Skip to content

Set Up a Web Server with Nginx

Nginx is software that can be used as a web server, reverse proxy, and for other purposes. In this article, we install Nginx from a package in an RHEL-compatible environment such as AlmaLinux and publish web content over HTTP while keeping SELinux in Enforcing mode.

The setup covers not only installing Nginx, but also checking its configuration, starting it and enabling automatic startup with systemd, placing web content and adjusting SELinux labels, and allowing HTTP traffic with firewalld.

Finally, we access the server over HTTP both from the server itself and from another device, and verify that the sample content example can be retrieved.

Use an RHEL-compatible environment that meets the following conditions.

  • Packages can be installed with dnf
  • systemd is used
  • SELinux is available
  • firewalld is available
  • Administrative operations can be performed with sudo
  • After setup, the server can be reached over HTTP from another device

This article does not disable SELinux. We first confirm that SELinux is in Enforcing mode, then verify the HTTP response after publishing the web content while keeping Enforcing enabled.

To verify access from another device, you need the actual IP address of the configured server.

Values that differ between environments are represented as follows.

Variable nameConfiguration exampleDescription
<<SERVER_IP>>192.0.2.10Destination address used to connect to Nginx over HTTP from another device

When running the commands manually, replace <<SERVER_IP>> with the actual IP address of the target server.

Step 1: Verify that SELinux is in Enforcing mode

Section titled “Step 1: Verify that SELinux is in Enforcing mode”

First, check the current SELinux mode. The first line displays the current value, and the second line exits successfully only when the mode is Enforcing.

Terminal window
sudo getenforce
test "$(sudo getenforce)" = "Enforcing"

If Enforcing is displayed and the entire code block completes successfully, the prerequisite is satisfied.

If SELinux is set to Permissive or Disabled, Nginx running in that state does not meet the completion conditions of this article. Begin the procedure in an environment where SELinux is set to Enforcing.

Install Nginx and curl, which will later be used to verify the HTTP response from the server itself.

With set -e, the remaining commands in this block will not run if an earlier command fails.

Terminal window
set -e
sudo dnf install -y nginx curl
sudo rpm -q nginx

If the final command displays information about the installed Nginx package and completes successfully, the installation is complete.

If the Nginx package cannot be obtained, do not proceed to start the service. First check the repository configuration of the RHEL-compatible environment you are using.

Before starting the service, verify that Nginx can read the current configuration file correctly.

Terminal window
sudo nginx -t

If the syntax is valid and the configuration test succeeds, proceed to the next step.

If the check fails at this stage, review and correct the indicated configuration file and error message. Repeatedly starting the service while the configuration check is failing will not resolve the configuration problem.

Step 4: Start Nginx and enable automatic startup

Section titled “Step 4: Start Nginx and enable automatic startup”

Start Nginx and configure it to start automatically when the operating system boots. Then check the current service state and automatic startup setting separately.

Terminal window
set -e
sudo systemctl enable --now nginx
sudo systemctl is-enabled nginx
sudo systemctl is-active nginx

If is-enabled returns enabled and is-active returns active, the configuration is successful.

Even if Nginx is currently running, it will not start automatically after an operating system reboot if automatic startup is disabled. Conversely, even if automatic startup is enabled, a currently stopped service cannot process HTTP requests. Check both states.

Step 5: Publish web content and adjust the SELinux label

Section titled “Step 5: Publish web content and adjust the SELinux label”

Place a sample page in /usr/share/nginx/html/, the location used for Nginx web content.

To make the connectivity check result easy to identify, use example as the page content. After placing the file, run restorecon to apply the SELinux context defined for the path.

Terminal window
set -e
printf '%s\n' 'example' | sudo tee /usr/share/nginx/html/index.html >/dev/null
sudo restorecon -v /usr/share/nginx/html/index.html
sudo grep -Fq 'example' /usr/share/nginx/html/index.html
sudo ls -Z /usr/share/nginx/html/index.html | grep -Fq 'httpd_sys_content_t'

If all commands complete successfully, the sample content has been published and the file is being handled with an SELinux type appropriate for web content.

For example, when a file is moved from another directory, its original SELinux context may remain. If you encounter an access problem, do not disable SELinux; first check the context of the affected file.

Step 6: Permanently allow HTTP with firewalld

Section titled “Step 6: Permanently allow HTTP with firewalld”

Start firewalld and allow the HTTP service so that another device can connect to Nginx.

After adding HTTP to the permanent configuration, reload the configuration and check both the permanent configuration and the currently active configuration.

Terminal window
set -e
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --reload
sudo firewall-cmd --permanent --query-service=http
sudo firewall-cmd --query-service=http

If the last two checks both return yes, the HTTP service is allowed in both the permanent configuration and the current runtime configuration.

If a network interface is explicitly assigned to another firewalld zone, also check the configuration of the zone actually used for communication.

Instead of stopping firewalld entirely to work around a problem, configure only the required HTTP traffic as allowed.

Step 7: Verify the HTTP response from the server itself

Section titled “Step 7: Verify the HTTP response from the server itself”

Before testing access from an external device, first access Nginx over HTTP from the server on which it is configured.

At the same time, verify again that SELinux is still in Enforcing mode and retrieve the sample content that was published.

Terminal window
set -e
sudo getenforce
test "$(sudo getenforce)" = "Enforcing"
curl -fsS http://127.0.0.1/ | grep -F 'example'

If Enforcing is displayed and example can be retrieved from the HTTP response, Nginx is responding to local HTTP requests while SELinux remains in Enforcing mode.

If this step fails, check the Nginx status, configuration, published file, and SELinux context before investigating the external network.

Step 8: Verify the HTTP response from another device

Section titled “Step 8: Verify the HTTP response from another device”

Finally, access the server over HTTP from a device other than the Nginx server.

Replace <<SERVER_IP>> with the actual IP address assigned to the configured server.

Terminal window
curl -fsS "http://<<SERVER_IP>>/" | grep -F 'example'

If example can be retrieved, the other device can reach the server over TCP port 80 and retrieve the Nginx web content published in this procedure.

By checking not only that the HTTP connection succeeds but also that the expected sample text is returned, you can avoid mistakenly treating a connection to a different web page as a successful result.

When publishing Nginx in an RHEL-compatible environment such as AlmaLinux, simply installing the package and starting the service is not enough. It is important to verify the configuration, SELinux, firewalld, and the HTTP response step by step.

In this article, we first verified that SELinux was in Enforcing mode, installed Nginx, and then performed the configuration check, startup and automatic startup configuration with systemd, web content publication, SELinux label adjustment, and HTTP authorization with firewalld.

If example can finally be retrieved both from the server itself and from another device, this confirms that Nginx is running while SELinux remains in Enforcing mode and that the web server is externally accessible over HTTP.

Category: Linux