SlideShare una empresa de Scribd logo
1 de 28
IIS vs. ApacheMyths and Reality
Apache - Overview Free web server. Often combined with Linux, MySQL, and PHP to make the LAMP stack. First released in 1995. Modular architecture. Built using an open source development model. Commercial friendly open-source license. Current Version is 2.2.9 which was released in June of 2008
IIS 6 Overview IIS 6.0 – A Solid Foundation Shipped with Windows Server 2003 Proven Security Significant reduction in attack surface compared to previous releases No security vulnerabilities since it’s release five years ago. Proven Scalability and Stability Used by many major sites and companies such as MySpace.com, Match.com, US Bank, USA Today, Allstate, Continental Airlines and others. Significant increase in reliability of hosted web sites compared to IIS 5.0. A solid trusted foundation for IIS 7.0
IIS7 Overview Benefits Features Reduced Attack Surface Create Streamlined Servers Modular and Extensible Integrated with .NET Improved Security Agile Administration Built in Request     Tracing Easier to ManageFast Diagnostics Extend/Modify IIS Features
Questions
Security“Which of the two platforms, IIS and Apache, is more secure?” IIS 7.0 Security Minimal Surface Area Automatic Site / Application Sandboxing Anonymous User Account Changes URL Authorization Built in Request Filtering Integrated Active Directory Authorization IIS / Security Development Lifecycle Automatic Update Patching Security Tracking – Secunia IIS 6 by comparison has only 5 advisories released to date. http://secunia.com/product/1438/?task=advisories Apache 2.0.x on the other hand has over 35, several of which are critical rated. http://secunia.com/product/73/?task=advisories
SecurityIndependent Commentary
Management“Is IIS or Apache easier to manage?” IIS 7.0 Manageability Centralized Web Farm Configuration Streamlined and Focused Administration Tool Remote Administration Tool Command Line Administration Rapid Troubleshooting and Limited Downtime AdHost -   Able to Reduce Site Setup Time to a Quarter of the Previous Time with IIS 7.0
ManagementIndependent Commentary
Performance / Scalability“Does Apache have better performance /scalability than IIS?” IIS 7.0 Performance/Scalability Leaner Web Servers Server Core Static and Dynamic Compression Output Caching Improvements Enterprise Level Performance “Match.com runs IIS 7.0 with 30 million page views daily.” “PlentyOffFish.com gets 1.2 billion page views a month.” “WS2008 and IIS 7.0 allow www.microsoft.com to process 122 million more requests at the same CPU level – compared to IIS 6.0” “MySpace.com runs IIS 7.0 with 23 billion page views a month.” HostMySite -   Now hosting 1,100 web sites per server / Up from 500 shared applications.
Performance / ScalabilityIndependent Commentary
Reliability“Which web server is more reliable?” IIS 7.0 Reliability Proven and Trusted Platform 54% of the Fortune 1000 rely on IIS 7.0 Rapid diagnostics tools to troubleshoot any concerns quickly Failed Request Tracing Runtime State and Control API. HiChina -   Reduced Application downtime by 99% for applications that were moved to     Windows Server 2008 and IIS.
ReliabilityIndependent Commentary
Modularity“Which is more modular, IIS or Apache?” IIS 7.0 Modularity Server functionality is split into 40 modules Only 10 modules installed by default Modules and a Generic Pipeline Extensibility
ModularityIndependent Commentary
Innovation“Is IIS or Apache a more innovative platform?” IIS 7.0 Innovation IIS 7.0 Admin Pack  URL Rewrite Module (Technical Preview) PowerShell Provider for IIS  Remote Manager – IIS 7 UI for Down-level Clients Web Playlists
InnovationIndependent Commentary
Troubleshooting“Is IIS or Apache an easier platform to troubleshoot?” IIS 7.0 Troubleshooting Detailed Error Messages Verbose Error Messages Suggests Causes and Solutions Details include configuration sections in question, modules in use, page, etc. Failed Request Tracing Allows for custom failure criteria per URL Persist Failure Log Files beyond process lifetime Common Usages Request take too long Request Error (completes but with error code)
TroubleshootingIndependent Commentary
Application Support“Does Apache support more Applications?” IIS 7.0 Application Support Extensible, modular architecture – add, remove or replace any built-in module Enhanced ASP.NET integration including unified configuration, HTTP runtime and administration tools Caching support (kernel and user) for all types of dynamic content Built-in FastCGI support for Open Source frameworks such as PHP and Ruby. Strong integration with other Enterprise Products such as SharePoint Extensive Support for Streaming Media
Application SupportIndependent Commentary
TCO“Does IIS or Apache have the lower TCO?” IIS 7.0  - Cost of Ownership Rapid Troubleshooting and Minimized Downtime Minimized Surface Area Isolation and Sandboxing Scalable Multi-Tenant Hosting Less Expensive Administrator Resources to Maintain Delegated Control to Site Owners Strong Microsoft Support Resources HiChina ,[object Object]
  Saved nearly 20% in overall maintenance and operating costs.,[object Object]
PHP Applications“Is Apache the best platform for PHP?” IIS 7.0 and PHP Support Consolidate .NET and PHP applications on a single server Consolidate Web and Other Server Management Frameworks to a single platform Better Web Platform Management Host on Minimal / Headless Server with Server Core Powerful Media Serving Microsoft Supported Solution
PHP ApplicationsIndependent Commentary
Summary IIS 7.0 has: A Modular and Extensible Architecture Deep integration with .NET Applications Improved Security Agile Administration  Built in Troubleshooting Tools such as Request Tracing This leads to a Web Platform that is: Streamlined Easy to extend To Manage Quick to Troubleshoot Highly Secure
IIS Resources Technical Communities, Webcasts, Blogs, Chats & User Groupshttp://www.microsoft.com/communities/default.mspx Microsoft Learning and Certificationhttp://www.microsoft.com/learning/default.mspx Microsoft Developer Network (MSDN) & TechNet http://microsoft.com/msdnhttp://microsoft.com/technet Trial Software and Virtual Labshttp://www.microsoft.com/technet/downloads/trials/default.mspx IIS.Net http://www.iis.net http://forums.iis.net http://blogs.iis.net http://www.iis.net/downloads
© 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation.  Because Microsoft must respond to changing market conditions,it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation.  MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Más contenido relacionado

