Adm Help
Adm Help
3<B3@>@7A3
/0A=:CB3AgabS[7\bSU`Wbg
3<B3@>@7A3
Security Notice
Deep Freeze does not protect against booting from a floppy drive or CD-ROM drive. The CMOS
should be configured to prevent booting from the floppy drive or CD-ROM drive (i.e. set to boot to the
hard drive) and the CMOS must be password protected. This is a normal precaution for most public
access computers. The Windows Registry, the computer CMOS and the boot sector are protected by
Deep Freeze from within Windows.
Technical Support
Every effort has been made to design this software for ease of use and to be problem free. If problems
are encountered, contact Technical Support:
Email:
support@[Link]
Phone:
800-943-6422 or 604-637-3333
Hours:
Contact Information
Web:
[Link]
Email:
sales@[Link]
Phone:
800-943-6422 or 604-637-3333
Fax:
800-943-6488 or 604-637-8188
Hours:
Address:
Faronics Corporation
620 - 609 Granville St.
Vancouver, BC V7Y 1G5
Canada
About Faronics
Faronics delivers market-leading solutions that help manage, simplify, and secure complex IT
environments. Our products ensure 100% workstation availability, and have dramatically impacted the
day-to-day lives of thousands of information technology professionals. Fueled by a customer-centric
focus, Faronics technology innovations benefit educational institutions, healthcare facilities, libraries,
government organizations and corporations.
Last modified: June, 2007
1999 - 2007 Faronics Corporation. All rights reserved. Faronics, Deep Freeze, Deep Freeze Mac, Faronics Anti-Executable, Faronics
Device Filter Mac, Faronics Power Save, Faronics Power Save Mac, Faronics Insight, Faronics System Profiler, User Refresh Mac
and WINSelect are trademarks and/or registered trademarks of Faronics Corporation. All other company and product names are
trademarks of their respective owners.
3<B3@>@7A3
Contents
Deep Freeze Overview........................................................................................................................................7
About Deep Freeze..........................................................................................................................................................7
System Requirements......................................................................................................................................................7
Deep Freeze Enterprise Files..........................................................................................................................................7
Deep Freeze Configuration Administrator........................................................................................................8
Installing the Configuration Administrator.................................................................................................................8
Initializing with the Customization Code....................................................................................................................9
Re-Initializing the Customization Code.......................................................................................................................9
Update Mode..................................................................................................................................................................10
Using the Configuration Administrator..........................................................................................................11
Welcome Tab.....................................................................................................................................................11
Toolbar..............................................................................................................................................................11
Configuration Tab.............................................................................................................................................13
Passwords........................................................................................................................................................................13
Drives..............................................................................................................................................................................14
ThawSpace......................................................................................................................................................................15
Maintenance...................................................................................................................................................................17
Advanced Maintenance................................................................................................................................................19
Windows Update...........................................................................................................................................................19
Batch File........................................................................................................................................................................19
Miscellaneous.................................................................................................................................................................20
Network .........................................................................................................................................................................20
Advanced Options.........................................................................................................................................................21
One Time Passwords Tab.............................................................................................................................................22
Creating Workstation Install Program and Workstation Seed................................................................................23
Uninstalling the Configuration Administrator.........................................................................................................24
Deep Freeze Enterprise Console......................................................................................................................25
Launching the Enterprise Console..............................................................................................................................25
Activating the Enterprise Console..............................................................................................................................25
Using the Enterprise Console......................................................................................................................................26
Managing Communication Between the Console and Workstations....................................................................27
Configuring the local service.......................................................................................................................................27
Enabling the local service.............................................................................................................................................27
Disabling the local service............................................................................................................................................27
Adding a local service Connection.............................................................................................................................28
Editing or Removing a local service Connection......................................................................................................28
Remote Consoles...............................................................................................................................................29
Managing Deep Freeze with the Console...................................................................................................................30
Dynamically Updating a Deep Freeze Configuration File.......................................................................................34
Scheduling Deep Freeze Tasks.....................................................................................................................................36
Managing Network and Groups..................................................................................................................................40
Importing Groups from Active Directory..................................................................................................................41
Adding Workstations to a User Defined Group...............................................................................................42
Deep Freeze Console Shutdown.......................................................................................................................43
Installing Deep Freeze......................................................................................................................................44
Attended Install or Uninstall........................................................................................................................................44
Uninstalling Deep Freeze.............................................................................................................................................45
Silent Install or Uninstall..............................................................................................................................................46
Silent Install or Uninstall Using a Shortcut................................................................................................................46
Network Install on Multiple Workstations.................................................................................................................47
Installing Over Existing Deep Freeze Versions.........................................................................................................47
Installing Using Imaging..............................................................................................................................................47
3<B3@>@7A3
Target Install...................................................................................................................................................................47
Managing Deep Freeze Workstations...............................................................................................................48
Workstation Logon........................................................................................................................................................48
Boot Control...................................................................................................................................................................48
Network .........................................................................................................................................................................49
Clone...............................................................................................................................................................................49
One Time Passwords.....................................................................................................................................................49
ThawSpace......................................................................................................................................................................50
Permanent Software Installations, Changes, or Removals.......................................................................................50
Deep Freeze Command Line Control ([Link])...........................................................................................51
DFC Return Values........................................................................................................................................................51
Batch File Example........................................................................................................................................................53
Ports and Protocols Explained.........................................................................................................................54
Appendix A - Network Examples.....................................................................................................................55
Example 1 - Single Subnet............................................................................................................................................56
Example 2 - Multiple Subnets One local service.......................................................................................................57
Example 3 - Multiple Ports, Console Accessed Remotely........................................................................................58
Example 4 - Multiple Subnets Multiple local services..............................................................................................59
Appendix B - Troubleshooting a Remote Console Connection......................................................................60
No Clients In the Console............................................................................................................................................60
Port is in Use Error When Starting the Console.......................................................................................................61
3<B3@>@7A3
3<B3@>@7A3
3. Follow the steps presented. Read and accept the license agreement.
4. Click Install and the Configuration Administrator is installed on the computer.
3<B3@>@7A3
The Customization Code must be recorded and guarded with care. Faronics is unable to
recover a lost or forgotten Customization Code!
