Both WFE and APP servers need a connection to SQL server, so you need firewall rules for both. The communication is initiated by SP servers to SQL server. Standard ports are 1433, if you are using named instances for SQL then also 1434 and the port of
the named instance.
Marek Chmel(MVP SQL Server, MCSE SharePoint 2013, MCT, CCNA,CCDA)
Please Mark As Answer if my post solves your problem or Vote As Helpful if a post has been helpful for you.