ISPConfig 3 is an open source hosting control panel that manages websites, email, DNS, databases and FTP accounts. In a multi-server setup, one server (the master) runs the ISPConfig interface and the central database, and every other server (the slaves) runs only the services you assign to it, pulling its configuration from the master every minute. In this tutorial you will install a master on one Ubuntu 24.04 server with the official autoinstaller, add a second server as a dedicated web node, and create a website on it from the master's panel.

Prerequisites

You need two fresh servers, for example two CubePath VPS instances:

RoleExample hostnameExample private IPServices
Masterserver1.your_domain10.0.0.11ISPConfig panel, web, mail, DNS, database
Slaveserver2.your_domain10.0.0.12Web and database

Both servers must meet these requirements:

  • A clean install of Ubuntu 24.04 LTS (the autoinstaller also supports Debian 12 and 13). Do not install a web server, mail server or MariaDB beforehand.
  • At least 2 GB of RAM (4 GB on the master if it also handles mail with Rspamd).
  • Root access or a user with sudo privileges.
  • A fully qualified hostname with a DNS A record pointing to the server's public IP, so the autoinstaller can request a Let's Encrypt certificate for it.
  • Network connectivity between the servers. A private network is recommended, because the slave talks to the master's MariaDB on port 3306.

Replace the example hostnames and IPs with your own everywhere in this guide.

Step 1 - Preparing hostnames on both servers

ISPConfig identifies each server by its fully qualified domain name, and the slave connects to the master by name. Set the hostname on each server. On the master:

sudo hostnamectl set-hostname server1.your_domain

On the slave:

sudo hostnamectl set-hostname server2.your_domain

Then edit /etc/hosts on both servers so each name resolves to the right address and the private IPs are used between the nodes:

sudo nano /etc/hosts
127.0.0.1   localhost
10.0.0.11   server1.your_domain server1
10.0.0.12   server2.your_domain server2

If Ubuntu added a 127.0.1.1 line with the hostname, remove it. Verify on each server:

hostname -f
getent hosts server1.your_domain server2.your_domain
server1.your_domain
10.0.0.11       server1.your_domain server1
10.0.0.12       server2.your_domain server2

Step 2 - Installing ISPConfig on the master

The ISPConfig autoinstaller installs and configures every component (Apache or Nginx, PHP-FPM, MariaDB, Postfix, Dovecot, Rspamd, BIND, Pure-FTPd, Roundcube, phpMyAdmin) and then ISPConfig itself. Download it and review it before running it as root:

curl -fsSL -o ispconfig-ai.sh https://get.ispconfig.org
less ispconfig-ai.sh

List the available options:

sudo sh ispconfig-ai.sh --help

Run a full installation on the master. This example uses Nginx and installs Monit and unattended security upgrades; drop --use-nginx if you prefer Apache:

sudo sh ispconfig-ai.sh --use-nginx --monit --unattended-upgrades --lang=en

The installer asks you to confirm and then runs unattended for 10 to 30 minutes. At the end it prints the generated credentials:

[INFO] Your ISPConfig admin password is: 8fK2...
[INFO] Your MySQL root password is: Qx7p...

Store both passwords in your password manager. You need the MySQL root password of the master in the next step.

Open the panel at https://server1.your_domain:8080 and log in as admin with the generated password. Change the password under Tools > Password and Language.

Step 3 - Allowing the slave to reach the master database

The slave installer writes its server record and a dedicated database user into the master's dbispconfig database, so it needs root access to the master's MariaDB over the network. You will create a root account that can log in only from the slave's IP.

On the master, make MariaDB listen on the private IP instead of only on localhost. Open the server configuration:

sudo nano /etc/mysql/mariadb.conf.d/50-server.cnf

Find the bind-address line in the [mysqld] section and set it to the master's private IP:

[mysqld]
bind-address = 10.0.0.11

Restart MariaDB and confirm it listens on that address:

sudo systemctl restart mariadb
sudo ss -tlnp | grep 3306
LISTEN 0      80         10.0.0.11:3306      0.0.0.0:*    users:(("mariadbd",pid=2231,fd=24))

Now open the MariaDB shell with the root password printed by the autoinstaller:

sudo mysql -u root -p

Create the remote root account for the slave. Use the MySQL root password of the master or another strong password in place of your_strong_password:

CREATE USER 'root'@'10.0.0.12' IDENTIFIED BY 'your_strong_password';
GRANT ALL PRIVILEGES ON *.* TO 'root'@'10.0.0.12' WITH GRANT OPTION;
FLUSH PRIVILEGES;
EXIT;

If UFW is active on the master (sudo ufw status), allow port 3306 only from the slave:

sudo ufw allow from 10.0.0.12 to any port 3306 proto tcp

From the slave, test the connection. Install the MariaDB client temporarily if the command is missing (sudo apt install mariadb-client):

mysql -h server1.your_domain -u root -p -e "SHOW DATABASES LIKE 'dbispconfig';"
+------------------------+
| Database (dbispconfig) |
+------------------------+
| dbispconfig            |
+------------------------+

If the connection times out, check the firewall rule and bind-address. If you get Access denied, check the IP in the CREATE USER statement.