Re-Initializing the Customization Code
If another administrator wants to create installation files with the same Configuration Administrator
using a different Customization Code, the [Link] program should be run. This resets the existing
Customization Code for the Configuration Administrator. Enter a new Customization Code. Click OK
for the new Customization Code to become active.
3<B3@>@7A3
Update Mode
Update Mode is an advanced feature of Deep Freeze Enterprise that requires an understanding of
command line scripting.
The update command requires the administrator not change any of the default Deep
Freeze directories or file locations.
Update Mode can be used to automatically create updated versions of existing files of Deep Freeze
Enterprise by executing a special update command. This command completes two tasks:
1. Updates previous versions of the Deep Freeze Enterprise Console and the Deep Freeze
Configuration Administrator. (Found in Faronics > Deep Freeze 6 Enterprise.)
2 Updates any user created files stored in the Faronics > Deep Freeze 6 Enterprise > Install
Programs folder.
The benefit of these updates is that a large amount of workstation installation files can receive
customized updates to the configuration files created from an older version of the Deep
Freeze Configuration Administrator.
The command automatically updates files created by an administrator (.exe, .rdx) that are present
in the Faronics > Deep Freeze 6 Enterprise > Install Programs directory, including the following subdirectories:
Workstation install files
Workstation Seed files
In the example below, the district office has received a new version of Deep Freeze Configuration
Administrator and can automatically update any existing Deep Freeze Workstation Install files and
Installation Seeds at a remote location.
Workstation Install
File
District Office
Remote
Location
Workstation Seed
The update command does not require a password, but does require a Customization Code. Use the
following command syntax:
\PathToFile\[Link] /update=Customization Code c:\[Link]
10
must be replaced with the actual path to the installation file ([Link])
[Link] must be the actual name of the installation file (it may differ if it was
downloaded)
Customization Code must be in quotes if there is a space in it
Customization Code must match the old installation files Customization Code
PathToFile
3<B3@>@7A3
The log file provides full details of exactly which files were updated.
The update process may take a few minutes to complete.
Update Mode does not update the existing version of Deep Freeze on workstations.
Workstations must be updated using the Enterprise Console.
Welcome Tab
The Welcome tab provides contact information for Faronics, including a link to the company and
Technical Support Web sites.
Toolbar
The Toolbar is available at the top of every tab in the Configuration Administrator.
The buttons allow users to make a New configuration file (.rdx), to Open a saved configuration file, and
to Save or Save As a configuration file. Users can also access the Help files from this toolbar.
The Create button allows users to create a Workstation Install Program and a Workstation Seed. (.exe)
containing settings specified in the Configuration tab.
Selecting New opens the Configuration Administrator with default configuration settings. Changes
made but not saved prior to selecting New will be lost.
11
3<B3@>@7A3
File Menu
The File Menu contains the same options as those available on the Toolbar, with the additions of the
option to choose from the available languages and Password Protection.
Password Protection
Password Protection offers an optional layer of security for the administrator.
To password protect access to the Configuration Administrator, complete the following steps:
1.
2.
3.
4.
12
3<B3@>@7A3
Configuration Tab
The Configuration tab has six sub-tabs that are used to configure various options. After all the desired
configuration options have been selected, a customized workstation installation program file is ready
to be created. This program file can then be used to install a pre-configured version of Deep Freeze on
workstations.
Passwords
Deep Freeze Enterprise allows the administrator to choose up to 15 passwords, in addition to the One
Time Password Generation System.
2.
From the Type drop-down list, choose the preferred kind of password. The following options
are available:
Workstation: designated for use at a workstation.
Command Line: for use with Command Line Controls; the Command Line Control tool
([Link]) does not function unless at least one Command Line password is defined.
3.
4.
5.
LANDesk: designated for use through the LANDesk Management Suite Console.
Optional: For Workstation passwords, check the User Change checkbox to allow a user to
change the password at the workstation.
Enter the password.
To set a password to become active and expire on specified dates, check the Timeout checkbox
and use the drop-down calendars to specify an Activation date and Expiration date.
Deep Freeze can use both One Time Passwords (OTPs) and fixed passwords. The OTP
feature is always available and cannot be disabled. (For more information on OTPs
refer to the One Time Password section of the documentation.) The fixed workstation
passwords, defined in the Passwords tab, are optional.
13
3<B3@>@7A3
Drives
The Drives tab is used to select which drives are to be Frozen (protected by Deep Freeze) or Thawed
(unprotected), and to create a ThawSpacea virtual partition on a Frozen drive where data can be
saved permanently.
Frozen Drives
By default, all drives are Frozen. To put a drive in a Thawed state, clear the checkbox of the preferred
drive.
In the example above, the C: drive is checked, but not the D: drive. This results in all workstations with
only a C: drive being Frozen. Workstations with a D: partition or drive have a Frozen C: drive and a
Thawed D: partition or drive.
While only local drives (partitions or physical drives) can be Frozen, all drive letters are shown because
the pre-configured installation file may be installed on many workstations with various hardware and
software setups.
Thaw External Hard Drives
By default, external hard drives are Thawed. To put the external drives in a Frozen state, clear the
checkboxes.
If the USB and/or IEEE 1394 (FireWire) external hard drives check boxes are cleared, the drive is
Frozen or Thawed according to the letter each drive mounts to in the Frozen Drives section.
Therefore, if the USB hard drive checkbox is cleared but it mounts to letter F which happens to be
checked in the Frozen Drives section, then that drive will be Frozen.
Network drives and removable media drives (floppy, memory keys, CD-RW, etc.) are
not affected by Deep Freeze and therefore cannot be Frozen.
14
3<B3@>@7A3
ThawSpace
ThawSpace is a virtual partition on a workstation that can be used to store programs, save files, or
make permanent changes. All files stored in the ThawSpace are retained after a restart, even if the
workstation is Frozen.
To create a ThawSpace using the Configuration Administrator, complete the following steps.
1. In the ThawSpace pane, check Create.
2. The ThawSpace Drive option is used to select the drive letter assigned to the ThawSpace.
The default letter is T:, but it can be changed to any available letter. The next available letter is
used if the selected drive letter already exists on a workstation when Deep Freeze is installed.
3. The Size option reflects the size of the ThawSpace; the default size is 1 GB and the minimum
size is 16MB.
Workstations running Windows 95/98/Me can host a maximum ThawSpace of 2GB.
Workstations running Windows 2000/XP/Vista can host a maximum ThawSpace of 1 TB
when using the NTFS file system or 4GB when using the FAT32 file system. If the workstation
does not have enough free space to accommodate the selected ThawSpace size, the size of the
ThawSpace is adjusted downward to ensure proper operation of the workstation.
4. Workstations running Windows 95/98/Me must use the FAT16 file system for a ThawSpace.
Workstations running Windows 2000/XP/Vista use the NTFS file system by default, but this
can be changed to FAT32 by selecting the radio button.
Retain existing Thawspace is checked by default to prevent Thawspaces created during previous
installations from being deleted.
A dialog is always displayed asking if the ThawSpace should be retained or deleted
during an Attended Uninstall, regardless of whether Retain Existing ThawSpace
has been checked. This option is not displayed if the uninstall is performed through
the Console.
15
3<B3@>@7A3
Restart/Shutdown
The Restart/Shutdown tab is used to schedule restarts or shutdowns.
Restart/Shutdown Schedule
In the Idle Restart/Shutdown Schedule pane, check Enable to configure a shutdown or restart after a
specified period of inactivity. Choose Restart or Shutdown from the drop-down list, and indicate the
number of minutes of inactivity that must pass before the workstation restarts or shuts down.
NOTE: Idle time is defined as no mouse or keyboard activity.
Notification
If the specified idle time passes, a dialog box appears on the workstation indicating that the workstation
is about to restart or shutdown.
Enter the number of minutes this dialog will remain on the screen for in the Warn user for: field
(one minute by default). When the dialog is displayed, the user has the option to cancel the restart or
shutdown by using the keyboard or mouse.
Restart on Logoff
To have the workstation restart when a user logs off, check this option.
Only one Restart/Shutdown per day can be scheduled from this menu; if the workstation
needs to be automatically restarted on a more frequent basis, the Idle Restart/Shutdown
should be used, and/or the workstation shutdown task can be used. (For more information
on scheduling refer to the Deep Freeze tasks section of the documentation).
16
3<B3@>@7A3
Maintenance
The Maintenance tab is used to schedule a time when Deep Freeze is Thawed and when upgrades, new
installations, maintenance, or any other permanent changes can be made.
Check the box beside each day of the week when the Scheduled Maintenance will happen.
Optional: Check Set One Change All to apply certain changes made for one day of the week
to all other days.
2.
3.
Enter the time to start the Scheduled Maintenance period and to restart the workstation into
the Thawed state in the Start Time field.
Optional: Check Disable Keys to prevent the keyboard and mouse from functioning on the
workstation during the Maintenance Period. If this option has been checked, the workstation
displays the following dialog during the Maintenance Period:
17
3<B3@>@7A3
4.
From the Run drop-down list, choose an action to occur during the Maintenance Period.
Choose Batch file to allow workstations to run a Batch file automatically during the
Maintenance Period. A custom Batch file can be entered on the Advanced Maintenance tab.
5.
6.
Choose the Windows Updates to allow workstations to automatically install critical updates
for Windows 2000/XP/Vista during the Maintenance Period via the Internet or an SUS/
WSUS server. The choice to use an SUS/WSUS server and specify the servers IP address is
configured on the Advanced Maintenance tab.
Enter the time to complete the Scheduled Maintenance period and to restart the workstation
into the Frozen state in the Stop Time field.
If the Stop Time precedes the Start Time, the Stop Time is assumed to be during the next
day.
Optional: check the Shutdown box to shut the workstation down at the conclusion of the
Maintenance Period instead of restarting it. If Shutdown is checked, the workstation is Frozen
the next time it is started.
The Run Windows Updates feature does not actually perform updates, but makes the
call to have the normal update method take place during the Maintenance Period.
If the computer is off at the start of the Maintenance Period, the maintenance will not
occur.
The computer will not automatically turn on for the Maintenance Period unless a
Wake-on-LAN call is scheduled in the Console. ( For more information on performing
maintenance refer to the Deep Freeze tasks section of the documentation.)
18
3<B3@>@7A3
Advanced Maintenance
The Advanced Maintenance tab is used to specify SUS or WSUS server and batch file options for a
Scheduled Maintenance period.
