DFE Manual
DFE Manual
© 1999 – 2019 Faronics Corporation. All rights reserved. Faronics, Deep Freeze, Deep Freeze Cloud,
Faronics Core Console, Faronics Anti-Executable, Faronics Anti-Virus, Faronics Device Filter, Faronics Data
Igloo, Faronics Power Save, Faronics Insight, Faronics System Profiler, and WINSelect are trademarks
and/or registered trademarks of Faronics Corporation. All other company and product names are
trademarks of their respective owners.
Protected by patents: US 7,539,828 | US 7,917,717 | US 9,152,824 | US 9,785,370
Contents
Preface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9
Important Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
About Faronics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Product Documentation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10
Technical Support . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Contact Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
Deep Freeze Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
System Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Deep Freeze Enterprise Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
License . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 54
Creating Workstation Install Program and Workstation Seed . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 56
Deleting a Task . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
Executing a Task Immediately . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
Scheduled Task Properties . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 95
Managing Network and Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96
Adding a Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96
Building a User-Defined Group Structure . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99
Importing Groups from Active Directory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99
History . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100
Adding Computers to a Group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101
Configure Custom Actions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 102
Control with RDC . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 102
Remote Execute with PsExec . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 103
Push and Install MSI file with PsExec . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 104
Push and Launch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105
Remote Launch. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105
Deleting, Importing and Exporting Custom Actions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 106
Console Customizer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 108
Deep Freeze Enterprise Console Shutdown . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 109
Installing Deep Freeze on the Workstation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110
Attended Install or Uninstall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 110
Uninstalling Deep Freeze on the Workstation via the Console . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 111
Silent Install or Uninstall. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112
Example Command Line . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112
Silent Install or Uninstall Using a Shortcut . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
Network Install on Multiple computers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
Installing Over Existing Deep Freeze Versions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
Installing Using Imaging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113
Target Install . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 115
Check for Updates. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 116
Preface
This user guide explains how to install, configure and use Deep Freeze Enterprise.
Topics
Important Information
Technical Support
Important Information
About Faronics
Faronics delivers market-leading solutions that help manage, simplify, and secure
complex IT environments. Our products ensure 100% machine availability, and have
dramatically impacted the day-to-day lives of thousands of information technology
professionals. Fueled by a market-centric focus, Faronics’ technology innovations benefit
educational institutions, health care facilities, libraries, government organizations, and
corporations.
Product Documentation
The following documents form the Deep Freeze Enterprise documentation set:
• Deep Freeze Enterprise User Guide – This is the document you are reading. This
document guides you how to use the product.
• Deep Freeze Enterprise Release Notes – This document lists the new features and
known issues and closed issues.
Technical Support
Every effort has been made to design this software for ease of use and to be problem
free. If problems are encountered, contact Technical Support.
Email: support@faronics.com
Phone: 800-943-6422 or +1-604-637-3333
Hours: 7:00am to 5:00pm (Pacific Time)
Contact Information
• Web: www.faronics.com
• Email: sales@faronics.com
• Phone: 800-943-6422 or +1-604-637-3333
• Fax: 800-943-6488 or +1-604-637-8188
• Hours: 7:00am to 5:00pm (Pacific Time)
• Address:
Faronics EMEA
8, The Courtyard, Eastern Road
Bracknell, Berkshire
RG12 2XB, United Kingdom
Introduction
Deep Freeze protects the computers that are set to boot from the hard drive.
Configure the CMOS to boot from the hard drive only. The CMOS must be
password protected to prevent unauthorized changes. Deep Freeze protects
the Master Boot Record (MBR) when the computer is Frozen.
Topics
Faronics Deep Freeze helps eliminate computer damage and downtime by making
computer configurations indestructible. Once Deep Freeze is installed on a computer,
any changes made to the computer—regardless of whether they are accidental or
malicious—are never permanent. Deep Freeze provides immediate immunity from many
of the problems that plague computers today—inevitable configuration drift, accidental
system misconfiguration, malicious software activity, and incidental system degradation.
Faronics Anti-Virus can now be managed using Deep Freeze Enterprise (a separate
license is required for Faronics Anti-Virus). Faronics Anti-Virus provides protection from
security threats without slowing down computers due to slow scan times and large
footprints. Built with next-generation technology, Faronics Anti-Virus gives you powerful
anti-virus, anti-rootkit and anti-spyware software in-one. This protects you against
today’s highly complex malware threats while providing seamless integration with Deep
Freeze.
