Yes, limit connections in firewall. Ideally you are only listening on a private network anyway, better yet only listening on loopback or a local socket. But still firewall it. You can also configure the database to only accept connections from a particular source. Do that too.
How do you handle firewall? Just open up the source IP with the IP of wherever the Application is hosted?