Windows Update
To use an SUS (Microsoft Software Update Services) Server or a WSUS (Windows Software Update
Services) Server for Windows critical updates, check the preferred option and enter the IP address.
If Use SUS/WSUS Server is unchecked, Windows critical updates are downloaded via the internet for
each workstation individually.
Microsoft SUS client and SUS server can be downloaded at: [Link]
Batch File
Enter a custom batch file to run during the Maintenance Period on days specified on the Maintenance
tab. The same Batch file applies to all days that Run Bat File has been checked. The following options
are available when running custom Batch files:
To clear the current batch file, click New
To load an existing file, click Open and browse to the location of the file
To save the contents of the field, click Save and browse to the preferred save location
The batch file can be any command or series of commands that the command processor can run. Users
can run custom scripts that require the use of a third-party scripting engine by calling the script from
the batch file as if it was being run from the command line.
Run batch file with the Microsoft Network
From the drop-down menu, choose to run a batch file via the Microsoft Network.
By default, customized batch files execute using the local System account. If the updates to be deployed
are located on file servers that require authentication, check Specified User Account and enter the
account Login ID, Password, and Domain to access the file servers. This applies to Windows 2000/XP/
Vista only.
Run batch file with the Novell Network
To run a batch file with the Novell Network, select it from the drop down menu and provide entries for
Login ID, Password, Tree, Context and Server.
19
3<B3@>@7A3
Miscellaneous
The Miscellaneous tab is used to configure the network settings used by the workstations to communicate
with the Console, and configures various security options.
Network
Communication between the Deep Freeze Enterprise Console and workstations with Deep Freeze
installed can use two different modes: LAN Mode or LAN/WAN Mode.
LAN: Check the LAN radio button to configure Deep Freeze to communicate within a Local Area
Network (LAN).
LAN mode is a self-configuring mode that requires only a port number; the default port is 7725. The
port number can be changed if it is in conflict with other programs on the LAN. In LAN mode, the
Deep Freeze workstations and the Enterprise Console find each other through UDP broadcasts. These
broadcasts only occur when workstations or the Enterprise Console are started, ensuring that there is
little network traffic associated with workstation and Console communication.
LAN/WAN: Check the LAN/WAN radio button to configure Deep Freeze to communicate in both a
LAN and a WAN (wide area network).
LAN/WAN can be used in either a LAN or WAN environment and over the Internet. This mode uses
an IP address or the computer name, along with a port number, to allow communication between the
Console and the managed workstations.
The following two methods are available to identify the Console:
specify the Console IP, which must be static
specify the Console Name, in which case the IP can be dynamic
When the Enterprise Console is behind a firewall or a NAT (network address translation) router,
the firewall or router must be configured to allow traffic to pass through to the Enterprise Console.
Depending on the firewall or router, workstations may need to be configured with the IP address of the
firewall so that traffic can be forwarded.
These settings can be changed on local workstations using the Network tab. If these settings are changed,
those changes will also need to be applied at the Console.
20
3<B3@>@7A3
For more information on configuring and using Deep Freeze in a specific network environment, refer
to Appendix ANetwork Examples or contact Technical Support.
If a port number other than the default of 7725 (registered to Deep Freeze) is used, care
should be taken to ensure that there are no conflicts with applications already running
on the network. Well-known ports (01023) should be avoided and any Registered
Ports (102449151) should be checked for conflicts before deployment.
A complete listing of the ports assigned to various applications can be found on the
Internet Assigned Numbers Authority web site at [Link]
port-numbers.
Advanced Options
Win 9x
Prevent break outs from [Link]: Check this option if the Windows 9x workstations
are using the [Link] file to execute programs before Windows starts; this prevents users
from aborting the execution of the [Link] file and gaining access to the system in an
unprotected state
Use Hard reboot when Thawed: Check this option to force workstations to perform an immediate
restart when leaving the Thawed state; this option should be selected if the workstations
experience problems shutting down when leaving the Scheduled Maintenance period.
Local Policies
Enable Deep Freeze local policies: For enhanced security, Deep Freeze removes the following
local privileges: debugging programs, modifying firmware, and changing the system time;
uncheck this option to use existing privileges.
Allow user to change the clock: Check this option to allow Frozen users to adjust the system
clock.
Disable Command Line options: This option is checked by default. Unchecking this option
allows for further customization of the Deep Freeze installation program when using the Silent
Install System; checking this option prevents the pre-existing configuration choices from being
changed during installation.
Stealth Mode
Show Frozen icon in system tray: Check this option to display the
Deep Freeze is installed and the workstation is Frozen.
Show Thawed icon in system tray: Check this option to display the
Deep Freeze is installed but the workstation is Thawed.
If the options to show a Deep Freeze icon in the System Tray are unchecked, the keyboard
shortcut CTRL+ALT+SHIFT+F6 must be used to access the logon dialog.
Control Windows Updates: This option is checked by default. This option allows Deep Freeze
to override any Group Policy settings pertaining to Windows Updates.
21
3<B3@>@7A3
Select either Password valid for one use only or Password valid for multiple uses.
All OTPs expire at midnight on the day they were created, regardless of type.
2.
Enter the OTP Token from the workstation that requires the OTP into the Token field.
The OTP Token for the workstation is located in the logon dialog, as shown below.
OTP token
3.
Click Generate.
The OTP Generator is also available in the Deep Freeze Enterprise Console in the
Tools menu. Also note that the Deep Freeze Command Line interface does not
support the use of One Time Passwords.