Destacado

Comparing IIS and Apache - Questions and Answers
Comparing IIS and Apache - Questions and AnswersComparing IIS and Apache - Questions and Answers
Comparing IIS and Apache - Questions and Answers
butest
 
Web Server Administration
Web Server AdministrationWeb Server Administration
Web Server Administration
webhostingguy
 
Deploying WO on Windows
Deploying WO on WindowsDeploying WO on Windows
Deploying WO on Windows
WO Community
 
Apache Web Server Architecture Chaitanya Kulkarni
Apache Web Server Architecture Chaitanya KulkarniApache Web Server Architecture Chaitanya Kulkarni
Apache Web Server Architecture Chaitanya Kulkarni
webhostingguy
 
Configuring the Apache Web Server
Configuring the Apache Web ServerConfiguring the Apache Web Server
Configuring the Apache Web Server
webhostingguy
 
Apache web server
Apache web serverApache web server
Apache web server
zrstoppe
 

Destacado (13)

Comparing IIS and Apache - Questions and Answers
Comparing IIS and Apache - Questions and AnswersComparing IIS and Apache - Questions and Answers
Comparing IIS and Apache - Questions and Answers
 
Web server administration
Web server administrationWeb server administration
Web server administration
 
Web Server Administration
Web Server AdministrationWeb Server Administration
Web Server Administration
 
Configuring linksys wireless router
Configuring linksys wireless routerConfiguring linksys wireless router
Configuring linksys wireless router
 
Deploying WO on Windows
Deploying WO on WindowsDeploying WO on Windows
Deploying WO on Windows
 
Apache Presentation
Apache PresentationApache Presentation
Apache Presentation
 
Wireless Networking Security
Wireless Networking SecurityWireless Networking Security
Wireless Networking Security
 
Apache Web Server Architecture Chaitanya Kulkarni
Apache Web Server Architecture Chaitanya KulkarniApache Web Server Architecture Chaitanya Kulkarni
Apache Web Server Architecture Chaitanya Kulkarni
 
Configuring the Apache Web Server
Configuring the Apache Web ServerConfiguring the Apache Web Server
Configuring the Apache Web Server
 