Deep Freeze integration with Faronics Anti-Virus ensures your protection is up-to-date in
the simplest way possible, providing deployment and management capabilities through
Deep Freeze Enterprise Console. Designed to work together seamlessly, Faronics
Anti-Virus is updated even while workstations are Frozen, offering the most
comprehensive protection system.
System Requirements
Deep Freeze uses different colored icons to represent its components. Files identified by
a red icon should generally only be installed on an administrative computer.
Icon Definition
Topics
Installation Overview
Customization Code
One Time Passwords
Installation Overview
If you are using Deep Freeze 6.5 (or higher), you have the option to
automatically upgrade the Enterprise Console, Configuration Administrator,
and Deep Freeze install/configuration files (under the Install Programs
folder) during installation while installing Deep Freeze 8.1 (or higher). The
Customization Code is not required while upgrading Deep Freeze.
2. Click Next. Read and accept the license agreement. Click Next.
3. Enter the License Key in the License Key field or select the Use Evaluation checkbox to
install in Evaluation mode. Click Next. (Deep Freeze will automatically activate the
workstation licenses. Deep Freeze must be activated within 30 days to avoid expiry.)
4. Enter the License Key in the License Key field or select the Use Evaluation checkbox to
install in Evaluation mode. Click Install.
6. Specify the Customization Code and click Next. The Customization Code must be a
minimum of eight characters.
Customization Code
The Customization Code must be recorded and guarded with care. Faronics
is unable to recover a lost or forgotten Customization Code.
Update Mode
Update Mode can be used to automatically create updated versions of existing files of
Deep Freeze Enterprise by executing a special Update command. This command
completes two tasks:
• Updates previous versions of the Deep Freeze Enterprise Console and the Deep Freeze
Enterprise Configuration Administrator. (Found in Faronics > Deep Freeze Enterprise.)
• Updates any user created files stored in the Faronics > Deep Freeze Enterprise > Install
Programs folder.
The benefit of these updates is that a number of files can be updated to the latest version
while retaining their configuration data (created with an older version of Deep Freeze
Enterprise).
The command automatically updates files created by an administrator (.exe, .rdx) that are
present in the Faronics > Deep Freeze Enterprise > Install Programs directory, including the
following sub-directories:
• Workstation install files
• Workstation Seed files
In the example below, the district office has received a new version of Deep Freeze
Enterprise Configuration Administrator and can automatically update any existing Deep
Freeze Workstation Install files and Workstation Seeds at a remote location.
The update command does not require a password, but does require a Customization
Code. Use the following command syntax:
\PathToFile\DFEnt.exe /update=”Customization Code” c:\dfupdate.log
• PathToFile must be replaced with the actual path to the installation file (DFEnt.exe)
• DFEnt.exe must be the actual name of the installation file (it may differ if it was
downloaded)
• Customization Code must be in quotes if there is a space in it
• Customization Code must match the old installation files’ Customization Code
The log file provides full details of exactly which files were updated.
The update process may take a few minutes to complete.
Update Mode does not update the existing version of Deep Freeze on computers.
Computers must be updated using the Enterprise Console.
The One Time Passwords Generation System is used to generate temporary passwords for
Deep Freeze that expire at midnight on the day they were generated.
One Time Passwords dialog can be accessed from
• Tools > One Time Passwords in the Enterprise Console. For more information refer to
Using Deep Freeze Enterprise Console.
• File > One Time Passwords in the Configuration Administrator. For more information
refer to Using Deep Freeze Enterprise Configuration Administrator.
A One Time Password (OTP) can be useful if, for example, a Deep Freeze password is
forgotten or if a configuration file was created without any passwords defined. An OTP
can also be used to provide access to a computer for an individual performing
maintenance duties without requiring that individual to know the permanent Deep Freeze
password.
To create an OTP, complete the following steps:
1. Select either Password valid for one use only or Password valid for multiple uses. All
OTPs expire at midnight on the day they were created, regardless of type.
2. Enter the OTP Token from the computer that requires the OTP into the Token field. The
OTP Token for the computer is located in the logon dialog, as shown below.
3. Click Generate.
The Deep Freeze Command Line interface does not support the use of One
Time Passwords.
