Post Date: September 25, 2026
Last Updated: September 25, 2026
Introduction
By default, Nginx listens for HTTP traffic on port 80. However, there are situations where Nginx needs to use an alternate port such as 8080. This is common when another web server, such as Apache, is already using port 80, or when an application requires Nginx to listen on a separate port.
Changing the Nginx listening port involves more than updating the listen directive. On systems with SELinux enabled, the new port must also be permitted by the SELinux policy. If the server firewall or cloud security rules restrict the port, those settings must be updated as well.
Prerequisites
Before proceeding, make sure you have:
- A Linux server with Nginx installed
- Root or sudo access
- Access to the Nginx configuration
- Port 8080 available on the server
- Basic Linux command-line knowledge
- Access to the server firewall configuration, if required
- Access to the cloud security group or network firewall, if applicable
Note: Another service cannot use the same IP address and TCP port that Nginx is configured to use.
You can check whether port 8080 is already in use:
sudo ss -ltnp | grep :8080
If there is no output, port 8080 is generally available.
Step 1: Install Nginx
If Nginx is not already installed, install it using your Linux distribution’s package manager.
RHEL / CentOS
On systems where EPEL is required:
sudo yum install epel-release
Install Nginx:
sudo yum install nginx
On newer RHEL-based systems, dnf can be used:
sudo dnf install nginx
Ubuntu / Debian
sudo apt update sudo apt install nginx
After installation, verify the Nginx version:
nginx -v
Step 2: Identify the Nginx Configuration File
The configuration file location depends on the Linux distribution and installation method.
RHEL / CentOS
The main configuration file is generally:
/etc/nginx/nginx.conf
Ubuntu / Debian
The main configuration file is generally:
/etc/nginx/nginx.conf
Individual virtual host configurations are commonly stored under:
/etc/nginx/sites-available/
and enabled through:
/etc/nginx/sites-enabled/
For example:
/etc/nginx/sites-available/default /etc/nginx/sites-enabled/default
You can inspect the complete active Nginx configuration with:
sudo nginx -T
This is useful when you are unsure which configuration file contains the listen directive.
Step 3: Back Up the Nginx Configuration
Before making configuration changes, create a backup.
For the main configuration:
sudo cp /etc/nginx/nginx.conf /etc/nginx/nginx.conf.backup
If you are modifying a specific virtual host configuration, back up that file instead.
For example:
sudo cp /etc/nginx/sites-available/default /etc/nginx/sites-available/default.backup
Having a configuration backup makes it easier to revert the change if an issue occurs.
Step 4: Change the Nginx Listening Port
Open the appropriate configuration file.
For example:
sudo nano /etc/nginx/nginx.conf
Look for a listen directive similar to:
listen 80;
Change it to:
listen 8080;
If the configuration uses default_server, preserve that option:
listen 8080 default_server;
A basic server block may look like:
server {
listen 8080;
server_name example.com;
root /var/www/html;
index index.html index.htm;
}
If you are using a separate virtual host file, make the change in that server block instead.
Step 5: Test the Nginx Configuration
Before restarting Nginx, validate the configuration:
sudo nginx -t
A successful test should show output similar to:
syntax is ok test is successful
If Nginx reports an error, fix the configuration before continuing.
This validation step is important because restarting Nginx with an invalid configuration can prevent the service from starting.
Step 6: Configure SELinux for Port 8080
On RHEL/CentOS systems with SELinux enabled and enforcing, Nginx may not be permitted to bind to port 8080 unless that port is associated with the appropriate SELinux HTTP port type.
First, check the SELinux status:
sestatus
If SELinux is enforcing, check the ports currently associated with HTTP services:
sudo semanage port -l | grep http_port_t
If the semanage command is not available, install the required SELinux management package.
On many RHEL/CentOS systems:
sudo yum install policycoreutils-python-utils
On some older distributions, the package name may be different.
Add port 8080 to the HTTP port type:
sudo semanage port -a -t http_port_t -p tcp 8080
Verify the configuration:
sudo semanage port -l | grep http_port_t
Port 8080 should now appear in the list.
If port 8080 is already defined
If SELinux already has an entry for port 8080 but it is associated with another port type, modify it:
sudo semanage port -m -t http_port_t -p tcp 8080
Important: Disabling SELinux is not required just to make Nginx listen on port 8080. Configure the appropriate SELinux policy instead.
Step 7: Allow Port 8080 Through the Firewall
Nginx can listen on port 8080 while external clients are still unable to connect if the server firewall blocks the port.
If your server uses firewalld, allow TCP port 8080:
sudo firewall-cmd --permanent --add-port=8080/tcp
Reload the firewall:
sudo firewall-cmd --reload
Verify the configuration:
sudo firewall-cmd --list-ports
You should see:
8080/tcp
Ubuntu / Debian with UFW
If UFW is enabled, allow port 8080:
sudo ufw allow 8080/tcp
Verify:
sudo ufw status
Note: Only open port 8080 if external access is actually required. If the port is intended for internal communication, restrict access to the required source networks instead of exposing it publicly.
Step 8: Check Cloud Firewall or Security Group Rules
If the server is hosted on a cloud platform, the operating system firewall may not be the only network control.
For example, on AWS, check the EC2 Security Group and ensure the required inbound rule exists:
Protocol: TCP Port: 8080 Source: Required IP range
Avoid using 0.0.0.0/0 unless public access to port 8080 is genuinely required.
The same principle applies to other cloud providers and network firewalls.