Agile & Secure SDLC
Agile & Secure SDLCAgile & Secure SDLC
Agile & Secure SDLC
 
Apache web server
Apache web serverApache web server
Apache web server
 
IIS
IISIIS
IIS
 
WAP- Wireless Application Protocol
WAP- Wireless Application ProtocolWAP- Wireless Application Protocol
WAP- Wireless Application Protocol
 

Más de Information Technology (20)

Web303
Web303Web303
Web303
 
Sql Server Security Best Practices
Sql Server Security Best PracticesSql Server Security Best Practices
Sql Server Security Best Practices
 
SAN
SANSAN
SAN
 
SAN Review
SAN ReviewSAN Review
SAN Review
 
SQL 2005 Disk IO Performance
SQL 2005 Disk IO PerformanceSQL 2005 Disk IO Performance
SQL 2005 Disk IO Performance
 
RAID Review
RAID ReviewRAID Review
RAID Review
 
Review of SQL
Review of SQLReview of SQL
Review of SQL
 
Sql 2005 high availability
Sql 2005 high availabilitySql 2005 high availability
Sql 2005 high availability
 
MOSS 2007 Deployment Fundamentals -Part2
MOSS 2007 Deployment Fundamentals -Part2MOSS 2007 Deployment Fundamentals -Part2
MOSS 2007 Deployment Fundamentals -Part2
 
MOSS 2007 Deployment Fundamentals -Part1
MOSS 2007 Deployment Fundamentals -Part1MOSS 2007 Deployment Fundamentals -Part1
MOSS 2007 Deployment Fundamentals -Part1
 
Clustering and High Availability
Clustering and High Availability Clustering and High Availability
Clustering and High Availability
 
F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)F5 beyond load balancer (nov 2009)
F5 beyond load balancer (nov 2009)
 
WSS 3.0 & SharePoint 2007
WSS 3.0 & SharePoint 2007WSS 3.0 & SharePoint 2007
WSS 3.0 & SharePoint 2007
 
SharePoint Topology
SharePoint Topology SharePoint Topology
SharePoint Topology
 
Sharepoint Deployments
Sharepoint DeploymentsSharepoint Deployments
Sharepoint Deployments
 
Microsoft Clustering
Microsoft ClusteringMicrosoft Clustering
Microsoft Clustering
 
Scalable Internet Servers and Load Balancing
Scalable Internet Servers and Load BalancingScalable Internet Servers and Load Balancing
Scalable Internet Servers and Load Balancing
 
Web Hacking
Web HackingWeb Hacking
Web Hacking
 
Migration from ASP to ASP.NET
Migration from ASP to ASP.NETMigration from ASP to ASP.NET
Migration from ASP to ASP.NET
 
Internet Traffic Monitoring and Analysis
Internet Traffic Monitoring and AnalysisInternet Traffic Monitoring and Analysis
Internet Traffic Monitoring and Analysis
 

Último

Último (20)

From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptxFactors to Consider When Choosing Accounts Payable Services Providers.pptx
Factors to Consider When Choosing Accounts Payable Services Providers.pptx
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 