Topics
Open the Configuration Administrator by selecting the following path from the Start
menu:
Start > All Programs > Faronics > Deep Freeze Enterprise > Deep Freeze Administrator
The Configuration Administrator provides various tabs to configure passwords, Frozen
drives, Workstation Tasks, Windows Updates, Batch Files, and Advanced Options. Once
the settings have been configured, a Workstation Install file can be created. The
Workstation Install file can be installed on the computers that need to be protected by
Deep Freeze. Deep Freeze Enterprise Configuration Administrator can also be accessed
from within the Deep Freeze Enterprise Console.
Toolbar
The Toolbar is available at the top of every tab in the Configuration Administrator.
Icon Function
Blanks out all existing configuration settings. Opens with default
New
configuration settings.
File Menu
The File menu contains the same options as those available on the Toolbar, with the
additions of the option to choose from the available languages and Password Protection.
Password Protection
Password Protection offers an additional layer of security for the administrator.
To password protect access to the Configuration Administrator, complete the following
steps:
1. Open the File menu and select Password Protection.
2. Select the Protect with password checkbox.
3. Enter and confirm the password.
4. Click OK to set the password or Cancel to exit the dialog without setting a password.
Store the password in a safe location. If the password is lost, you cannot
recover it. You will have to reinstall Deep Freeze.
Passwords Tab
5. To set a password to become active and expire on specified dates, select the Timeout
checkbox and use the drop-down calendars to specify an Activation date and
Expiration date.
Drives Tab
The Drives tab is used to select which drives are to be Frozen (protected by Deep Freeze)
or Thawed (unprotected). You can also create a ThawSpace — a virtual partition hosted
on a local Frozen or Thawed drive where data can be saved permanently without being
deleted by Deep Freeze during a reboot.
Frozen Drives
By default, all drives are Frozen. To put a drive in a Thawed state, clear the checkbox of the
preferred drive.
While only local drives (partitions or physical drives) can be Frozen, all drive letters are
shown because the pre-configured installation file may be installed on many computers
with various hardware and software setups.
Example
In the above screen, the D: is not selected from the Frozen Drives list. Therefore, all drives
except D: are Frozen.
ThawSpace
ThawSpace is a virtual partition that can be used to store programs, save files, or make
permanent changes. All files stored in the ThawSpace are retained after a restart, even if
the computer is Frozen. A ThawSpace can be created on a drive that is configured to be
Frozen or Thawed.
A ThawSpace can be set to automatically expand through the Automatically Grow option
to prevent running out of space. The ThawSpace will automatically expand by 25% of its
current size after reaching 25% free space or less. It will expand up to the maximum size
defined in ThawSpace configuration.
3. Enter the Size. This is the size of the ThawSpace. The maximum size is 1024 GB and the
minimum size is 16 MB.
If the computer does not have enough free space to accommodate the selected
ThawSpace size, the size of the ThawSpace is adjusted downward to ensure proper
operation of the computer.
If you select the Size less than 16 MB, the ThawSpace is set to 16 MB.
If you select the Size more than 1024 GB (1 TB), the ThawSpace is set to 1024 GB
(1 TB).
4. Select the ThawSpace storage unit in MB or GB.
5. Select the Host Drive.
The Host Drive is the drive where the ThawSpace is created.
The storage required for the ThawSpace is used from the total storage available on
the Host Drive.
6. Select Visible or Hidden from the Visibility drop-down.
If you select Visible, the drive will be visible in Windows Explorer.
If you select Hidden, the drive will not be visible in Windows Explorer.
However, the hidden drive can be accessed by typing the drive letter in Start > Run.
7. Check the Automatically grow ThawSpace to a maximum checkbox and configure the
maximum size of the ThawSpace.
8. Click Add to add the ThawSpace.
Removing a ThawSpace
To remove a ThawSpace, select the ThawSpace and click Remove. The ThawSpace is
removed and the drive letter is now added back to the Drive Letter drop-down. Click
Remove All to remove all the ThawSpaces.
Example
In the above screen, a ThawSpace of 16 MB is created on the Host Drive C: and the
ThawSpace is designated with the drive letter T:. The ThawSpace T: is set to Visible and
can be accessed via the Windows Explorer.
Existing ThawSpace
The Retain during install/uninstall checkbox is selected by default to prevent ThawSpaces
created during previous installations from being deleted. A dialog is always displayed
asking if the ThawSpace should be retained or deleted during an Attended Uninstall,
regardless of whether Retain during install/uninstall has been selected. This option is not
displayed if the uninstall is performed through the Enterprise Console.
Select Delete during configuration update to delete all the existing ThawSpaces on the
workstation and re-create while applying the configuration. The existing ThawSpaces and
the data in the ThawSpaces will be deleted and the new ThawSpaces as per the settings
will be created when the configuration is applied.