22
3<B3@>@7A3
For a target install, the Workstation Seed is included in this file; it is not necessary to install the
Workstation Seed if the Full Workstation Installation program is going to be installed. The default file
name for this program is [Link].
To create a Workstation Seed, click the Create button in the Configuration Administrator toolbar and
select Create Workstation Seed. The Workstation Seed is a small program that allows administrators to
remotely install and control workstations from the Enterprise Console. The Workstation Seed can be
installed as part of a master image and then deployed via imaging software. All workstations on the
LAN with the Workstation Seed installed are displayed in the Enterprise Console. The file name for
this program is [Link].
All files are saved to the Install Programs folder within the Deep Freeze 6 Enterprise folder by default.
Alternate locations can be chosen and the file name can be changed if desired. It is recommended that
a naming convention is used if the administrator is creating multiple customized installation files.
23
3<B3@>@7A3
Open the Add/Remove Programs utility in the Windows Control Panel by selecting the
following path from the Start menu:
Start > Control Panel > Add or Remove Programs
2.
Select Deep Freeze Administrator - Enterprise and click the Change/Remove button.
3.
Follow the steps presented and the Configuration Administrator will be uninstalled from
the computer.
Uninstalling the Configuration Administrator from the Add or Remove Programs
applet on the Console machine also removes the Consoles local service as well as
the local service configuration including user defined groups and scheduled tasks.
24
3<B3@>@7A3
The network administrator enters this token in the Configuration Administrators OTP Generation
System. An OTP is generated. Enter it in the dialog and the Console will run.
The Enterprise Console runs on Windows 2000/XP/Vista, and 2000 and 2003 Server.
The computer on which the Enterprise Console is installed must not have an installation
of the Workstation Seed ( using the same port) or a full Deep Freeze installation.
25
3<B3@>@7A3
Status Icons
The Enterprise Console displays the status of the workstations on the local area network with the
following icons beside or above the workstation name, depending on the view selected:
Workstations that have the Deep Freeze Workstation Seed installed but do not have
Deep Freeze installed; Deep Freeze can only be remotely installed on workstations
with this icon
Workstations with Deep Freeze installed in a Frozen state
Workstations with Deep Freeze installed in a Thawed state
Workstations with Deep Freeze installed in a Thawed Locked state
Workstations that are currently powered down
Workstations that are currently in maintenance mode
Workstations whose communication with the Console has been interrupted
Workstations that have been locked
26
3<B3@>@7A3
In most cases, communication with the workstation is re-established when the workstation is powered
on or when the conditions causing the communications breakdown are rectified. It may take several
minutes for the workstation to report back to the Console and re-establish communication. If
communication cannot be re-established, contact Technical Support for troubleshooting steps.
27
3<B3@>@7A3
To remove a port from the local service highlight the port and click Remove.
This does not delete the entry from the network pane in the Console, it simply removes it
from the Local service connections list
To remove the entry form the network pane in the Console, select it and click the remove icon
located in the sidebar.
28
3<B3@>@7A3
Remote Consoles
A Remote Console is a Console that hosts one or more connections that allow other Consoles to connect through. Existing connections must be edited to allow them to be accessed remotely.
Setting up Remote Control Enabled Connections
To allow a connection to be accessed remotely perform the following steps:
1.
2.
3.
4.
5.
In the Connect to Remote Console dialog, specify the connection details such as Remote Console
Name, Remote Console IP, port number and password. This information is provided by the administrator of the host Console. Once entered, this information can be retrieved by right-clicking a port in
the Network and Groups Pane and selecting Properties.
If the connection to a Remote Console has been severed, it can be reconnected by
clicking the Reconnect to Remote Console icon in the sidebar
or by right-clicking
on an entry in the Network and Groups pane.
29
3<B3@>@7A3
View Options
The Enterprise Console has three view options: Icons, Details, and List. Use the View menu to select
a preferred appearance.
The View menu can also be used to view the log for selected workstations or to remove the selected
workstation(s) from History.
The View menu can also be used to view the log for selected workstations or to remove the selected
workstation(s) from History.
If no workstations are selected, Clear History is available.
Managing Deep Freeze with the Console
The Enterprise Console contains a toolbar at the top of the screen that allows quick access to the
functions of the Console.
These commands can also be accessed using the contextual menu, as shown below, that appears by
right-clicking on a specific workstation.
30
3<B3@>@7A3
When a particular action is chosen, the selected workstation performs the action and the status icons
update accordingly.
Specific icons are disabled if the selected workstation does not support that action. For example, a
workstation that has a Target Icon, will not show the option to be Thawed or Frozen, because the
program has not been installed yet.
Updating Deep Freeze Software
To update Deep Freeze workstations with a new version of Deep Freeze, complete the following steps:
1.
2.
3.
In the Configuration Administrator of the new version of Deep Freeze, create a blank
workstation installation file.
In the Console, select the workstations to be updated; these workstations can be in either a
Frozen or Thawed state.
Right-click, and select Update Deep Freeze from the contextual menu.
Alternatively, click the
4.
5.
A standard Open file window appears. Select the blank workstation file and click Open.
The selected workstations update to the new version of Deep Freeze software, but retain all
settings from the current version.
This feature works only on workstations with Deep Freeze 6.0 and higher currently
installed.
3.
4.
Type the message in the dialog that appears and click Send.
A dialog appears asking for confirmation to send the message to the selected workstations.
Click OK to send or Cancel to close the dialog without sending the message.
31
3<B3@>@7A3
32
3<B3@>@7A3
2.
3.
Click OK.
4.
33
3<B3@>@7A3
2.
Right-click on the workstation(s) and select Update Maintenance from the contextual menu.
