.
Appendix: Using Proxy Gateway
If the gateway host cannot access the public internet, use a proxy gateway. Prepare two hosts in the same LAN that can reach each other:
- Host A: A host that can access the public internet.
- Host B: The host where you deploy the gateway.
Create a gateway on Host A to act as a proxy so Host B can connect to the NineData server through it.
Procedure
Sign in to the NineData console on Host A.
In the left navigation bar, select Datasource > Gateway.
Select Create Gateway.
Configure the following parameters.
Parameter Description Name Enter a gateway name that is easy to search and manage. Specify the gateway name manually. Environment Select the operating system of the gateway host. NineData displays the corresponding gateway installation method. The following operating systems are supported: - Windows (x86_64)
- Linux (x86_64)
- macOS
Access Region Select the region closest to the gateway host to reduce network latency. Advanced No configuration is required. Follow the displayed installation method to install and configure the gateway on Host A. When the gateway connects successfully, the connection diagram changes from Waiting for the local gateway to launch... to The local gateway is connected successfully.
Select Completed and back to List, and then select Create Gateway again.
In Environment, select the operating system of Host B.
Select Advanced, select Use Proxy, and open the dropdown under Proxy. Select the gateway created on Host A.
tipNineData opens a proxy port on Host A for Host B. When the page shows
<gateway_name> has enabled proxy function, port <port>, the proxy gateway is ready.Follow the displayed installation steps to install the gateway on Host B.
Wait until the connection diagram changes from Waiting for the local gateway to launch... to The local gateway is connected successfully.
Select Create Datasource to proceed to Step 2.