ISPConfig 3 is an open source hosting control panel that manages websites, email, DNS, databases and FTP accounts. In a multi-server setup, one server (the master) runs the ISPConfig interface and the central database, and every other server (the slaves) runs only the services you assign to it, pulling its configuration from the master every minute. In this tutorial you will install a master on one Ubuntu 24.04 server with the official autoinstaller, add a second server as a dedicated web node, and create a website on it from the master's panel.
Prerequisites
You need two fresh servers, for example two CubePath VPS instances:
| Role | Example hostname | Example private IP | Services |
|---|---|---|---|
| Master | server1.your_domain | 10.0.0.11 | ISPConfig panel, web, mail, DNS, database |
| Slave | server2.your_domain | 10.0.0.12 | Web and database |
Both servers must meet these requirements:
- A clean install of Ubuntu 24.04 LTS (the autoinstaller also supports Debian 12 and 13). Do not install a web server, mail server or MariaDB beforehand.
- At least 2 GB of RAM (4 GB on the master if it also handles mail with Rspamd).
- Root access or a user with
sudoprivileges. - A fully qualified hostname with a DNS A record pointing to the server's public IP, so the autoinstaller can request a Let's Encrypt certificate for it.
- Network connectivity between the servers. A private network is recommended, because the slave talks to the master's MariaDB on port 3306.
Replace the example hostnames and IPs with your own everywhere in this guide.
Step 1 - Preparing hostnames on both servers
ISPConfig identifies each server by its fully qualified domain name, and the slave connects to the master by name. Set the hostname on each server. On the master:
sudo hostnamectl set-hostname server1.your_domain
On the slave:
sudo hostnamectl set-hostname server2.your_domain
Then edit /etc/hosts on both servers so each name resolves to the right address and the private IPs are used between the nodes:
sudo nano /etc/hosts
127.0.0.1 localhost
10.0.0.11 server1.your_domain server1
10.0.0.12 server2.your_domain server2
If Ubuntu added a 127.0.1.1 line with the hostname, remove it. Verify on each server:
hostname -f
getent hosts server1.your_domain server2.your_domain
server1.your_domain
10.0.0.11 server1.your_domain server1
10.0.0.12 server2.your_domain server2
Step 2 - Installing ISPConfig on the master
The ISPConfig autoinstaller installs and configures every component (Apache or Nginx, PHP-FPM, MariaDB, Postfix, Dovecot, Rspamd, BIND, Pure-FTPd, Roundcube, phpMyAdmin) and then ISPConfig itself. Download it and review it before running it as root:
curl -fsSL -o ispconfig-ai.sh https://get.ispconfig.org
less ispconfig-ai.sh
List the available options:
sudo sh ispconfig-ai.sh --help
Run a full installation on the master. This example uses Nginx and installs Monit and unattended security upgrades; drop --use-nginx if you prefer Apache:
sudo sh ispconfig-ai.sh --use-nginx --monit --unattended-upgrades --lang=en
The installer asks you to confirm and then runs unattended for 10 to 30 minutes. At the end it prints the generated credentials:
[INFO] Your ISPConfig admin password is: 8fK2...
[INFO] Your MySQL root password is: Qx7p...
Store both passwords in your password manager. You need the MySQL root password of the master in the next step.
Open the panel at https://server1.your_domain:8080 and log in as admin with the generated password. Change the password under Tools > Password and Language.
Step 3 - Allowing the slave to reach the master database
The slave installer writes its server record and a dedicated database user into the master's dbispconfig database, so it needs root access to the master's MariaDB over the network. You will create a root account that can log in only from the slave's IP.
On the master, make MariaDB listen on the private IP instead of only on localhost. Open the server configuration:
sudo nano /etc/mysql/mariadb.conf.d/50-server.cnf
Find the bind-address line in the [mysqld] section and set it to the master's private IP:
[mysqld]
bind-address = 10.0.0.11
Restart MariaDB and confirm it listens on that address:
sudo systemctl restart mariadb
sudo ss -tlnp | grep 3306
LISTEN 0 80 10.0.0.11:3306 0.0.0.0:* users:(("mariadbd",pid=2231,fd=24))
Now open the MariaDB shell with the root password printed by the autoinstaller:
sudo mysql -u root -p
Create the remote root account for the slave. Use the MySQL root password of the master or another strong password in place of your_strong_password:
CREATE USER 'root'@'10.0.0.12' IDENTIFIED BY 'your_strong_password';
GRANT ALL PRIVILEGES ON *.* TO 'root'@'10.0.0.12' WITH GRANT OPTION;
FLUSH PRIVILEGES;
EXIT;
If UFW is active on the master (sudo ufw status), allow port 3306 only from the slave:
sudo ufw allow from 10.0.0.12 to any port 3306 proto tcp
NoteISPConfig can also manage UFW from System > Firewall in the panel. If you use that section later, run
sudo ufw statusafterwards and confirm the rule for 3306 is still there.
