Configure network connectors

Neo4j provides support for Bolt, HTTP, and HTTPS protocols using network connectors. Network connectors are configured in the neo4j.conf file.

Available network connectors

The table below lists the available network connectors in Neo4j:

Table 1. Neo4j network connectors and port number
Network connector name Protocol Default port number

server.bolt

Bolt

7687

server.http

HTTP

7474

server.https

HTTPS

7473

When configuring the HTTPS or Bolt connectors, see also SSL framework for details on how to work with SSL certificates.

Configuration options

The network connectors are configured by settings in the format server.<network-connector-name>.<setting-suffix>.

Table 2. Configuration option suffixes for network connectors
Option name Default Setting(s) Description

enabled

true [1]

server.bolt.enabled, server.http.enabled, server.https.enabled [2]

This setting allows the client connector to be enabled or disabled. When disabled, Neo4j does not listen for incoming connections on the relevant port.

listen_address

localhost:<network-connector-default-port>

server.bolt.listen_address, server.https.listen_address, server.http.listen_address

This setting specifies how Neo4j listens for incoming connections. It consists of two parts; an IP address (e.g. 127.0.0.1 or 0.0.0.0) and a port number (e.g. 7687), and is expressed in the format <ip-address>:<port-number>. If using IPv6, the IP address must be enclosed in square brackets, for example [::1]:7687 or [::]:7687.

advertised_address

localhost:<network-connector-default-port>

server.bolt.advertised_address, server.https.advertised_address, server.http.advertised_address

This setting specifies the address that clients should use for this network connector. This is useful in a cluster as it allows each server to correctly advertise the addresses of the other servers in the cluster. The advertised address consists of two parts; an address (fully qualified domain name, hostname, or IP address) and a port number (e.g. 7687), and is expressed in the format <address>:<port-number>. If using IPv6, the address must be enclosed in square brackets, for example [::1]:7687 or [::]:7687.

tls_level

DISABLED

server.bolt.tls_level

This setting is only applicable to the Bolt connector. It allows the Bolt connector to accept encrypted and/or unencrypted connections. The default value is DISABLED, where only unencrypted client connections are to be accepted by this connector, and all encrypted connections will be rejected.

Other values are REQUIRED and OPTIONAL. Use REQUIRED when only encrypted client connections are to be accepted by this connector, and all unencrypted connections will be rejected. Use OPTIONAL where either encrypted or unencrypted client connections are accepted by this connector.

1. When Neo4j is used in embedded mode, the default value is false.
2. The default value for server.https.enabled is false.
Example 1. Specify listen_address for the Bolt connector

To listen for Bolt connections on all network interfaces (0.0.0.0) and on port 7000, set the listen_address for the Bolt connector:

server.bolt.listen_address=0.0.0.0:7000
Example 2. Specify advertised_address for the Bolt connector

If routing traffic via a proxy, or if port mappings are in use, it is possible to specify advertised_address for each network connector individually. For example, if port 7687 on the Neo4j server is mapped from port 9000 on the external network, specify the advertised_address for the Bolt connector:

server.bolt.advertised_address=<server-name>:9000

Options for Bolt thread pooling

See Bolt thread pool configuration to learn more about Bolt thread pooling and how to configure it on the network connector level.

Defaults for addresses

It is possible to specify defaults for the configuration options with listen_address and advertised_address suffixes. Setting a default value applies to all network connectors unless specifically configured for a certain connector.

server.default_listen_address

This configuration option defines a default IP address of the settings with the listen_address suffix for all network connectors. If the IP address part of the listen_address is not specified, it is inherited from the shared setting server.default_listen_address.

Changing server.default_listen_address may expose cluster ports to the network. Therefore, it is recommended to explicitly override cluster listen_addresses to localhost if clustering is not in use.

Example 3. Specify listen_address for the Bolt connector

To listen for Bolt connections on all network interfaces (0.0.0.0) and on port 7000, set the listen_address for the Bolt connector:

server.bolt.listen_address=0.0.0.0:7000

This is equivalent to specifying the IP address by using the server.default_listen_address setting, and then specifying the port number for the Bolt connector.

server.default_listen_address=0.0.0.0

server.bolt.listen_address=:7000
server.default_advertised_address

This configuration option defines a default address of the settings with the advertised_address suffix for all network connectors. If the address part of the advertised_address is not specified, it is inherited from the shared setting server.default_advertised_address.

Example 4. Specify advertised_address for the Bolt connector

Specify the address that clients should use for the Bolt connector:

server.bolt.advertised_address=server1:9000

This is equivalent to specifying the address by using the server.default_advertised_address setting, and then specifying the port number for the Bolt connector.

server.default_advertised_address=server1

server.bolt.advertised_address=:9000

The default address settings can only accept the hostname or IP address portion of the full socket address. Port numbers are protocol-specific, and can only be added by the protocol-specific network connector configuration.

For example, if you configure the default address value to be example.com:9999, Neo4j will fail to start and you will get an error in neo4j.log.

IPv6 support

Neo4j supports IPv6 addresses for all connectors. IPv6 addresses must be enclosed in square brackets in all configuration values, for example [::1] or [::].

Configure connectors for IPv6

To bind Neo4j connectors to an IPv6 address, set the listen_address and advertised_address settings in neo4j.conf.

Bolt connector
# Listen on all IPv6 interfaces
server.bolt.listen_address=[::]:<port>

# Advertise a specific IPv6 address to clients
server.bolt.advertised_address=[2001:db8::1]:<port>
HTTP connector
server.http.listen_address=[::]:<port>
server.http.advertised_address=[2001:db8::1]:<port>
HTTPS connector
server.https.listen_address=[::]:<port>
server.https.advertised_address=[2001:db8::1]:<port>

Dual-stack configuration

To accept both IPv4 and IPv6 connections simultaneously, bind connectors to the wildcard IPv6 address [::]. On most operating systems, this enables dual-stack mode, meaning IPv4 connections are also accepted via IPv4-mapped IPv6 addresses.

# Global bind address (does not use brackets)
server.default_listen_address=::

# Individual connector addresses (MUST use square brackets for IPv6)
server.bolt.enabled=true
server.bolt.listen_address=[::]:7687

server.http.enabled=true
server.http.listen_address=[::]:7474

server.https.enabled=false
# server.https.listen_address=[::]:7473

# Local advertised mappings
server.default_advertised_address=localhost
server.bolt.advertised_address=localhost:7687
server.http.advertised_address=localhost:7474

Dual-stack behavior depends on the operating system. macOS enables dual-stack sockets by default. When you bind Neo4j to [::] on your Mac, the operating system will natively map incoming IPv4 traffic to IPv6 addresses, allowing both types of connections to succeed on ports 7687 and 7474 automatically. On some Linux systems, net.ipv6.bindv6only may be set to 1, which disables IPv4-mapped addresses. In that case, you must run Neo4j with two separate listen addresses — one for IPv4 and one for IPv6 — or change the kernel setting.

Glossary

allocator

A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.

asynchronous replication

Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.

Aura instance

A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.

auto-commit transaction

An automatically committed transaction that contains a single query.

Bolt protocol

Bolt is a protocol used for interaction between Neo4j instances and drivers.

bookmark

A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.

category (Bloom)

A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).

causal consistency

All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.

cluster

A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.

client application

Software that interacts with a Neo4j server.

commit

A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.

composite database

Composite databases are the means to access partitioned graph data with a single Cypher query.

constraint

Constraints are sets of data modeling rules that ensure the data is consistent and reliable.

Cypher®

Neo4j’s graph query language.

data model

A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.

database

A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.

database vs graph

Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.

Database Management System

Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.

database schema

The prescribed property existence and datatypes for nodes and relationships.

deallocate

An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.

degree (of a node)

The number of relationships of a specific node; loops are counted twice.

disaster recovery

A manual intervention to restore availability of a cluster, or databases within a cluster.

driver

A software library that provides access to Neo4j from a particular programming language.

election

In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.

entity

A node or a relationship.

expression (Cypher)

A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.

fabric

Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.

fault tolerance

A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.

follower

A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.

Generative AI (GenAI)

A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.

graph

A logical representation of a set of nodes where some pairs are connected by relationships.

index

Data structure that improves read performance of a database.

knowledge graph

A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.

label

Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.

leader

A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.

main database

In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.

motif

A description of a specific pattern within a graph.

node

A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.

operator

A symbol representing a mathematical or logical operation.

parameter

Named value provided when running a Cypher statement.

path

A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.

pattern

A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.

perspective (Bloom)

A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.

primary

A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.

primary vs secondary

In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.

project (Aura)

An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.

property

Properties are key-value pairs that are used for storing data on nodes and relationships.

query (Cypher)

A statement that retrieves or writes information to a database.

Raft group

A group of servers that are participating in hosting a particular database in primary mode.

Raft group member

A server that is participating in a Raft group. A server can be a member of one or more groups.

Raft log

A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.

Raft protocol

The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.

read scaling

Distributing query load by creating additional database copies hosted in secondary mode (read-only).

relationship

A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.

secondary

An asynchronously replicated copy of the database that provides read scaling within the cluster.

seed

A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.

server

A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.

session

A causally linked sequence of transactions.

session consistency

An alternative name for Neo4j’s causal consistency.

standalone

A single server running Neo4j and not part of a cluster.

synchronous replication

Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.

system database

A database used by Neo4j to store system information.

tenant (Aura)

An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.

tool asset database

In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.

topology

A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.

transaction

A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).