Apache vs IIS Myths

  • 1. IIS vs. ApacheMyths and Reality
  • 2. Apache - Overview Free web server. Often combined with Linux, MySQL, and PHP to make the LAMP stack. First released in 1995. Modular architecture. Built using an open source development model. Commercial friendly open-source license. Current Version is 2.2.9 which was released in June of 2008
  • 3. IIS 6 Overview IIS 6.0 – A Solid Foundation Shipped with Windows Server 2003 Proven Security Significant reduction in attack surface compared to previous releases No security vulnerabilities since it’s release five years ago. Proven Scalability and Stability Used by many major sites and companies such as MySpace.com, Match.com, US Bank, USA Today, Allstate, Continental Airlines and others. Significant increase in reliability of hosted web sites compared to IIS 5.0. A solid trusted foundation for IIS 7.0
  • 4. IIS7 Overview Benefits Features Reduced Attack Surface Create Streamlined Servers Modular and Extensible Integrated with .NET Improved Security Agile Administration Built in Request Tracing Easier to ManageFast Diagnostics Extend/Modify IIS Features
  • 6. Security“Which of the two platforms, IIS and Apache, is more secure?” IIS 7.0 Security Minimal Surface Area Automatic Site / Application Sandboxing Anonymous User Account Changes URL Authorization Built in Request Filtering Integrated Active Directory Authorization IIS / Security Development Lifecycle Automatic Update Patching Security Tracking – Secunia IIS 6 by comparison has only 5 advisories released to date. http://secunia.com/product/1438/?task=advisories Apache 2.0.x on the other hand has over 35, several of which are critical rated. http://secunia.com/product/73/?task=advisories
  • 8. Management“Is IIS or Apache easier to manage?” IIS 7.0 Manageability Centralized Web Farm Configuration Streamlined and Focused Administration Tool Remote Administration Tool Command Line Administration Rapid Troubleshooting and Limited Downtime AdHost - Able to Reduce Site Setup Time to a Quarter of the Previous Time with IIS 7.0
  • 10. Performance / Scalability“Does Apache have better performance /scalability than IIS?” IIS 7.0 Performance/Scalability Leaner Web Servers Server Core Static and Dynamic Compression Output Caching Improvements Enterprise Level Performance “Match.com runs IIS 7.0 with 30 million page views daily.” “PlentyOffFish.com gets 1.2 billion page views a month.” “WS2008 and IIS 7.0 allow www.microsoft.com to process 122 million more requests at the same CPU level – compared to IIS 6.0” “MySpace.com runs IIS 7.0 with 23 billion page views a month.” HostMySite - Now hosting 1,100 web sites per server / Up from 500 shared applications.
  • 12. Reliability“Which web server is more reliable?” IIS 7.0 Reliability Proven and Trusted Platform 54% of the Fortune 1000 rely on IIS 7.0 Rapid diagnostics tools to troubleshoot any concerns quickly Failed Request Tracing Runtime State and Control API. HiChina - Reduced Application downtime by 99% for applications that were moved to Windows Server 2008 and IIS.
  • 14. Modularity“Which is more modular, IIS or Apache?” IIS 7.0 Modularity Server functionality is split into 40 modules Only 10 modules installed by default Modules and a Generic Pipeline Extensibility
  • 16. Innovation“Is IIS or Apache a more innovative platform?” IIS 7.0 Innovation IIS 7.0 Admin Pack URL Rewrite Module (Technical Preview) PowerShell Provider for IIS Remote Manager – IIS 7 UI for Down-level Clients Web Playlists
  • 18. Troubleshooting“Is IIS or Apache an easier platform to troubleshoot?” IIS 7.0 Troubleshooting Detailed Error Messages Verbose Error Messages Suggests Causes and Solutions Details include configuration sections in question, modules in use, page, etc. Failed Request Tracing Allows for custom failure criteria per URL Persist Failure Log Files beyond process lifetime Common Usages Request take too long Request Error (completes but with error code)
  • 20. Application Support“Does Apache support more Applications?” IIS 7.0 Application Support Extensible, modular architecture – add, remove or replace any built-in module Enhanced ASP.NET integration including unified configuration, HTTP runtime and administration tools Caching support (kernel and user) for all types of dynamic content Built-in FastCGI support for Open Source frameworks such as PHP and Ruby. Strong integration with other Enterprise Products such as SharePoint Extensive Support for Streaming Media
  • 22.
  • 23.
  • 24. PHP Applications“Is Apache the best platform for PHP?” IIS 7.0 and PHP Support Consolidate .NET and PHP applications on a single server Consolidate Web and Other Server Management Frameworks to a single platform Better Web Platform Management Host on Minimal / Headless Server with Server Core Powerful Media Serving Microsoft Supported Solution
  • 26. Summary IIS 7.0 has: A Modular and Extensible Architecture Deep integration with .NET Applications Improved Security Agile Administration Built in Troubleshooting Tools such as Request Tracing This leads to a Web Platform that is: Streamlined Easy to extend To Manage Quick to Troubleshoot Highly Secure
  • 27. IIS Resources Technical Communities, Webcasts, Blogs, Chats & User Groupshttp://www.microsoft.com/communities/default.mspx Microsoft Learning and Certificationhttp://www.microsoft.com/learning/default.mspx Microsoft Developer Network (MSDN) & TechNet http://microsoft.com/msdnhttp://microsoft.com/technet Trial Software and Virtual Labshttp://www.microsoft.com/technet/downloads/trials/default.mspx IIS.Net http://www.iis.net http://forums.iis.net http://blogs.iis.net http://www.iis.net/downloads
  • 28. © 2007 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions,it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Notas del editor