Or, select the desired workstation(s) and click the Update Maintenance icon in the toolbar.
A menu bar with six buttons appears at the bottom of the Workstations window.
3.
1.
4. The three tabs on the Configuration Screen can be used to update the configuration on remote
workstations.
For further information about the options on each tab, refer to the sections in the
Configuration Administrator documentation for Restart/Shutdown, Maintenance, and
Advanced Maintenance.
After the preferred configuration settings have been chosen, close the Configuration Screen.
The following message appears:
5. Click OK.
6. In the Workstations window, select the desired workstation(s) to be dynamically updated with
the new configuration settings.
34
3<B3@>@7A3
7. Click Send on the menu bar to send the new configuration settings to the selected
workstation(s).
After sending the new configuration settings to the selected workstations, the following
options are available:
Click Save As to save the current settings of the Configuration Screen to a file. A standard Save
File dialog displays where a location and file name can be specified.
Click Edit at any time to re-open the Configuration Screen with the current settings intact.
Click Close to clear the contents of the Configuration Screen and exit out of the dynamic
configuration mode.
When updating the configuration on the workstation, the Restart/Shutdown,
Maintenance, and Advanced Maintenance options are updated with the new settings.
On Windows 9x machines only, all changes take effect after the workstation is
restarted.
35
3<B3@>@7A3
click Scheduler in the Network and Groups pane and click the Add Task icon
right-click on Scheduler in the Network and Groups pane, and choose Add Task
2.
36
Double click the preferred task or select the task and click Next.
3<B3@>@7A3
3.
In the following screen, enter a name for the task and choose the preferred task execution
schedule: Daily, Weekly, Monthly, or One time only.
Task names must be unique; no two tasks can have the same name.
4.
Click Next.
Depending on the choice of task execution, the time and date configuration options that
follow will vary:
NOTE: The default start time for a task is five minutes from the current time.
5.
Enter the preferred time and date for the task execution.
NOTE: If the task is set to execute on a One time only basis, and the starting date is in the
past, the task will not execute. If the task is set to execute on a Daily, Weekly or Monthly
basis, and the starting date is in the past, the task will execute, but will start on the same day
on the following week or month.
Click Next.
37
3<B3@>@7A3
6.
The final screen of the wizard is a summary of the task that has just been created.
Click Finish to complete the task schedule.
To assign workstations to a task, select the preferred computers from the Workstations pane in the
Console and drag them onto the preferred task.
To see which computers are assigned to a specific task, click on the task. The assigned computers
appear in the Workstations pane.
38
3<B3@>@7A3
To delete a workstation from a task, click on the workstation and press Delete.
Executing a Task Immediately
To execute a task immediately, right-click the task and select Execute Task.
Deleting a Task
To delete a task, click on the task and press Delete.
Scheduled Task Properties
To see the properties of a task, right-click the task name and select View Properties.
The following screen displays:
The properties of a task cannot be changed after it has been created. Only the workstations that will
execute the task can be changed by adding or deleting workstations.
Scheduled tasks will still execute even if the Enterprise Console is closed provided
the local service is enabled and the network connections are not shutdown upon
exiting the Console.
39
3<B3@>@7A3
40
3<B3@>@7A3
The following dialog appears, select either the Microsoft tab or the Novell tab.
Enter the LDAP server information of the import location. The option to login anonymously is also
available. If this box is not checked a login ID and password are required.
Select Connect. The Active Directory hierarchy appears, select the desired entries and click Import.
41
3<B3@>@7A3
42
3<B3@>@7A3
Once the set default option has been checked the dialog will not appear on future exits. To edit these
settings select Tools from the menu followed by Exit Options.
43
3<B3@>@7A3
2.
Click Install to begin the installation. Follow the steps presented, then read and accept the
license agreement. Deep Freeze installs and the workstation restarts.
Click Uninstall to uninstall Deep Freeze. Uninstall can only be clicked if Deep Freeze has
previously been installed. If there is an existing ThawSpace, Deep Freeze displays a dialog
asking if it should be retained or deleted.
44
3<B3@>@7A3
To uninstall Deep Freeze on a workstation and leave the Workstation Seed, right-click on the Thawed
workstation(s) and select Uninstall - Leave Seed, as shown above. Or click the
icon on the
toolbar.
To completely uninstall Deep Freeze and the Workstation Seed, select the workstation(s) to be
uninstalled and click the Uninstall icon
on the Toolbar.
The workstation must be Thawed before Deep Freeze can be uninstalled. The Enterprise
Console prompts for confirmation. Once the uninstall is confirmed, Deep Freeze
uninstalls and the workstation restarts.
45
3<B3@>@7A3
Description
[/Install]
[/Install /Seed]
[/Uninstall]
[/Uninstall /Seed]
[/PW=password]
[/AllowTimeChange]
[/Freeze=C,D,...]
[/Thaw=C,D,...]
[/USB]
[/FireWire]
In the example, the Deep Freeze installation program file is named [Link]. Only the C: drive will
be Frozen. Any other drives on the workstation will be Thawed. If the workstation only has a C: drive,
the [/Freeze] switch can be omitted. A password (password) will be created. After executing the
command, Deep Freeze will install and the workstation will restart Frozen and ready to use.
The Silent Install System does not work without the [/Install] or [/Uninstall] switch.
Deep Freeze must be in a Thawed state before [/Uninstall] can be used.
To run the configuration command line options, Disable Command Line options on the
Miscellaneous tab must be cleared.
Silent Install or Uninstall Using a Shortcut
Deep Freeze can be installed directly on a workstation without having to use the installation dialog box
by completing the following steps.