Step 9: Restart Nginx
After updating the configuration and firewall/SELinux settings, restart Nginx:
sudo systemctl restart nginx
Check the service status:
sudo systemctl status nginx
If Nginx fails to start, check the service logs:
sudo journalctl -u nginx --no-pager -n 50
You can also check the Nginx error log:
sudo tail -f /var/log/nginx/error.log
Step 10: Verify That Nginx Is Listening on Port 8080
Use the ss command to check the listening sockets:
sudo ss -ltnp | grep :8080
You should see output similar to:
LISTEN 0 511 0.0.0.0:8080 0.0.0.0:* users:(("nginx",pid=1234,fd=6))
For IPv6, you may also see:
LISTEN 0 511 [::]:8080 [::]:* users:(("nginx",pid=1234,fd=7))
You can also use:
sudo netstat -lntp | grep :8080
However, ss is generally preferred on modern Linux systems.
Step 11: Test the Website Locally
Before testing from another system, verify the service locally.
Use:
curl -I http://127.0.0.1:8080
A working web server should return an HTTP response such as:
HTTP/1.1 200 OK
Depending on the application, you may instead receive another valid HTTP status such as 301, 302, 403, or 404. The important point is that the request reaches Nginx and receives an HTTP response.
You can also test the configured server name:
curl -I http://example.com:8080
Step 12: Test From a Remote System
If port 8080 is intended to be accessible externally, open:
http://SERVER_IP:8080
For example:
http://10.1.1.1:8080
For a public server:
http://your-domain.com:8080
You can also test connectivity using:
curl -I http://SERVER_IP:8080
If the local test works but the remote test fails, check:
- Linux firewall
- Cloud security group
- Network firewall
- Routing
- Nginx listening address
- DNS configuration, if using a hostname
Troubleshooting
Nginx fails to start
First test the configuration:
sudo nginx -t
Then check:
sudo systemctl status nginx
and:
sudo journalctl -u nginx --no-pager -n 50
Port 8080 is already in use
Check:
sudo ss -ltnp | grep :8080
If another service is using the port, either stop or reconfigure that service, or select another available port.
SELinux blocks Nginx
Check for relevant AVC denials:
sudo ausearch -m AVC -ts recent
Then verify that port 8080 is associated with http_port_t:
sudo semanage port -l | grep http_port_t
Local access works but remote access fails
If this works:
curl -I http://127.0.0.1:8080
but this fails from another machine:
curl -I http://SERVER_IP:8080
check the firewall and cloud security rules first.
The browser cannot connect
Verify that Nginx is listening:
sudo ss -ltnp | grep :8080
Then test:
curl -I http://SERVER_IP:8080
Also confirm that the correct IP address and port are being used.
Security Considerations
Port 8080 is commonly used for alternate HTTP services, but changing the port does not make HTTP traffic secure.
If the application handles sensitive information, consider using HTTPS with a suitable TLS configuration.
For example, the public application may use:
https://example.com
while Nginx internally proxies requests to an application running on:
http://127.0.0.1:8080
This is different from exposing port 8080 directly to the public internet.
If port 8080 is only required for internal communication, restrict firewall access to trusted networks or hosts.
Configuration Summary
The basic change is:
Before
server {
listen 80;
server_name example.com;
}
After
server {
listen 8080;
server_name example.com;
}
Then validate and restart:
sudo nginx -t sudo systemctl restart nginx
Verify:
sudo ss -ltnp | grep :8080
And test:
curl -I http://127.0.0.1:8080
Conclusion
Configuring Nginx to use port 8080 is straightforward, but a successful configuration requires more than changing the listen directive.
The complete process should include:
- Updating the correct Nginx server block
- Testing the configuration before restarting
- Configuring SELinux when it is enforcing
- Allowing the port through the appropriate firewall
- Checking cloud security rules when applicable
- Restarting Nginx
- Verifying the listening socket
- Testing the application locally and remotely
Most importantly, do not disable SELinux simply to make Nginx work on port 8080. Configure the required SELinux policy and keep the server’s security controls enabled.
Frequently Asked Questions
1. What port does Nginx use by default?
Nginx normally listens for HTTP traffic on port 80 and HTTPS traffic on port 443, depending on the configured server blocks.
2. Why would I configure Nginx to use port 8080?
Port 8080 can be useful when port 80 is already occupied by another service, when running multiple web services, or when an application requires an alternate HTTP port.
3. How do I check whether port 8080 is available?
Run:
sudo ss -ltnp | grep :8080
If another process is listening on the port, you will need to use a different port or reconfigure the existing service.
4. Do I need to disable SELinux for port 8080?
No. If SELinux is enforcing, associate port 8080 with the appropriate HTTP port type:
sudo semanage port -a -t http_port_t -p tcp 8080
5. Why does Nginx work locally but not from another computer?
The most common causes include a blocked firewall port, cloud security group rules, network restrictions, or Nginx listening only on a local interface.
6. How can I verify that Nginx is listening on port 8080?
Run:
sudo ss -ltnp | grep :8080
You can also test the HTTP service with:
curl -I http://127.0.0.1:8080
Related Articles
How to setup SSL Certificate in Nginx on Ubuntu 20.04
How to install and configure PHP with Nginx on centos7
How to Install Nginx and Let’s Encrypt SSL with HTML + Docker – Ubuntu 20.04
Get Expert Linux & Server Support
Need help configuring Nginx, troubleshooting Linux servers, or resolving web server and networking issues? Our team can help with Linux administration, server configuration, security, and DevOps support.