  1. Apache is at the heart of the LAMP stack which is comprised of Linux, Apache, MySQL, and PHP. Apache was first released in 1995 and it has a modular architecture similar to that found in IIS 7.0. One significant difference between Apache and IIS is that Apache is built with an open source model with a series of individual contributors and organizations contributing code to the project. The current version of Apache is 2.2.9 which was released in June of 2008.
  2. IIS 7 contains a variety of improvements when compared to IIS 6.0. As detailed throughout this presentation IIS makes it easy to create streamlined servers, generate a reduced attack surface for a given deployment, quickly diagnose issues in production, dev, and test, and is built on a highly extensible and modular architecture.
  3. There are a number of perceptions that exist in the Apache community about the real differences between Apache and IIS. Some of the more common perceptions are detailed here.
  4. Minimal Surface AreaBy design IIS 7.0 is comprised of a variety of different modules. Only 10 of which are loaded by default leading to small attack surface. In addition modules can be added only as needed allowing administrators to carefully control the surface area of any given IIS web server deployment.Automatic Site / Application SandboxingIIS 7.0 introduces application pool sandboxing features that are transparent to the user. By default IIS 7.0 runs each application in a sandbox so that if a web application fails only the memory associated with that application is affected. This isolation is an important consideration as organizations deploy hundreds or thousands of web sites on a single server.Anonymous User AccountWith IIS 7.0 the “Anonymous User” account is no longer “keyed” to each server and instead is named IUSR instead of IUSR_<ServerName>. IUSR with IIS 7.0 is built into IIS 7.0 and is not an NT local account. This means there is no need to worry about a intruder being able to logon to the operating system with this account. URL AuthorizationIIS 7.0 also supports URL authorization for controlling access to sites, folders, and files with the need for using NTFS ACL’s. Rules are stored in *.config files making authorization stores portable and allowing administrators to utilize Xcopy to migrate and maintain security settings for an application. In addition these *.config file rules can be controlled via the administrative interfaces that ship with IIS 7.0Request FilteringIIS 7.0 includes integrated URLScan style rules. These rules prevent URL’s that contain “any string”, they can block URL’s over x length, and prevent delivery of certain extensions or content such as *.config, or *.bin, or query length. You can also specify “hidden” namespaces that cannot be requested in a URL even if it is present on the server. For example App_Data and Bin are defined as hidden namespaces by default and will not be served by IIS 7.0. They are easy to implement in *.config. These rules can also now be edited in a UI with the IIS 7.0 Admin Pack. (link). Request Filtering helps to prevent malicious URL’s from ever reaching your applications. Finally there are new error codes that track rejections that occurred due to request filtering.Integrated Active Directory AuthorizationWhereas IIS integrates seamlessly with Active Directory Apache requires third party modules to achieve the same level of functionality.Security Tracking – SecuninaSecunia reports far more vulnerabilities in Apache 2.0 than were found in IIS 6.0.Security Development LifecycleApache’s community driven model for software development lacks a clearly defined vulnerability resolution path. While Apache’s community driven approach sometimes allows for a patch to developed and disseminated quickly it also does not ensure that all security vulnerabilities are addressed nor that each vulnerability is handled in the same way. By contrast IIS is developed via a structured, disciplined Security Development Lifecycle (SDL).Automatic Update PatchingDue to the benefit of being deployed on top of the Windows Server Platform IIS can easily participate in the automated patching mechanisms that are offered by Windows Server. By contrast Apache does not offer automatic patching capabilities similar to Windows Server and IIS’s automatic patching capabilities. Nor can Apache offer the same type of “patch Tuesday” consistency in terms of when patches come out, when they need to be applied, etc.ASP.NET Forms SecurityASP.NET on IIS offers Forms Security out of the box for all site content. Making it easy for developers to put together a secure site quickly.
  5. UC Berkley > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001475Ad Host > http://download.microsoft.com/download/6/2/d/62d27d2c-b4c1-47da-b348-12852c6fde91/Adhost_WS08.doc