1.
2.
3.
4.
Locate the Deep Freeze installation program file ([Link]) on the target workstation.
Right-click on the icon and choose Create Shortcut.
Right-click on the shortcut and choose Properties.
Edit the path of the Target field by typing /install or /uninstall at the paths end.
Double-clicking on the new shortcut results in the immediate installation or uninstallation of Deep
Freeze, followed by a restart of the workstation.
Deep Freeze must be in a Thawed state before /uninstall can be used.
46
3<B3@>@7A3
After imaging, the workstations require an additional restart for Deep Freeze to correctly detect the
changes in disk configuration. If the workstations are imaged in an unattended mode, steps should be
taken to ensure the workstations are restarted to allow the configuration to update.
To return to the Frozen state after imaging is complete, set Deep Freeze to Boot Thawed on next n number
of restarts (in the master image) so that after n number of restarts, the workstation is automatically
Frozen. Alternatively, use Deep Freeze Command Line Control to Freeze selected workstations.
Target Install
Deep Freeze can also be deployed using a Target Install from the Enterprise Console.
47
3<B3@>@7A3
Boot Thawed on next to ensure that the workstation is Thawed each time it is restarted for
the next specified number of restarts. When that number of restarts is
exceeded, the workstation will boot Frozen.
Boot Thawed
to ensure that the workstation is Thawed each time it is restarted
Select the radio button next to the desired choice and click OK to save any changes. Clicking Apply and
Reboot will save any changes and reboot the workstation immediately.
48
3<B3@>@7A3
Network
The Network tab can be used to configure the network options on a workstation.
To choose either the LAN or the LAN/WAN method of communication, click the preferred radio
button.
When the WAN radio button is selected, a valid IP address for the Enterprise Console must be entered
in the Console IP field. The default port number can be changed by unchecking Use Default Port and
entering the desired port number.
For further information on network configuration, refer to Appendix A.
Clone
The Clone tab is used to prepare master images for the deployment process. For more information refer
to the Install Using Imaging section.
One Time Passwords
A One Time Password (OTP) can be generated using the Configuration Administrator or Enterprise
Console. The administrator requires a token from the workstation in order to generate an OTP. The
OTP Token for the workstation is located in the Deep Freeze logon dialog.
Refer to the Configuration Administrator documentation for more information about the One Time
Password Generation System. An OTP can be used one or more times after it has been generated
(depending on the options set when it was generated). All OTP passwords expire at midnight on the
day they were created.
An OTP must be used to logon to Deep Freeze if no passwords were created for the Deep Freeze
configuration file.
49
3<B3@>@7A3
ThawSpace
ThawSpace is a virtual partition on a workstation that can be used to store programs, save files, or make
permanent changes. All files stored in the ThawSpace are saved after a restart, even if the workstation
is Frozen.
ThawSpace is only available if it was set to be created in the Deep Freeze Configuration
Administrator.
Any existing ThawSpace is deleted during an uninstall if any of the following apply:
the option to retain existing ThawSpace was not checked in the Configuration
Administrator
the ThawSpace was not created with Deep Freeze Professional Version 5 or later
the ThawSpace is on a Windows 95/98/Me workstation
Permanent Software Installations, Changes, or Removals
Workstations must be Thawed for any permanent changes to take effect. Installation of software often
requires one or more restarts to complete the installation.
It is recommended that the Boot Control tab is used to allow the workstation to restart with Deep
Freeze Thawed until installations or changes are finished.
50
3<B3@>@7A3
Description
1
2
3
4
5 - *
51
3<B3@>@7A3
Description
DFC
password
/UPDATE=[path
installer file]
52
to
3<B3@>@7A3
Goto END
:Error1
Echo Errorlevel 1
Goto END
:Error0
Echo Errorlevel 0
Goto END
:END
Actions can be placed between the ECHO Errorlevel # statement and the Goto END statement for
each of the detected error levels. To use this Batch file to automatically Thaw a Frozen workstation, the
following section of the Batch file would have to change to the following:
:Error1
Echo Errorlevel 1
[Link] password /BOOTTHAWED
Echo
Goto END
53
3<B3@>@7A3
The key to setting up the Deep Freeze architecture is knowing which ports to use. The important factor
is knowing which ports are in use on the network and using ports that will not conflict with those. The
default port, 7725 has been officially registered to Deep Freeze.
The following three components make up the Deep Freeze architecture:
As long as the clients and Remote Console connection use the same port there should not be any port
conflicts between the different components:
Client
Uses Port A
Connects
on
Port A
B1>C2>
Remote Console
Connections use
Port A
Connects
on
Port A
B1>
Console
Local Service
Enabled
Ports can also be used to divide the clients. If the local service is set up to run three ports (7725, 7724
and 7723), Consoles can connect to the three different ports to see a different set of clients under each
port.
In the diagram above, the client(s) use both the TCP and UDP protocols to communicate with the
Remote Console. The Console(s) that connects to the Remote Console uses only the TCP protocol to
communicate with the Remote Console. It is important to remember the ports and protocols being
used in order to prevent firewalls, switches or routers from blocking them.
54
3<B3@>@7A3
Example 1
Example 2
Example 3
Example 4
Each example explains how different Deep Freeze components interact in different networking
environments.
NOTE: In the following examples, the client machines have either the Deep Freeze workstation
installation or Workstation Seed installed. Both installs contain the communications component
which talks to the Console/Remote Console. The difference between the workstation install and
Workstation Seed is that the workstation install actually installs Deep Freeze while the Seed has
only the communication component.