The Honor Group Policy settings for Hidden Drives ensures that the Group Policy settings
for hidden drives do not conflict with the Deep Freeze settings for hidden drives.
Hidden drive settings for Group Policies are user-specific. Hidden drive settings for Deep
Freeze are global if the Honor Group Policy settings for Hidden Drives option is disabled.
Example
In the above screen, drives E: and F: are selected in the Frozen Drives pane.
Let us assume that E: corresponds to a USB hard drive and F: corresponds to an IEEE 1394
(FireWire) hard drive.
The USB and IEEE 1394 (FireWire) checkboxes are selected in the Always Thaw External
Hard Drives pane, the external hard drives would be Thawed.
The USB checkbox is selected. The IEEE 1394 (FireWire) checkbox is cleared. In this
example, the USB drive (D:) would be Thawed and the IEEE 1394 (FireWire) drive (F:) would
be Frozen.
The Workstation Tasks tab allows you to schedule various tasks that run at the
workstation. The Workstation Tasks reside at the workstation and will run even if the
workstations lose their network connectivity or if they are unable to communicate with
the Deep Freeze Console. The Workstation Tasks are part of the Workstation Install File or
Deep Freeze Configuration (.rdx) file. The following Workstation Tasks are available:
• Windows Update – Schedule Windows updates. You can configure additional settings
in the Windows Update tab.
• Restart – Periodically restart workstations to bring them to the original configuration
or erase unwanted data.
• Shutdown – Shut down the workstations at a specified time every day to save power.
• Idle Time – Shut down or restart the workstations if they are idle for a specified
period of time.
• Batch File – Run a batch file on the target workstation. You can configure additional
settings in the Batch File tab.
• Thawed Period – Reboot Thawed for a specified period to perform manual software
installs, automated software installs via third-party tools or other permanent
configuration changes.
Each task is covered in detail in the following sections.
Windows Update
Windows Update tasks are scheduled for downloading Windows Updates on the
workstation. Windows Updates can be downloaded even when the workstation is in a
Frozen state. A Windows Update task has a Start Time and an End Time. After
downloading Windows Updates, the workstation reboots in a Thawed state to apply.
The Windows Update task can be scheduled by completing the following steps:
1. Select Windows Update from the Task Type drop-down and click Add.
2. The following options are displayed:
Allow user to cancel task – Select the checkbox if the user is allowed to cancel the
task before it starts.
Attempt to wake up locally – Select this checkbox to wake up the workstation locally
without requiring any communication from the Enterprise Console.
Shutdown after task – Select the checkbox to shutdown the computer after the task.
Disable Keyboard and Mouse – Select the checkbox to disable keyboard and mouse
during the task.
Show message – Select the checkbox to display a message on the computer Before
and During the task. Specify the time interval in minutes and enter a brief message
to be displayed before the task starts.
3. Click OK. You will be taken to the Windows Update Tab to configure additional
settings if it has not been configured earlier.
When scheduling the Windows Update task select the When Windows
Update completes option or ensure that you allow a sufficient time frame to
permit all required update activities. Review of Microsoft Security Bulletins
from the Technet web site
(http://technet.microsoft.com/en-us/security/bulletin) to consider the
appropriate time frame based upon the Critical and Security updates being
released.
If you are not using WSUS, Deep Freeze Windows Update process will only
apply non-user-intervention Critical and Security updates, as well as Feature
updates for Windows 10. If you are using WSUS, all WSUS approved updates
will be applied.
If you are not using WSUS, Windows Update task will always try to install
Feature updates whenever available for the current version of Windows 10
system. You can defer installing Feature updates by selecting Choose when
updates are installing under Advanced Options of Windows Updates system
settings, or enabling local computer policy Select when Preview Builds and
Feature Updates are received located in Computer Configuration >
Administrative Templates > Windows Components > Windows Update >
Windows Update for Business.
Alternatively, to apply other available updates, visit the Microsoft Update
Catalog site (http://catalog.update.microsoft.com) to obtain KB downloads
which can then be applied using a Deep Freeze Batch File Workstation Task.
Batch File tasks can also be used to apply other third-party software updates.
The Deep Freeze Windows Update tab settings override the Windows
Update settings on the workstation.
Example
In the above screen, a Windows Update task has been created to perform Windows
Updates at the computer daily at 12:00 AM and end when Windows Update completes.