From the slave, test the connection. Install the MariaDB client temporarily if the command is missing (sudo apt install mariadb-client):
mysql -h server1.your_domain -u root -p -e "SHOW DATABASES LIKE 'dbispconfig';"
+------------------------+
| Database (dbispconfig) |
+------------------------+
| dbispconfig |
+------------------------+
If the connection times out, check the firewall rule and bind-address. If you get Access denied, check the IP in the CREATE USER statement.
Step 4 - Installing ISPConfig on the slave
On the slave, download the same autoinstaller. This node will only host websites and databases, so disable mail, DNS, Roundcube, phpMyAdmin and Mailman. The --interactive flag is required: it runs the ISPConfig setup in expert mode, which is the only mode that can join an existing multi-server setup.
curl -fsSL -o ispconfig-ai.sh https://get.ispconfig.org
sudo sh ispconfig-ai.sh --use-nginx --no-mail --no-dns --no-roundcube --no-pma --no-mailman --interactive --lang=en
Use the same web server (--use-nginx or the Apache default) as on the master, so website settings behave the same on every node.
The autoinstaller first installs the packages and then starts the ISPConfig setup, which asks questions. Answer the important ones as follows and accept the default for the rest:
| Prompt | Answer |
|---|---|
| Installation mode (standard,expert) | expert |
| Full qualified hostname (FQDN) of the server | server2.your_domain |
| MySQL server hostname / root user / password | Accept the local defaults |
| Shall this server join an existing ISPConfig multiserver setup (y,n) | y |
| MySQL master server hostname | server1.your_domain |
| MySQL master server port | 3306 |
| MySQL master server root username | root |
| MySQL master server root password | The password from Step 3 |
| MySQL master server database name | dbispconfig |
| Configure Mail / DNS | n |
| Configure Web Server | y |
| Install ISPConfig Web Interface | n |
When the setup asks which services to configure, only the ones you answer y to are managed on this node. The web interface stays on the master only. At the end, the autoinstaller prints the local MySQL root password of the slave; store it as well.
When the installation finishes, confirm that the ISPConfig server script is scheduled in root's crontab. This script polls the master for pending changes every minute:
sudo crontab -l | grep server.sh
* * * * * /usr/local/ispconfig/server/server.sh 2>&1 | while read line; do echo `/bin/date` "$line" >> /var/log/ispconfig/cron.log; done
Step 5 - Verifying the new server in the master panel
Log in to the panel on the master and go to System > Server Services. You should now see two entries, server1.your_domain and server2.your_domain. Open server2.your_domain and check that only the services you installed are ticked (for this example, Webserver and DB-Server). Untick any service that is not installed on that node, then save.
Go to Monitor and choose server2.your_domain in the server selector at the top. After a few minutes the Server State page shows the status of Nginx, PHP-FPM and MariaDB on the slave, which confirms that monitoring data is flowing back to the master.
Step 6 - Creating a website on the slave
Now create a site and let ISPConfig deploy it on the second node. In the panel:
- Go to Sites > Website > Add new website.
- In Server, select
server2.your_domain. - Enter the domain, for example
site.your_domain, choose the PHP mode (PHP-FPM) and save.
ISPConfig writes the change to a job queue in the master database. Within a minute the slave's server.sh picks it up and creates the site. On the slave, check that the directory exists:
ls /var/www/
clients html site.your_domain
Point the DNS A record of site.your_domain to the slave's public IP, then open it in a browser. You can enable Let's Encrypt for the site in its Website settings once DNS resolves.
If nothing appears after a couple of minutes, check the red job-queue indicator at the top of the panel and read /var/log/ispconfig/cron.log on the slave.
Step 7 - Keeping the setup updated
In a multi-server setup, always update the master first and then each slave. On every server run:
sudo ispconfig_update.sh
Choose the stable channel. When a slave asks whether to reconfigure permissions in the master database, answer yes and enter the master root password from Step 3. This is why the remote root account for each slave should be kept, restricted to that slave's IP.
Troubleshooting
- Changes stay pending in the job queue: the slave cannot reach the master database. From the slave, repeat the
mysql -h server1.your_domaintest from Step 3 and read/var/log/ispconfig/cron.log. - The slave setup cannot connect to the master database: the master hostname does not resolve on the slave, port 3306 is filtered or the remote root account uses a different IP. Check
/etc/hostson the slave, andbind-address, UFW and theCREATE USERhost on the master. - Let's Encrypt failed for the hostname during installation: the A record of the server's FQDN did not point to its public IP. Fix DNS; the panel still works with a self-signed certificate in the meantime.
Conclusion
You now have a two-node ISPConfig installation: the master holds the panel and the central database, and the slave hosts websites that you manage from the same interface. You can add more nodes by repeating Steps 3 and 4 with their own IPs, for example a dedicated mail server with --no-web or a secondary DNS server. Consider also setting up regular backups of the master's dbispconfig database, since every node depends on it.