55
3<B3@>@7A3
Subnet 1
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
The client machines, represented by the computer icons, are located on the same subnet as the Deep
Freeze Enterprise Console machine, and are represented by the Deep Freeze Console icon. In this
scenario, clients are using port A while the Console has setup a local service connection for the same
port. This port is configured in the Deep Freeze Configuration Administrator in the Configuration tab
on the Miscellaneous sub-tab, as shown below, before creating the workstation install/seed.
56
3<B3@>@7A3
Subnet 1
Subnet 2
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
>=@B/
[Link]
In this scenario (similar to example 1) both the clients and the connection hosted by the Console are
using the same port. This port is configured in the Deep Freeze Configuration Administrator in the
Configuration tab on the Miscellaneous sub-tab, before creating the workstation install/seed.
In order for the clients to be seen, they need to be configured to use a LAN/WAN connection. When
the LAN/WAN option is selected, a Console IP entry box appears. Specify the IP of the machine that
will run the Console.
An example of these settings are shown in the Miscellaneous tab below:
57
3<B3@>@7A3
Subnet 1
Subnet 2
>=@B/
>=@B/
>=@B/
>=@B0
>=@B0
>=@B0
>=@B/
>=@B/
>=@B/
>=@B0
>=@B0
>=@B0
Host
>=@B/0
>=@B0
>=@B/
>=@B0
>=@B0
In this scenario, the host has set up a connection using the local service. Looking at the above diagram,
three other Consoles connect to the host in order to see the clients according to their ports. The
Consoles do not have to be a part of individual subnets as long as they can see the host.
More specifically, The Console connected through port A/B can see the host Console as well as each
individual workstation assigned to ports A and B. The other Consoles connected through port B can
see the host and only the workstations assigned to port B.
58
3<B3@>@7A3
the locations are spread apart and have only a minimal connection to each other
there is a network administrator at each location who is responsible for looking after Deep
Freeze at that location
both locations need to be administered from a third location
In this example, the Remote Consoles are set up at each location and a local service is used
Location 1 (a computer lab on campus) uses port A to communicate with the clients and the connections
hosted by the Console. The school librarys computers use port B, the Console in the technical support
department uses the connections hosted by both lab and library Consoles.
Any console not directly communicating with a workstation should have the local service turned off
The following diagram shows the network topology:
:]QObW]\CaW\U>]`b/
AcP\Sb
AcP\Sb
:]QObW]\ CaW\U>]`b0
AcP\Sb
AcP\Sb
:]QObW]\CaW\U>]`b/
AcP\Sb
AcP\Sb
:]QObW]\ CaW\U>]`b0
AcP\Sb
AcP\Sb
:]QObW]\CaW\U>]`b/
AcP\Sb
>=@B1
:]QObW]\ CaW\U>]`b0
AcP\Sb
AcP\Sb
>=@B/
AcP\Sb
>=@B0
>=@B1
>=@B1
>=@B/
>=@B/
>=@B0
>=@B0
The benefit of this setup is that it allows all the packets sent from the clients in the lab to be contained
at that location. The less distance a packet must travel, the less chance there is of the packet failing.
The administrator in the lab can connect to the local service in the same location 1 but cannot connect
to the local service in the library. The reason for this is that the lab administrator does not know the
password to access the local service for the library. The same goes for the administrator in the library.
If technical support knows the password to both local services (lab and library) the local service at both
locations can be connected to, in order to administer all the clients.
59
3<B3@>@7A3
With SP1, the firewall must be turned off. With SP2, either the firewall must be turned off or the ports
being used must be added to the Exceptions tab. Deep Freeze requires both TCP and UDP protocols;
therefore, one exception should be added for each.
2. The Console and clients do not contain the correct network settings.
If the Console is set up to run under one port and the clients are using another, they will not be able to
see each other. Also, if the workstations are configured for LAN/WAN, the IP must be equal to the IP
of the machine where the Console is running.
The default LAN setup works as long as all the machines running the workstation and Console exist
on the same subnet. However, if a VLAN is being run, or if there are several subnets where the clients
exist, the workstation install must be configured to run under the LAN/WAN settings.
3. Something on the network is blocking the port used between the Console and the
clients.
Check for a connection using a ping. The clients are unable to send packets to the Console/Remote
Console because there does not seem to be a route to the host. Attempting to ping the IP of the Console/
Remote Console does not seem to work. To resolve this issue, make sure the two machines can connect
to each other.
If a server, router, or switch on the network is not allowing the port to get through, the clients will not
be seen. By default, 7725 is the port being used.
4. The workstations were created under a different Customization Code than the
Console.
When the Deep Freeze Configuration Administrator is first run, a prompt for a Customization Code
appears. This code is very important as it encrypts the software. This means that any workstations created
are encrypted with this Customization Code. If a Console was created using another administrator
that was installed with a different Customization Code, it cannot see workstations created under the
original code. The workstations and Console must be created under a Configuration Administrator
installed using the same exact Customization Code.
60
3<B3@>@7A3
It is possible that the workstation install is in stealth mode (the icon does not appear in the system tray).
The seed does not show an icon. The best test is to run a workstation install on the machine in question.
If the uninstall option presents itself, the workstation or seed is installed and can be uninstalled. If the
uninstall option does not appear, the workstation or seed is not installed.
The simplest solution would be to first turn off the local service and then connect to a Console that can
be accessed remotely.
2. Another program or service is using the port on this machine.
This may involve running a port sniffer on the machine in question to see what ports are open. There
are several tools available on the web to perform this action. The [Link] application found in
Windows also should show whether the port Deep Freeze is using is already in use.
3. The network cable is unplugged.
61