Skip to content

L0007 - Multiple Web Applications in IIS

Some clients may want the RMS Server component of Kensium POS to be hosted on IIS in parallel with other client web applications.

This topic describes several options that can be used to configure multiple web applications on the same IIS instance.

Options

IIS supports several methods to differentiate and route incoming requests to the correct application.

a. Different IP Addresses

IIS can bind each web application to a unique IP address. This method is effective when the server has (or can have) multiple IP addresses assigned, and provides a clear way to segregate web application traffic.

With this method:

  • Each application is represented by an IIS Website.
  • The Website bindings are set to a specific IP address.
  • Each application also has its own host/domain name.
  • Each application and its own SSL certificate (unless a wildcard SSL certificate can be used across applications).

Note

This method is suitable only if multiple IP addresses can be easily configured for the IIS server. There may be network considerations that make one the other options more attractive.

An example configuration is:

  • The client's App1 would be bound to 10.0.2.10 and have its own host name app1.client-org.com.
  • RMS would be bound to 10.0.2.11 and have its own host name rms.client-org.com.

Steps

  1. Open IIS Manager.
  2. Right-click the site > Edit Bindings.
  3. Add a new binding with the specific IP address and port.

b. Host Headers (Domain Names)

Host headers allow IIS to differentiate applications based on the domain name in the HTTP request. This is efficient for hosting multiple websites on a single IP address.

This method is similar to using different IP addresses:

  • Each application is represented by an IIS Website.
  • The Website bindings are set to specific host names and share a single IP address.
  • Each application also has its own host/domain name.
  • Each application and its own SSL certificate (unless a wildcard SSL certificate can be used across applications).

Note

One small disadvantage over the IP address method is that web application traffic is segregated only at the IIS application layer, and not at the IP address level (which may be an issue if the client wishes to enforce certain access through IP-based firewall rules, for example). This approach works well, otherwise, and is recommended for most production RMS deployments.

An example configuration is:

  • The client's App1 would be bound to host name app1.client-org.com.
  • RMS would be bound to host name rms.client-org.com.

Steps

  1. Ensure DNS or local hosts file maps both domains to the server IP.
  2. In IIS Manager, set the Host Name in the site bindings.

c. IIS Virtual Folders

IIS allows hosting multiple applications within the same website by configuring virtual folders (also known as virtual directories). This method is useful when you want to organize applications under a common domain or path.

With this method:

  • All applications share the same IIS Website (and domain name and SSL certificate).
  • One application may be at the site root.
  • Other applications are in their own virtual folders.

This method is recommended for internal test, demonstration and development environments.

Warning

This method is not recommended for most production RMS environments. Applications in virtual folders share the same site context, which can lead to security risks if not properly isolated. URL routing issues may also arise if applications have overlapping paths or route definitions.

An example configuration is:

  • The client's App1 would be bound to the site root folder host.client-org.com/.
  • RMS would be bound to its own virtual folder host.client-org.com/rms.

Steps

  1. Open IIS Manager.
  2. Expand the site node and right-click on it.
  3. Select 'Add Virtual Directory'.
  4. Specify an alias (e.g., 'app1') and the physical path to the application.
  5. Optionally, convert the virtual directory to an application by right-clicking and selecting 'Convert to Application'.

d. Different Ports

It is also possible to bind applications to IIS through TCP port numbers.

This approach is not recommended (and not described here) as it has several significant disadvantages:

  • Users must remember port numbers when accessing the web applications. These can be hard to remember and enter in configuration screens.
  • Non-standard ports typically require additional firewall or proxy rule configuration.

Combining Methods

IIS also supports combining these methods for more granular control. For example, you can host multiple applications on different ports and IPs, or use host headers with SSL SNI (Server Name Indication) to serve secure content for multiple domains.

More Information

See the following Microsoft Learn documentation for more information about IIS sites, applications and virtual folders: