ADFS doesn't use IIS since Windows Server 2012 R2. It is built directly on the top on the HTTP.sys.
The federation metadata file is always available without authentication by default. You need to use the following URL: https://ADFSFARMURL/FederationMetadata/2007-06/FederationMetadata.xml
Where ADFSFARMURL
is the FQDN of your farm not the FQDN of the server where the farm is. It has to be the right FQDN (not the IP address either) because of TLS/SNI (which in a nutshell will allow the TLS tunnel only if the FQDN that the client is sending is matching the FQDN registered in the HTTPs endpoint).