Start typing to search across invoices, services, domains, tickets, and more...
On a site-cluster server, a common requirement is to have each website resolve to and listen on its own IP for cleaner management, certificate handling and risk isolation. This guide explains how to assign a dedicated IP to each website on a site-cluster server: bind addresses with Nginx listen IP:80/443, set per-site IPs in BT Panel/aaPanel, understand outbound IP and SNAT, and follow practical SEO tips for site networks. It applies to Nginx on Debian/Ubuntu and CentOS/Rocky/AlmaLinux.
Nginx can only listen on addresses that exist on the system; otherwise it reports cannot assign requested address:
ip -4 addr show dev eth0 | grep inetIn each site's server block, change listen 80; to listen IP:80;. Config files usually live in /etc/nginx/conf.d/ or /etc/nginx/sites-available/:
server {
listen 203.0.113.11:80;
server_name site1.example www.site1.example;
root /var/www/site1;
index index.html index.php;
}
server {
listen 203.0.113.12:80;
server_name site2.example www.site2.example;
root /var/www/site2;
index index.html index.php;
}Requests to a given IP will then only match sites bound to that IP, even if the Host header does not match.
Do the same for port 443 and give each site its own certificate:
server {
listen 203.0.113.11:443 ssl;
server_name site1.example www.site1.example;
ssl_certificate /etc/nginx/ssl/site1.example/fullchain.pem;
ssl_certificate_key /etc/nginx/ssl/site1.example/privkey.pem;
root /var/www/site1;
}With one HTTPS site per IP, even clients without SNI support receive the correct certificate.
Add a default_server for each IP that rejects unknown hostnames, so nobody can point their domain at your IP and mirror your content:
server {
listen 203.0.113.11:80 default_server;
server_name _;
return 444;
}nginx -t && systemctl reload nginx
ss -lntp | grep nginxBefore DNS propagates, use curl --resolve to test each site against its IP:
curl -I --resolve site1.example:80:203.0.113.11 http://site1.example/
curl -I --resolve site2.example:80:203.0.113.12 http://site2.example/New sites in BT Panel/aaPanel listen on port 80 for all IPs by default. To bind a site to a dedicated IP, open the site's settings in the panel, go to the configuration file and change the listen lines to a specific IP:
listen 203.0.113.11:80;
listen 203.0.113.11:443 ssl;Nginx listen only controls the inbound IP. When the server makes outgoing requests (scraping, API calls, mail), it uses the primary IP by default. To send a site's traffic from a specific IP, bind the source address in your code (curl --interface, PHP cURL CURLOPT_INTERFACE), or run the site as a dedicated user and SNAT by user with iptables:
useradd -r -s /sbin/nologin site1run
iptables -t nat -A POSTROUTING -o eth0 -m owner --uid-owner site1run -j SNAT --to-source 203.0.113.11
curl --interface 203.0.113.11 https://ifconfig.meSave the iptables rules with iptables-save or netfilter-persistent so they survive reboots.
The IP is usually not bound to the NIC, or another process uses the port. Check with ip addr and ss -lntp.
Look for a server block still using listen 80 default_server, or DNS still pointing to the old IP.
Yes. Use <VirtualHost 203.0.113.11:80> together with the Listen directive.
Still stuck? Open a ticket with IMIDC 24/7 technical support.