The task is configured to display a message to the user before Windows Update. The
keyboard and mouse are disabled.
Restart
The Restart task can be scheduled by completing the following steps:
1. Select Restart from the Task Type drop-down and click Add.
Example
In the above screen, a Workstation Task has been created to restart the computer daily at
12:00 AM. The task is configured to display a message to the user 1 minute before the
Restart.
Shutdown
The Shutdown task can be scheduled by completing the following steps:
1. Select Shutdown from the Task Type drop-down and click Add.
2. The following options are displayed:
3. Click OK.
Example
In the above screen, a Shutdown task has been created to shutdown the computer daily at
12:00 AM. The task is configured to display a message to the user 1 minute before the
Shutdown task.
Idle Time
The Idle Time task can be scheduled by completing the following steps:
1. Select Idle Time from the Task Type drop-down and click Add.
2. The following options are displayed:
After the computer is started, the Idle Time counter becomes active only
after the first keyboard or mouse activity has been initiated. During a Remote
Desktop session, the Idle Time of the controlling computer is used to activate
the task.
3. Click OK.
Example
In the above screen, the Idle Time task is set to Restart when the computer is idle for 1
minute. A message is displayed to the user for 1 minute after the idle time has elapsed.
The computer will restart unless the user cancels the task in the message dialog
displayed.
Batch File
Batch File tasks are scheduled for executing batch files on the workstation. A Batch File
task has a Start Time and an End Time. During this period, the batch file is executed on
the workstation. You must configure additional settings in the Batch File tab for the Batch
File Task to work. You can configure to shutdown the workstation after the Batch File Task
is completed. Workstations will reboot Frozen after the batch file has been executed.
The Batch File task can be scheduled by completing the following steps:
1. Select Batch File from the Task Type drop-down and click Add.
2. The following options are displayed:
Shutdown after task – Select the checkbox to shutdown the computer after the task.
Disable Keyboard and Mouse – Select the checkbox to disable keyboard and mouse
during the task.
Show message – Select the checkbox to display a message on the computer Before
and During the task. Specify the time interval in minutes and enter a brief message
to be displayed before the task starts.
3. Click OK.
4. Go to Batch File Tab to configure additional settings.
The message This computer will reboot in %d for Batch File is displayed in the
Message to be displayed before the task field. This message can be edited.
Add the word minutes in the message after %d to include the word minutes
as part of the message.
Example
In the above screen, a Batch File task has been created to execute a Batch File at the
computer daily at 12:00 AM and end at 12.15 AM. The task is configured to display a
message to the user before the Batch File is executed. The keyboard and mouse are
disabled.
Thawed Period
Thawed Period tasks are scheduled to reboot the workstation is in a Thawed state. A
Thawed Period is useful for some applications that update automatically at regular
intervals. A Thawed Period is also useful for administrators to schedule maintenance and
make permanent changes to the computers. This may include installing new software,
updating software, configuration changes, and other maintenance functions. A Thawed
Period has a Start Time and an End Time.
Shutdown after task – Select the checkbox to shutdown the computer after the task.
Disable Keyboard and Mouse – Select the checkbox to disable keyboard and mouse
during the task.
Show message – Select the checkbox to display a message on the computer Before
and During the task. Specify the time interval in minutes and enter a brief message
to be displayed before the task starts.
3. Click OK.
Example
Anti-Virus programs require regular virus definition updates to protect the system. Virus
definitions can be updated during a Thawed Period.
In the above screen, a Thawed Period task has been created daily between 12:00 AM and
12:15 AM. The user is not allowed to cancel the task before it starts. The computer will
shut down after the maintenance period. The keyboard and mouse are disabled during
the maintenance period. The task is configured to display a message to the user 5
minutes before the task starts. The following message will be displayed on the computer
at 11:55 AM The computer will reboot in 5 minutes to enter into a Thawed Period.
To ensure that the virus definitions are applied permanently, schedule the virus definition
update for your Anti-Virus program so that it starts after Deep Freeze successfully starts
the Thawed Period task and ends before Deep Freeze ends the Thawed Period task. This
ensures that the virus definitions downloaded and updated by the Anti-Virus program
stay permanently on the system. Hence the system is fully protected by Anti-Virus and
Deep Freeze.
Faronics Anti-Virus: Faronics Anti-Virus works with Deep Freeze and does
not require a Thawed Period task for updating virus definitions. Faronics
Anti-Virus can update virus definitions even when the computers managed
by Deep Freeze are in a Frozen state.
Other Anti-Virus Programs: All other Anti-Virus programs require
scheduling a Thawed Period task to update virus definitions. Refer to your
Anti-Virus program user guide for information on how the virus definitions
are downloaded. Alternatively, virus definitions can be applied manually
when the computers managed by Deep Freeze are in a Thawed state. You can
also schedule a no user intervention install of your virus definitions through a
Batch File Task.
The Windows Update tab allows you to customize settings for Windows Update. When
you first create a Windows Update Task, you will be given an option to modify the default
settings in the Windows Update tab. Modifying the default settings is not mandatory.
Windows Update will be performed even with the default settings. The settings in the
Windows Update tab will apply to all Windows Update tasks.
The Deep Freeze Windows Update tab settings override the Windows
Update settings on the workstation.
The hidden drive letter is not visible on the workstations and is only available
for Windows 10 systems.
When choosing Important and Security Updates, Deep Freeze will also install
available Feature Updates for Windows 10.
A log file is created for each individual workstation and is stored locally on
the workstation.
The default name for the Deep Freeze Windows Update Log file is
DFWuLogfile.log and can be found at:
C:\Program Files\Faronics\Deep Freeze\Install C-[X]\DFWuLogfile.log (32-bit
systems) and C:\Program Files (x86)\Faronics\Deep Freeze\Install
C-[X]\DFWuLogfile.log (64-bit systems).
• You cannot change the name or location of the log file.
• The Deep Freeze Log file and the Windows Update log file (at
c:\windows\windowsupdate.log) are very useful for troubleshooting your
Windows updates.
• X is an incremental value depending on how many times you have
installed Deep Freeze on the workstation.
Contact Faronics Support for help troubleshooting the DFWuLogfile.log (at
http://support.faronics.com).
Contact Microsoft Support for troubleshooting Windows Update Errors. (See
http://support.microsoft.com/kb/906602)
Also see Microsoft KB 902093 How to read the Windows Update log file found
at: http://support.microsoft.com/kb/902093/ or visit
http://support.microsoft.com.
The Batch File tab allows you to customize settings for the Batch File task. When you
schedule a Batch File task from the Workstation Tasks tab, you must configure the
settings in the Batch File tab.
To save the contents of the field, click Export and browse to the preferred save
location.
The batch file can be any command or series of commands that the command
processor can run. You can run custom scripts that require the use of a third-party
scripting engine by calling the script from the batch file as if it was being run from
the command line.
Batch Files allow you to use VB Scripts, PowerShell scripts, Ninite and other
third-party solutions. Contact your software vendor or refer to your
third-party solution user guide to know more about scripting solutions that
include no user intervention options.
The Advanced Options tab is used to configure the network settings used by the
computers to communicate with the Console, configure various security options, and
administer License Keys.
Network
Communication between the Deep Freeze Enterprise Console and computers with Deep
Freeze installed can use two different modes: LAN Mode or LAN/WAN Mode.
• LAN – Select LAN to configure Deep Freeze to communicate within a Local Area
Network (LAN). LAN mode is a self-configuring mode that requires only a port
number. The default port is 7725. The port number can be changed if it is in conflict
with other programs on the LAN. In LAN mode, the Deep Freeze target computer and
the Enterprise Console find each other through UDP broadcasts. These broadcasts
only occur when computer or the Enterprise Console is started, ensuring that there is
little network traffic associated with target computer and Console communication.
• LAN/WAN – Select LAN/WAN to configure Deep Freeze to communicate in both a
LAN and a WAN (wide area network). LAN/WAN can be used in either a LAN or WAN
environment and over the Internet. This mode uses an IP address or the computer
name, along with a port number, to allow communication between the Enterprise
Console and the managed computers.
The following two methods are available to identify the Console:
• Specify the Console IP, which must be static
• Specify the Console Name, in which case the IP can be dynamic (if valid DNS name
resolution is available as part of the domain infrastructure).
When the Enterprise Console is behind a firewall or a NAT (network address translation)
router, the firewall or router must be configured to allow traffic to pass through to the
Enterprise Console. Depending on the firewall or router, computers may need to be
configured with the IP address of the firewall so that traffic can be forwarded.
For more information on configuring and using Deep Freeze in a specific network
environment, refer to Appendix B or contact Technical Support.