  6. Centralized Web Farm ConfigurationWith IIS , while you can leverage simple XCOPY configuration deployment to ease the deployment of configuration changes across a number of different servers this still leaves you with the issue of having to configure each IIS instance independently. IIS 7.0 also includes the ability to share configuration state information from a network share and point each IIS instance at this shared configuration information. Thereby allowing you to update configuration settings in one place but still have multiple IIS servers pick up the configuration change.Apache’s feature that supports distributed configuration by contrast in one that the Apache.org site recommends be disabled due to the performance hit that ensues when it is enabled.Streamlined and Focused Administration ToolIIS has an intuitive, feature-focused administration tool with streamlined administration tasks. By contrast Apache forces administrators to primarily work via the command line and edit configuration files manually. This requires administrations to memorize appropriate commands and makes discoverability of the right “next step” in managing a server a potentially time consuming process compared to the use of the GUI’s found in IIS. Remote Administration ToolIIS 7.0 also includes solid remote management tools. In addition these tools leverage HTTPS, letting you use the same UI for remote management as if you were logged in locally to the server.Command Line AdministrationApache is administrated predominately via the command line with all of the configuration information contained in text files. By contrast IIS supports a rich set of GUI management applications in addition to a rich command line and text file configuration based management framework. With IIS administrators can edit configuration files directly, leverage AppCMD.exe from the command line to manage configuration changes, or utilize additional management API’s. Also, with IIS the server does not require a restart to apply configuration changes whereas in a fair number of cases Apache does require a restart to apply configuration changes. Finally IIS comes with a default configurations that can be used right after deployment of the web server.Rapid Troubleshooting and Limited DowntimeIIS comes with a rich set of troubleshooting and management tools such as Failed Request Tracing. By contrast Apache’s troubleshooting tools are very basic and there is very limited diagnostic or troubleshooting support built in. In addition the Apache Foundation does not have a dedicated support arm and dedicated Apache support packages must be purchased from third parties.
  7. AdHost > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001311MaximumASP > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001217DiscountASP.NET > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000002557Vanderbuilt > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001460Dell > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001634
  8. Leaner Web ServersIIS Modular nature makes it easier to streamline the process of responding to requests and serving content. Removing modules where they are not needed can result in higher application throughput and faster responses.Server CoreServer Core makes it easier to support IIS deployments that do not leverage the .NET Framework and ASP.NET with less memory and overall system resources compared to a full Windows Server 2008 install in conjunction with IIS.Static and Dynamic CompressionIIS 7.0 supports the compression technologies of IIS 6.0 in static and dynamic compression. Compression is an effective way to make maximum use of the bandwidth available to deliver responses to client applications. Static Compression, pre-compresses content and stores it on disk. Dynamic Compression compresses the response in real time.Output Caching ImprovementsPreviously IIS offered caching via the kernel cache or the output cache. Each had their own specific limitations. With IIS 7.0 the new output cache bridges the gap between the old kernel and output caches of IIS 6.0. The new output cache supports the caching of any type of content (ASP, ASP.NET, PHP, etc.). The new cache allows content to be stored in the kernel cache to be stored there and other content to be stored in the output cache. The IIS output cache also supports a series of programmatic API’s that make it easy to set caching policies based on information gained dynamically at runtime.
  9. Bargainland > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001488MaximumASP > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001217TeamZoneSports > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000002457Dell > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001634Parking.Ru > http://download.microsoft.com/download/7/7/7/777dd770-58de-4aed-be92-bfc8d4cf22f3/Parkingru_WS08_Final.doc
  10. Proven and Trusted PlatformIIS 7.0 is built on top of a proven and trusted platform that has powered numerous high traffic sites from MySpace to Microsoft.com. In addition 54% of the Fortune 1000 rely on IIS 7.0.Rapid Diagnostic ToolsIIS 7.0 has a set of tools that allow you to rapidly troubleshoot any concerns quickly. Failed Request Tracing can be used to generate a detailed trace of the events leading up to the error. Failed Request Tracing can also be used to track down specific errors you might be trying to isolate. IIS also comes with the Runtime State and Control API. This API can be used to see the active state of sites, applications, and active requests on the server., as well as a variety of administrative functions such as starting and stopping the server. This API is accessible via a variety of means such as Microsoft.Web.Administration API or AppCMD.exe from the command line.
  11. Hostbasket >http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001623AdHost > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001311Parking.Ru > http://download.microsoft.com/download/7/7/7/777dd770-58de-4aed-be92-bfc8d4cf22f3/Parkingru_WS08_Final.doc
  12. 40 Modules / 10 by DefaultIIS 7.0 ships with 40 modules however only 10 of these are installed by default. These “default” modules consist of common HTTP feature (Static Content, Default Document, Directory Browsing, HTTP Errors), Health and Diagnostics (HTTP Logging and Request Monitor), Security (Request Filtering),Performance (Static Content Compression),Management Tools (IIS Management Console), and the Windows Process Activation Service. This is a intentionally limited set of modules. For example ASP.NET and Remote Management by contrast need to be explicitly installed.Modules and the Generic PipelineModules plug into a generic request pipeline compared to previous releases of IIS.Modules and Extensibility APIIn addition to being able to pick and choose which modules are included as part of an install of IIS you have the ability to utilize third party modules or develop your own.
  13. MaximumASP > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001217TeaLeaf > http://www.iis.net/spotlight/customer.aspx?Customer=TealeafWeatherBug > http://www.iis.net/spotlight/customer.aspx?Customer=WeatherBugServiceU > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001258
  14. The IIS team and the broader IIS community have been actively involved in the development of a variety of enhancements for IIS 7.0. The following is just a sample of some of these efforts.IIS 7.0 Admin PackThe IIS admin pack consists of a set of custom modules that assist in administrating a IIS web server. Modules include a configuration editor, an IIS Reports modules for statistics tracking, and a set of UI modules that allow you to manage existing features such as FastCGI via IIS manager.URL Rewrite ModuleThe URL rewrite module provides a rule based mechanism (regular expressions, wild card) for changing request URL’s before they get processed by he web server. The module helps enable user and search friendly URL’s with dynamic web applications. PowerShell Provider for IISThe PowerShell Provider is a snap in that allows you to perform tasks such as create web sites, web applications, change configuration properties on web sites, query run time data, search and discover configuration settings, etc.Remote Manager – Down Level ClientsThe IIS Remote Manager for down level clients allows you to easily manage IIS instances from Windows Vista, Windows XP, and Windows Server 2003 servers.Web PlaylistsWeb Playlists let you deliver server controlled media playlists from a web server infrastructure rather than utilizing a dedicated media server. Web Playlists let you control seek and skip functionality, supports content protection through dynamically generated tokenized URL’s, and is fully integrated into IIS 7.0 configuration models.
  15. Cason > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001625TeamZoneSports > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000002457Continental Airlines > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001486SpotRunner > http://www.iis.net/spotlight/customer.aspx?Customer=Spot%20RunnerElima > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001624
  16. Detailed Error MessagesIIS also provides verbose error messages that suggest causes and solutions. Details include configuration sections in questions, modules in use, etc. In addition these verbose errors by default are only delivered to localhost.IIS 7.0 Failed Request TracingIIS supports failed request tracing. Failed Request Tracing allows you to only keep the events for failed requests as well as the setting of custom failure criteria per URL such as the time taken and status codes. Common Usages for Failed Request Tracing include, tracking down requests that take too long or hang, requests that complete but with an error (authorization/authentication problems), etc. Finally the perf overhead for Failed Request Tracing is a static amount per request. Finally you can easily turn off Failed Request Tracing when you do not need it.
  17. HostBasket > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001623CrystalTech > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001287Continental Airlines > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001486Combell > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001254Parking.Ru > http://download.microsoft.com/download/7/7/7/777dd770-58de-4aed-be92-bfc8d4cf22f3/Parkingru_WS08_Final.doc
