Nginx is one of the most popular web servers in the world — fast, lightweight, and trusted by Netflix, Cloudflare, and millions of smaller sites. If you run an Ubuntu 24.04 server (a VPS from DigitalOcean, Hetzner, AWS, or any host), installing Nginx takes less than ten minutes. This guide walks you through every step: installation, firewall setup, verification, basic management, and fixes for the most common errors.
Prerequisites
- An Ubuntu 24.04 server (or 22.04 — the steps are identical) with sudo access
- SSH access to the server
- A domain name is optional for now — you can test everything with the server's IP address
Step 1 — Update the package index
Always start by refreshing Ubuntu's package lists so you install the latest available Nginx build:
sudo apt update
This doesn't install anything — it just makes sure apt knows about the newest package versions.
Step 2 — Install Nginx
Now install Nginx itself:
sudo apt install nginx -y
The -y flag answers "yes" to the confirmation prompt automatically. Ubuntu will download Nginx and its dependencies, which usually takes under a minute.
Step 3 — Allow web traffic through the firewall
Ubuntu 24.04 ships with UFW (Uncomplicated Firewall). If it's active, HTTP and HTTPS traffic will be blocked until you allow them. Nginx registers ready-made UFW profiles, so this is easy:
sudo ufw allow 'Nginx Full'
Nginx Full opens both port 80 (HTTP) and port 443 (HTTPS). If you only want plain HTTP for now, use 'Nginx HTTP' instead. Check that UFW is running and the rule is active:
sudo ufw status
You should see Nginx Full listed with ALLOW. If UFW shows as inactive and you want to enable it, run sudo ufw enable — but be careful: if you're connected over SSH, first run sudo ufw allow OpenSSH or you'll lock yourself out.
Step 4 — Verify Nginx is running
Ubuntu starts Nginx automatically after installation. Confirm with:
sudo systemctl status nginx
Look for active (running) in green. Press q to exit the status view.
Step 5 — Test it in your browser
Find your server's public IP address:
curl -4 icanhazip.com
Open http://YOUR_SERVER_IP in a browser. You should see the Nginx welcome page — "Welcome to nginx!" That page lives at /var/www/html/index.nginx-debian.html and confirms everything works.
No browser handy? Test from the terminal instead:
curl -I http://localhost
A 200 OK response with a Server: nginx header means success.
Step 6 — Learn the basic management commands
You'll use these constantly:
sudo systemctl start nginx # start the server
sudo systemctl stop nginx # stop the server
sudo systemctl restart nginx # stop + start (brief downtime)
sudo systemctl reload nginx # reload config with ZERO downtime
sudo systemctl enable nginx # auto-start on boot (already enabled by default)
sudo systemctl status nginx # check if it's running
Prefer reload over restart after config changes — it applies the new configuration without dropping active connections.
Step 7 — Understand the file layout
Before changing anything, know where things live:
/etc/nginx/nginx.conf— the main configuration file/etc/nginx/sites-available/— server block (virtual host) definitions/etc/nginx/sites-enabled/— symlinks to the sites that are actually active/var/www/html/— the default website's files/var/log/nginx/access.loganderror.log— your best friends when debugging
Step 8 — Create your first server block (optional but recommended)
A server block lets Nginx serve a specific domain. Create a directory for your site and a test page:
sudo mkdir -p /var/www/example.com/html
sudo chown -R $USER:$USER /var/www/example.com/html
echo '<h1>It works!</h1>' > /var/www/example.com/html/index.html
Now create the server block file:
sudo nano /etc/nginx/sites-available/example.com
Paste this in (replace example.com with your domain):
server {
listen 80;
listen [::]:80;
root /var/www/example.com/html;
index index.html;
server_name example.com www.example.com;
location / {
try_files $uri $uri/ =404;
}
}
Enable it by creating a symlink, test the configuration, then reload:
sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginx
nginx -t is the single most important habit: it validates your config before Nginx tries to use it. If it reports syntax is ok and test is successful, you're safe to reload.
Verify it worked
curl -I http://YOUR_SERVER_IPreturns200 OKwithServer: nginx- The browser shows the Nginx welcome page (or your own
index.html) sudo systemctl is-enabled nginxprintsenabled(survives reboots)
Common issues & fixes
"Connection refused" in the browser
Nginx probably isn't running, or the firewall is blocking port 80. Run sudo systemctl status nginx and sudo ufw status — one of them will show the problem.
Port 80 already in use
Another web server (often Apache) is holding the port. Check with sudo ss -tlnp | grep :80, then stop the other service (sudo systemctl stop apache2) or remove it if you don't need it.
403 Forbidden
Almost always a permissions problem on your web root. The Nginx worker user (www-data) must be able to read the files: sudo chown -R www-data:www-data /var/www/example.com/html and make sure directories have 755 and files 644 permissions.
nginx -t reports an error after editing config
Read the error line number carefully — it's usually a missing semicolon or an unclosed brace. Fix it, run nginx -t again, and only then reload. Never reload with a failing config test.
Welcome page still shows after adding your site
The default server block is catching the request. Either delete the default symlink (sudo rm /etc/nginx/sites-enabled/default) or make sure your server_name matches the domain you're visiting, then reload.
Nginx is now installed, secured behind UFW, verified working, and you know how to manage it and host your own sites with server blocks. The natural next steps are pointing a domain at the server and adding free HTTPS with Let's Encrypt. If you'd rather have an expert handle your server setup, XpertBees configures and hardens Ubuntu servers for clients every week — get in touch.
