We help IT Professionals succeed at work.

IIS WEB FARM

dano992
dano992 used Ask the Experts™
on
CURRENT SETUP:
one webfarm using 2 IIS webservers one SSL site.
need to configure second SSL site on same webfarm
(do not want touse different ssl port for second site)
what is the best way to accpomlpish this.
i was thinking creating a second virtual IP address one each server .
creating a new cluster
use this new virtual ip for this new IIS ssl WEBSITE.
NEED COMENTS OR SUGESTIONS ON THIS
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Mino DCSolution Consultant

Commented:
you have only two option:

Add new Virtual IP Address
or
Change port for ssl. (to be discarded because it's not what you want)

You can't have the same service on the same ip and port.

I would add a new VIP.
Distinguished Expert 2017

Commented:
You answered your own question, are you looking for a convincing argument why you should change your mind and use a different port versus setting up a virtual IP?
Using a different port would mean you are not taking an IP that may otherwise be used for some other purpose.
Presumably your web farm is behind a load-balancer which has to be configured any way, and I believe it takes fewer steps to configure a resource mapping to an existing IP new port versus to a new IP.

Author

Commented:
to add a second virtual ip do i need to create a second cluster for this new ip?
Brad HoweDevOps Manager
Top Expert 2011

Commented:
Correct,  A second VIP is required or another port other then 443.

To add the 2nd VIP - Open NLB manager, right click cluster properties, cluster IP Addresses, and add the new VIP.

Next, make sure that VIP is Nat'd to another static external IP that is different from the current SSL site.

From there make sure you associate the correct host headers to each webserver sites on the NODES that will be servicing this site.

Add the SSL Cert on one Node by using the IIS Wizard to create the request.

Export the SSL cert to the other Nodes using Certificate Manager.

Start browsing.

-Hades666


Brad HoweDevOps Manager
Top Expert 2011

Commented:
To add a second virtual ip do i need to create a second cluster for this new ip?
   The answer is no. If you did this you would need more network cards....

-Hades666
You have 2 options here.

1. Get a new VIP and assign it to new site. - If getting VIP is fast and doesnt have any issues with your company.

2. Use same IP and do port forwarding rule in firewall. Say your new site is at port 90. Any request coming to your new site will forward it to port 90.

Based on your companys convenience you can use one of the above.

Author

Commented:
i will need toi create a second cluster for this added site, what is involved
how many more nic will i need?
Brad HoweDevOps Manager
Top Expert 2011

Commented:
You will need 2 more NICs per Server and then configure the cluster to run on those. - Hades666
Brad HoweDevOps Manager
Top Expert 2011

Commented:
2 Nics total 1 /server.

Author

Commented:
so i would need an additional 2 nics on every web server that is going to be part of this web farm