ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Site Clusters & Multi-IP

Assign a Dedicated IP to Each Website on a Site-Cluster Server: Nginx, aaPanel and Outbound IP

8 steps 10 min read 5 views 0
On this page

On a site-cluster server, a common requirement is to have each website resolve to and listen on its own IP for cleaner management, certificate handling and risk isolation. This guide explains how to assign a dedicated IP to each website on a site-cluster server: bind addresses with Nginx listen IP:80/443, set per-site IPs in BT Panel/aaPanel, understand outbound IP and SNAT, and follow practical SEO tips for site networks. It applies to Nginx on Debian/Ubuntu and CentOS/Rocky/AlmaLinux.

First bind the IP block to the server NIC (see our article on bulk-binding a /24 on Linux) and point each domain's A record to its own IP. The examples use 203.0.113.11, 203.0.113.12 and the domains site1.example and site2.example.

Step 1: Confirm the IPs Are Bound to the Interface

Nginx can only listen on addresses that exist on the system; otherwise it reports cannot assign requested address:

ip -4 addr show dev eth0 | grep inet

Step 2: Bind Each Website to Its Own IP with Nginx listen IP:80

In each site's server block, change listen 80; to listen IP:80;. Config files usually live in /etc/nginx/conf.d/ or /etc/nginx/sites-available/:

server {
    listen 203.0.113.11:80;
    server_name site1.example www.site1.example;
    root /var/www/site1;
    index index.html index.php;
}

server {
    listen 203.0.113.12:80;
    server_name site2.example www.site2.example;
    root /var/www/site2;
    index index.html index.php;
}

Requests to a given IP will then only match sites bound to that IP, even if the Host header does not match.

Step 3: Use listen IP:443 ssl for HTTPS Sites

Do the same for port 443 and give each site its own certificate:

server {
    listen 203.0.113.11:443 ssl;
    server_name site1.example www.site1.example;
    ssl_certificate     /etc/nginx/ssl/site1.example/fullchain.pem;
    ssl_certificate_key /etc/nginx/ssl/site1.example/privkey.pem;
    root /var/www/site1;
}

With one HTTPS site per IP, even clients without SNI support receive the correct certificate.

Step 4: Add a Default Server per IP to Block Unknown Domains

Add a default_server for each IP that rejects unknown hostnames, so nobody can point their domain at your IP and mirror your content:

server {
    listen 203.0.113.11:80 default_server;
    server_name _;
    return 444;
}

Step 5: Test, Reload Nginx and Verify Each Site's IP

nginx -t && systemctl reload nginx
ss -lntp | grep nginx

Before DNS propagates, use curl --resolve to test each site against its IP:

curl -I --resolve site1.example:80:203.0.113.11 http://site1.example/
curl -I --resolve site2.example:80:203.0.113.12 http://site2.example/

Step 6: Multi-IP Sites in BT Panel / aaPanel

New sites in BT Panel/aaPanel listen on port 80 for all IPs by default. To bind a site to a dedicated IP, open the site's settings in the panel, go to the configuration file and change the listen lines to a specific IP:

listen 203.0.113.11:80;
listen 203.0.113.11:443 ssl;
Changing SSL, rewrite or port settings in the panel may regenerate the listen lines. Re-check the config file afterwards. Menu names depend on your panel version.

Step 7: Outbound IP and SNAT in Brief

Nginx listen only controls the inbound IP. When the server makes outgoing requests (scraping, API calls, mail), it uses the primary IP by default. To send a site's traffic from a specific IP, bind the source address in your code (curl --interface, PHP cURL CURLOPT_INTERFACE), or run the site as a dedicated user and SNAT by user with iptables:

useradd -r -s /sbin/nologin site1run
iptables -t nat -A POSTROUTING -o eth0 -m owner --uid-owner site1run -j SNAT --to-source 203.0.113.11
curl --interface 203.0.113.11 https://ifconfig.me

Save the iptables rules with iptables-save or netfilter-persistent so they survive reboots.

SEO Tips for Multi-IP Site Clusters

  • A dedicated IP is only a baseline; original content, site quality and user experience matter far more for ranking;
  • Avoid identical templates, content and analytics IDs across sites;
  • Set rDNS for IPs if needed and give each site its own certificate;
  • Follow search engine webmaster guidelines; do not use site networks for link spam or scraped mirrors.

FAQ

Nginx says bind() to 203.0.113.11:80 failed.

The IP is usually not bound to the NIC, or another process uses the port. Check with ip addr and ss -lntp.

Visiting the IP still shows another site.

Look for a server block still using listen 80 default_server, or DNS still pointing to the old IP.

Can I do the same with Apache?

Yes. Use <VirtualHost 203.0.113.11:80> together with the Listen directive.

Still stuck? Open a ticket with IMIDC 24/7 technical support.

Was this answer helpful?

Related Tutorials