L0007 - Multiple Web Applications in IIS¶
Some clients may want the RMS Server component of Kensium POS to be hosted on IIS in parallel with other client web applications.
This topic describes several options that can be used to configure multiple web applications on the same IIS instance.
Options¶
IIS supports several methods to differentiate and route incoming requests to the correct application.
a. Different IP Addresses¶
IIS can bind each web application to a unique IP address. This method is effective when the server has (or can have) multiple IP addresses assigned, and provides a clear way to segregate web application traffic.
With this method:
- Each application is represented by an IIS Website.
- The Website bindings are set to a specific IP address.
- Each application also has its own host/domain name.
- Each application and its own SSL certificate (unless a wildcard SSL certificate can be used across applications).
Note
This method is suitable only if multiple IP addresses can be easily configured for the IIS server. There may be network considerations that make one the other options more attractive.
An example configuration is:
- The client's App1 would be bound to
10.0.2.10and have its own host nameapp1.client-org.com. - RMS would be bound to
10.0.2.11and have its own host namerms.client-org.com.
Steps¶
- Open IIS Manager.
- Right-click the site > Edit Bindings.
- Add a new binding with the specific IP address and port.
b. Host Headers (Domain Names)¶
Host headers allow IIS to differentiate applications based on the domain name in the HTTP request. This is efficient for hosting multiple websites on a single IP address.
This method is similar to using different IP addresses:
- Each application is represented by an IIS Website.
- The Website bindings are set to specific host names and share a single IP address.
- Each application also has its own host/domain name.
- Each application and its own SSL certificate (unless a wildcard SSL certificate can be used across applications).
Note
One small disadvantage over the IP address method is that web application traffic is segregated only at the IIS application layer, and not at the IP address level (which may be an issue if the client wishes to enforce certain access through IP-based firewall rules, for example). This approach works well, otherwise, and is recommended for most production RMS deployments.
An example configuration is:
- The client's App1 would be bound to host name
app1.client-org.com. - RMS would be bound to host name
rms.client-org.com.
Steps¶
- Ensure DNS or local hosts file maps both domains to the server IP.
- In IIS Manager, set the Host Name in the site bindings.
c. IIS Virtual Folders¶
IIS allows hosting multiple applications within the same website by configuring virtual folders (also known as virtual directories). This method is useful when you want to organize applications under a common domain or path.
With this method:
- All applications share the same IIS Website (and domain name and SSL certificate).
- One application may be at the site root.
- Other applications are in their own virtual folders.
This method is recommended for internal test, demonstration and development environments.
Warning
This method is not recommended for most production RMS environments. Applications in virtual folders share the same site context, which can lead to security risks if not properly isolated. URL routing issues may also arise if applications have overlapping paths or route definitions.
An example configuration is:
- The client's App1 would be bound to the site root folder
host.client-org.com/. - RMS would be bound to its own virtual folder
host.client-org.com/rms.
Steps¶
- Open IIS Manager.
- Expand the site node and right-click on it.
- Select 'Add Virtual Directory'.
- Specify an alias (e.g., 'app1') and the physical path to the application.
- Optionally, convert the virtual directory to an application by right-clicking and selecting 'Convert to Application'.
d. Different Ports¶
It is also possible to bind applications to IIS through TCP port numbers.
This approach is not recommended (and not described here) as it has several significant disadvantages:
- Users must remember port numbers when accessing the web applications. These can be hard to remember and enter in configuration screens.
- Non-standard ports typically require additional firewall or proxy rule configuration.
Combining Methods¶
IIS also supports combining these methods for more granular control. For example, you can host multiple applications on different ports and IPs, or use host headers with SSL SNI (Server Name Indication) to serve secure content for multiple domains.
More Information¶
See the following Microsoft Learn documentation for more information about IIS sites, applications and virtual folders: