---
title: "Network configuration"
description: "Configure Aerospike Database network ports, service sections, and admin settings for cluster communication."
---

# Network configuration

> For the complete documentation index see: [llms.txt](https://aerospike.com/docs/llms.txt)
> 
> All documentation pages available in markdown.

This page describes how to configure critical network ports on an Aerospike Database.

Aerospike Database’s network configuration section sets up critical network ports to be used by other nodes, applications, and tools. The following table describes the ports used by Aerospike Database and cross-datacenter replication (XDR).

| Name | Default port | Description |
| --- | --- | --- |
| service | 3000 | Application, tools, and remote XDR use the service port for database operations and cluster state. |
| fabric | 3001 | Intra-cluster communication port. Replica writes, migrations, and other node-to-node communications use the fabric port. |
| mesh heartbeat | 3002 | Heartbeat protocol ports form and maintain the cluster. Only one heartbeat port may be configured. Mesh heartbeat and fabric should run on the same NIC. |
| multicast heartbeat | 9918 | Heartbeat protocol ports are used to form and maintain the cluster. Only one heartbeat port may be configured. |
| admin | 3003 | A dedicated admin port for continuous access by the monitoring stack exporter, as well as emergency access to unresponsive nodes using `asadm` and `asinfo`. |

Verify that all application and XDR nodes can communicate to the service port on all Aerospike nodes, and that each node can communicate over the configured heartbeat and fabric ports.

::: note
The telnet-compatible info port 3003 was removed in Database 8.1.0. Use the admin port instead.
:::

## Configure network sections

The `network` section of the Aerospike configuration file requires the following sections:

-   service
-   fabric
-   heartbeat
-   admin

To isolate fabric (inter-node replication, migration) and heartbeat from service traffic or XDR traffic, add an address distinct from the service address to the heartbeat and fabric sections.

::: note
For information on how to configure the heartbeat section, see [heartbeat configuration](https://aerospike.com/docs/database/8.1.2/manage/network/heartbeat) which defines the interface for intra-cluster communications.
:::

### The service section

The following table describes each configuration item in the service section.

| Configuration item | Description |
| --- | --- |
| [`address`](https://aerospike.com/docs/database/reference/config#network__address) | Interfaces or IP addresses to bind and listen to. Multiple IP addresses are allowed. |
| [`access-address`](https://aerospike.com/docs/database/reference/config#network__access-address) | Interfaces or IP addresses to publish for clients, typically clients within the same subnet or datacenter. |
| [`alternate-access-address`](https://aerospike.com/docs/database/reference/config#network__alternate-access-address) | Interfaces or IP addresses to publish for clients that can’t connect to `access-address` interfaces or IP addresses. If the items specified here are actual interfaces and not mapped over NAT, then the corresponding `address` configuration must be specified unless `address any` is set. Clients requiring the `alternate-access-address` to be returned must request it by specifying `useServicesAlternate` in their client policy. |
| [`access-port`](https://aerospike.com/docs/database/reference/config#network__access-port) | When configured, this port is published to the clients. Requires port forwarding to be set up when the value is different than the `port`. |
| [`alternate-access-port`](https://aerospike.com/docs/database/reference/config#network__alternate-access-port) | When configured and the client specifies `useServicesAlternate` in the client policy, this port is published to the clients. Requires port forwarding to be set up when the value is different than the `port`. |

#### Example 1: Service section configuration

Host with 2 network interfaces, x.x.x.x and y.y.y.y, with x.x.x.x for clients within the same subnet or datacenter (private IP) and y.y.y.y for clients in a different subnet or datacenter (public IP). The IP address y.y.y.y is not mapped over NAT:

```plaintext
network {

  service {

    address x.x.x.x

    address y.y.y.y

    access-address x.x.x.x

    alternate-access-address y.y.y.y

  }

}
```

The `access-address` x.x.x.x prevents the y.y.y.y IP from also being published. If `access-address` is not specified, all IPs specified as `address` are published.

#### Example 2: Service section configuration

If the y.y.y.y IP is mapped over NAT:

```plaintext
network {

  service {

    address x.x.x.x

    access-address x.x.x.x

    alternate-access-address y.y.y.y

  }

}
```

Or, as `address` is published by default when not overwritten through `access-address`:

```plaintext
network {

  service {

    address x.x.x.x

    alternate-access-address y.y.y.y

  }

}
```

#### Example 3: Service section configuration

This alternate configuration works in most cases: setting `address` to `any` binds to all available interfaces, then publishes the specific `access-address` and `alternate-access-address`.

```plaintext
network {

  service {

    address any

    access-address x.x.x.x

    alternate-access-address y.y.y.y

  }

}
```

### Fabric section configuration examples

To isolate intra-cluster fabric traffic from regular client traffic, specify an address different from the service section. By default, the fabric address is set to `any`. For heartbeat-specific examples, see [Network heartbeat configuration](https://aerospike.com/docs/database/8.1.2/manage/network/heartbeat).

```plaintext
network {

  fabric {

    address any

    port 3001   # Intra-cluster communication port (migrates, replication, etc).

  }

}
```

### Admin section

The following table describes each configuration item in the optional admin section.

| Configuration item | Description |
| --- | --- |
| [`port`](https://aerospike.com/docs/database/reference/config#network__admin__port) | Port that is not secured (non-TLS) at which the server listens for admin client connections. |
| [`address`](https://aerospike.com/docs/database/reference/config#network__admin__address) | IP address at which the server listens (binds) for non-secure (non-TLS) admin connections. |
| [`tls-authenticate-client`](https://aerospike.com/docs/database/reference/config#network__admin__tls-authenticate-client) | `false`: Only the client authenticating the server.  
  
`any`: Two-way (mutual) authentication, both client and server need to be authenticated.  
  
`user-defined`: Two-way (mutual) authentication along with subject validation. |
| [`tls-port`](https://aerospike.com/docs/database/reference/config#network__admin__tls-port) | TLS-enabled port where the server listens for admin client connections. |
| [`tls-name`](https://aerospike.com/docs/database/reference/config#network__admin__tls-name) | Specifies which TLS parameters to use for the given context’s TLS connections. |
| [`tls-address`](https://aerospike.com/docs/database/reference/config#network__admin__tls-address) | IP address where the server listens (binds) for secured (TLS) admin connections. |
| [`disable-localhost`](https://aerospike.com/docs/database/reference/config#network__admin__disable-localhost) | When set to `true`, the service will not listen on localhost. |

Example configuration:

```plaintext
network {

  admin {

    port 3003

    address any

    tls-port 3004

    tls-name asd_node

    tls-address any

    tls-authenticate-client any

    disable-localhost false

  }

}
```

You can use the admin port to remove an unresponsive node. See [Ejecting an unresponsive node using asadm and the admin port](https://aerospike.com/docs/database/8.1.2/advanced/troubleshoot/cluster#eject-an-unresponsive-node-using-the-admin-port).

## More information

-   Configure the [heartbeat section](https://aerospike.com/docs/database/8.1.2/manage/network/heartbeat).
-   Configure [Rack awareness](https://aerospike.com/docs/database/8.1.2/manage/namespace/rack-aware) to enable Aerospike to support top-of-rack switch failure.
-   [Configure Aerospike Database](https://aerospike.com/docs/database/8.1.2/manage/database/as-config).