Step 4 - Installing ISPConfig on the slave

On the slave, download the same autoinstaller. This node will only host websites and databases, so disable mail, DNS, Roundcube, phpMyAdmin and Mailman. The --interactive flag is required: it runs the ISPConfig setup in expert mode, which is the only mode that can join an existing multi-server setup.

curl -fsSL -o ispconfig-ai.sh https://get.ispconfig.org
sudo sh ispconfig-ai.sh --use-nginx --no-mail --no-dns --no-roundcube --no-pma --no-mailman --interactive --lang=en

Use the same web server (--use-nginx or the Apache default) as on the master, so website settings behave the same on every node.

The autoinstaller first installs the packages and then starts the ISPConfig setup, which asks questions. Answer the important ones as follows and accept the default for the rest:

PromptAnswer
Installation mode (standard,expert)expert
Full qualified hostname (FQDN) of the serverserver2.your_domain
MySQL server hostname / root user / passwordAccept the local defaults
Shall this server join an existing ISPConfig multiserver setup (y,n)y
MySQL master server hostnameserver1.your_domain
MySQL master server port3306
MySQL master server root usernameroot
MySQL master server root passwordThe password from Step 3
MySQL master server database namedbispconfig
Configure Mail / DNSn
Configure Web Servery
Install ISPConfig Web Interfacen

When the setup asks which services to configure, only the ones you answer y to are managed on this node. The web interface stays on the master only. At the end, the autoinstaller prints the local MySQL root password of the slave; store it as well.

When the installation finishes, confirm that the ISPConfig server script is scheduled in root's crontab. This script polls the master for pending changes every minute:

sudo crontab -l | grep server.sh
* * * * * /usr/local/ispconfig/server/server.sh 2>&1 | while read line; do echo `/bin/date` "$line" >> /var/log/ispconfig/cron.log; done

Step 5 - Verifying the new server in the master panel

Log in to the panel on the master and go to System > Server Services. You should now see two entries, server1.your_domain and server2.your_domain. Open server2.your_domain and check that only the services you installed are ticked (for this example, Webserver and DB-Server). Untick any service that is not installed on that node, then save.

Go to Monitor and choose server2.your_domain in the server selector at the top. After a few minutes the Server State page shows the status of Nginx, PHP-FPM and MariaDB on the slave, which confirms that monitoring data is flowing back to the master.

Step 6 - Creating a website on the slave

Now create a site and let ISPConfig deploy it on the second node. In the panel:

  1. Go to Sites > Website > Add new website.
  2. In Server, select server2.your_domain.
  3. Enter the domain, for example site.your_domain, choose the PHP mode (PHP-FPM) and save.

ISPConfig writes the change to a job queue in the master database. Within a minute the slave's server.sh picks it up and creates the site. On the slave, check that the directory exists:

ls /var/www/
clients  html  site.your_domain

Point the DNS A record of site.your_domain to the slave's public IP, then open it in a browser. You can enable Let's Encrypt for the site in its Website settings once DNS resolves.

If nothing appears after a couple of minutes, check the red job-queue indicator at the top of the panel and read /var/log/ispconfig/cron.log on the slave.

Step 7 - Keeping the setup updated

In a multi-server setup, always update the master first and then each slave. On every server run:

sudo ispconfig_update.sh

Choose the stable channel. When a slave asks whether to reconfigure permissions in the master database, answer yes and enter the master root password from Step 3. This is why the remote root account for each slave should be kept, restricted to that slave's IP.

Troubleshooting

  • Changes stay pending in the job queue: the slave cannot reach the master database. From the slave, repeat the mysql -h server1.your_domain test from Step 3 and read /var/log/ispconfig/cron.log.
  • The slave setup cannot connect to the master database: the master hostname does not resolve on the slave, port 3306 is filtered or the remote root account uses a different IP. Check /etc/hosts on the slave, and bind-address, UFW and the CREATE USER host on the master.
  • Let's Encrypt failed for the hostname during installation: the A record of the server's FQDN did not point to its public IP. Fix DNS; the panel still works with a self-signed certificate in the meantime.

Conclusion

You now have a two-node ISPConfig installation: the master holds the panel and the central database, and the slave hosts websites that you manage from the same interface. You can add more nodes by repeating Steps 3 and 4 with their own IPs, for example a dedicated mail server with --no-web or a secondary DNS server. Consider also setting up regular backups of the master's dbispconfig database, since every node depends on it.