If a port number other than the default of 7725 (registered to Deep Freeze) is used, care
should be taken to ensure that there are no conflicts with applications already running on
the network. Well-known ports (0–1023) should be avoided and any Registered Ports
(1024–49151) should be checked for conflicts before deployment.
A complete listing of the ports assigned to various applications can be found on the
Internet Assigned Numbers Authority web site at
http://www.iana.org/assignments/port-numbers.
Advanced Options
• Disable Command Line options – This option is selected by default. Clearing this
checkbox allows for further customization of the Deep Freeze installation program
when using the Silent Install System. Selecting this option prevents the pre-existing
configuration choices from being changed during installation.
• Enable Deep Freeze local policies – For enhanced security, Deep Freeze removes the
following local privileges: debugging programs, modifying firmware, and changing
the system time; clear this option to use existing privileges.
• Allow user to change the clock – Select this option to allow Frozen users to adjust the
system clock. Enable this feature during Daylight Savings to allow Windows to update
the time automatically each season.
• Manage Secure Channel Password – Secure Channel Password is a feature of all
Windows operating systems and only applicable if the system is running in Windows
Server Domain Environment. Secure Channel Password is used for secure
communication between the server and workstations. The Secure Channel Password
is automatically changed based on the operating system settings. While using Deep
Freeze, the newly changed Secure Channel Password is lost on reboot. The Manage
Secure Channel Password option avoids this situation. The Manage Secure Channel
Password feature of Deep Freeze changes the value of the Group Policy Maximum
machine account password age based on the Deep Freeze state (Frozen or Thawed).
Select the Manage Secure Channel Password option if you want Deep Freeze to
manage Secure Channel Password.
When the workstation is Frozen – The workstation will not change the Secure
Channel Password. This ensures that the secure communication between the server
and the workstation is always maintained.
When the workstation is Thawed – The workstation will change the Secure Channel
Password and sync the password with the server.
Do not select the Manage Secure Channel Password option if you do not want Deep
Freeze to manage the Secure Channel Password.
When the workstation is Frozen – When the Secure Channel Password is changed
and synced with the server, it resets to the old password on reboot.
When the workstation is Thawed – If the workstation is Thawed on the day the
Secure Channel Password is changed, the new password takes affect and the
workstation is synced with the server.
• Restart on Logoff – Select this checkbox to Restart the computer automatically when it
is logged off. If this option is selected, the computer is restarted when a user logs off
in a Frozen state.
• Protect MBR/GPT – Select this checkbox if you want Deep Freeze to protect the Master
Boot Record or the GUID Partition Table. If this option is selected, changes to the
Master Boot Record are reversed on reboot when the computer is in a Frozen state.
• Retain Windows Event Logs – Select this checkbox to retain Windows Event Logs.
Deep Freeze creates a 100 MB ThawSpace and stores all Windows Event Logs so they
are not erased upon reboot even when the computer is in a Frozen state. The log file is
recycled once it reaches 100 MB. The log files contain events related to Application,
Hardware, System and Security.
• Delay Frozen reboot to complete Windows updates – Select this option to delay
reboot into a Frozen state if configuration or installation for Windows updates are
pending. If you select this option and perform Windows updates (through means
other than Deep Freeze), rebooting into a Frozen State will ensure that all Windows
updates installation and configuration are completed before rebooting into a Frozen
state.
If you select Delay Frozen reboot to complete Windows updates and install
Deep Freeze, the installer checks if all Windows updates are completed. If the
Windows updates are not completed, Deep Freeze installation will not
proceed. Complete Windows updates and try installing Deep Freeze again.
If you disable Delay Frozen reboot to complete Windows updates and install
Deep Freeze, ensure that all Windows updates are completed manually.
Disabling this option may result in the computer being stuck in a reboot
cycle due to incomplete Windows updates.
Example
On a Windows Domain Environment using Windows Server 2008 R2 that manages
multiple workstations, Secure Channel Password is used for secure communication
between the server and workstations.
In Deep Freeze Enterprise Configuration Administrator, go to the Advanced Options tab
and select Manage Secure Channel Password. Create the Workstation Install file and
deploy it to the workstation.
Set the following in the Group Policy for the Manage Secure Channel Password feature to
work:
Domain Controller: Refuse machine account password changes to Not Defined
Domain Member: Disable machine account password changes to Disabled
When the workstation is Frozen, the Secure Channel Password does not change. When
the workstation is Thawed, the Secure Channel Password is changed at the workstation
and synced with the server.
Stealth Mode
• Show Frozen icon in system tray – Select this option to display the icon to indicate
that Deep Freeze is installed and the computer is Frozen.