  18. Extensible Modular ArchitectureIIS 7.0 supports an extensible modular architecture that lets you easily add, remove, or replace any built in module. Extensibility is provided via C/C++ and .NET interfaces. By contrast with Apache you need a solid understanding of the ecosystem around Apache and it’s associated projects to assembly a complete web server platform with equivalent functionality to IIS. Apache also does not offer ready made hosting for ASP.NET. While the mono project does contain support for ASP.NET the support is not full. Currently Mono only fully supports ASP.NET 1.1 in it’s entirety. With ASP.NET 2.0 feature such as Web Parts are missing from the mono implementation.Since IIS fully supports ASP.NET developers are able to take advantage of the rich integration with Visual Studio. IIS also allows developers to extend their development efforts toward managing IIS via managed interfaces and custom configuration schemas. Finally .NET is deeply integrated into IIS’s architecture from it’s request pipeline, configuration schema, management tools, and trace infrastructure.Caching SupportAs mentioned previously IIS supports a strong set of caching mechanism that have been improved upon from the IIS 6.0 release.FastCGIFast CGI supports PHP hosting on Windows along with all other FastCGI compatible applications such as Ruby on Rails.Strong Integration with other Microsoft ProductsUnlike Apache, IIS is natively integrated with other enterprise application such as Portals (SharePoint) and enterprise directory services (Active Directory). Apache also does not offer an integrated application server leaving it up the user or organization that uses Apache to be the integrator of this functionality on their own from various independent open source projects.Streaming MediaIIS has extensive support for streaming media. The combination of IIS 7.0, Windows Media Services, and the variety of functionality found in the IIS 7.0 media pack lead to a robust platform for media serving. IIS 7.0 allows you to save bandwidth costs on streaming media, decrease network traffic when streaming media, and easily monetize assets by preventing ad skipping.
  19. CrystalTech > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001287TeamZoneSports > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000002457
  20. Rapid Troubleshooting and Minimized DowntimeThe ability to generate detailed errors and utilizeautomatic failed request tracing leads to rapid troubleshooting and minimized server or site downtime.Minimized Surface AreaIIS 7.0’s minimized surface area leads to less administrative overhead as there is less to patch and maintain for streamlined IIS installations.Isolation and SandboxingThe isolation and sandboxing features detailed previously make it easier to ensure that a single site failure does not bring down additional sites or the server itself thereby increasing administration time.ScalableMulti-Tenant HostingScalable multi-tenant hosting makes it easy for IIS to scale and sandbox thousands of Web sites on a single server. This allowsIT organizations to consolidate more sites on a single server and minimize the overall number of servers that need to be administered.Delegated Control to Site OwnersIIS 7.0 also makes it easy to delegate site control to the actual owners of the site. A significant concern for hosting companies in particular.Strong Support ResourcesBy choosing IIS you can also leverage the extensive support options that Microsoft provides compared to a purely community based support model that Apache leverages.
  21. Mosso > http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000001432Pipex > http://www.iis.net/spotlight/customer.aspx?Customer=PipexAruba.IT > http://download.microsoft.com/download/6/b/e/6be5466b-51a5-4eaf-a7fc-590f32bc9cb3/Aruba.it%20Case%20Study.docx
  22. Consolidate .NET and PHP ApplicationsIIS 7.0 with it’s Fast CGI support makes it easy to consolidate .NET and PHP based applications on the same server. And both types of applications can benefit from the strong security inherent in IIS as well as the long history of reliability.Consolidate Web and Other Server Management Frameworks to a Single PlatformThe ability to host both PHP and ASP.NET applications on a single Windows Server instance with IIS makes it easier to have a consistent IT environment. In addition Windows Server comes with a variety of management frameworks out of the box that can be easily used to manage this consistent IT environment such as PowerShell, Server Manager, and Hyper-V for virtualized environments.Better Web Platform ManagementWindows Server 2008 and IIS 7.0 offer significant advantage when it comes to the day to day management of both PHP and ASP.NET based applications. For example IIS administrators can easily delegate management tasks to PHP site owners. Both PHP and ASP.NET site owners can also easily connect to their sites from Windows XP or Vista and manage their sites remotely. Finally PHP and ASP.NET sites can both leverage the centralized configuration model that IIS makes available to administrators.Server CoreServer Core gives Windows Server 2008 and IIS 7.0 the ability to function as a Minimal / Headless PHP server with a minimal surface area and a reduced use of system resources compared to a full Windows Server installation.Powerful Media ServingWindows Server 2008 and IIS 7.0 also provides a strong set of media serving capabilities via Windows Media Server 2008 and IIS 7.0’s Media Pack, an add-on that helps to enable progressive downloading of media from a web server and includes a bit rate throttling module. Microsoft Supported SolutionA final consideration is that for organizations that choose to run PHP applications on Windows they receive full support from Microsoft for essentially all aspects of the application deployment from a single vendor. This extends from the base operating system all the way up through the support for Fast CGI on IIS.