• Show Thawed icon in system tray – Select this option to display the icon to indicate
that Deep Freeze is installed but the computer is Thawed.
If the options to show a Deep Freeze icon in the System Tray are unchecked, the
keyboard shortcut CTRL+ALT+SHIFT+F6 must be used to access the logon dialog.
License
• License Key – Click Edit and enter the License Key. Click Update License.
• License Key Type – The License Key type is displayed. This field displays if this is an
Evaluation version or a full version.
• Expiry Date – The Expiry Date for Deep Freeze is displayed.
To create customized Deep Freeze installation program files with all of the options that
were configured in the previous sections, click the Create button in the Configuration
Administrator toolbar and select Create Workstation Install Program.
The default file name for this program is DFWks.exe. We recommend that
you keep the default name, but in larger deployments you may want to suffix
it with information related to its configuration such as:
DFwks_10gbThawSpace.exe or DFWks_NoMaintenance.exe or
DFwks_Wed-5pmUpdates.exe to assist in organization and identification of
the installer functions. The same recommendation applies for Deep Freeze
Configuration files (.rdx) as well.
This file can then be used to install Deep Freeze on computers using:
• Attended Install (install based on user input)
• Silent Install system – Install that does not inform user of progress or provide
messages during installation). For more information on the Silent Install command,
refer to Silent Install or Uninstall.
• Target Install – Through the Deep Freeze Enterprise Console for workstations that
already contain a Seed or previous version of Deep Freeze that has been created with
the same Customization Code.
To create a Workstation Seed, click the Create button in the Configuration Administrator
toolbar and select Create Workstation Seed. The Workstation Seed is a lightweight
program that allows administrators to remotely install and control computers from the
Enterprise Console. The Workstation Seed can be installed as part of a master image and
then deployed via imaging software. All computers on the LAN with the Workstation Seed
installed are displayed in the Enterprise Console. The default file name for this program is
DFWksSeed.exe.
All files are saved to Deep Freeze Enterprise > Install Programs folder by default. A
different location can be chosen and the file name can be changed if required. To set up
another location as the default location, select the preferred location for saving the
installation programs and Workstation Seeds and click Save. Check the Set this folder as
the default location save location checkbox when prompted. Click OK.
It is recommended that a naming convention is used if you are creating multiple
customized installation files.
Topics
Deep Freeze Configuration is a group of settings that defines the behavior of Deep
Freeze on the workstation. Deep Freeze Configurations can be created and applied
through the Deep Freeze Console.
Complete the following steps to create a Deep Freeze configuration:
1. Launch Deep Freeze Console.
2. Go to Network and Groups > Available Configurations > Deep Freeze.
3. Right-click and select Create New Configuration.
4. Select or specify the settings for each tab as described in Using Deep Freeze
Enterprise Configuration Administrator.
5. Specify the name of the configuration and click OK.
6. Optionally, select Export As > Workstation Seed or Export As > Workstation Installer
from the drop-down to export the configuration.
7. Click OK.
Configuration Generator
Deep Freeze Console provides a tool called the Configuration Generator to automatically
create Deep Freeze Installation or Deep Freeze Configuration files based on the
parameters specified in a CSV file. A Sample CSV file is provided which can be edited to
include unlimited entries. The parameters for the settings in CSV file are identical to the
settings in the Deep Freeze Enterprise Configuration Administrator. The column title in
the CSV file represents the particular setting and the row represents an entry for a single
Deep Freeze Configuration or Deep Freeze Installation file.
Complete the following steps to generate multiple Deep Freeze Installation files using
the Configuration Generator:
1. Launch Deep Freeze Console. Go to Tools > Configuration Generator. Alternatively, you
can also launch it from the Deep Freeze Enterprise Configuration Administrator from
File > Configuration Generator.
If you are using the Configuration Generator for the first time, click Sample
CSV to download a template of the file. You can update the Sample CSV file
with the values required for generating the Deep Freeze Installation or Deep
Freeze Configuration files. It is recommended to save the file with a more
descriptive name.
Column/Parameter Description
FileName Specify the file name and path where the files will be saved.
Column/Parameter Description
Specify 1 for enabling the password 1. Specify 0 to disable the password
Password1Enable
1.
FrozenDrives Specify the Frozen drive letters in a single line (for example CDEF).
Specify 1 to use the default port 7725. Specify 0 if the default port is not
UseDefaultPort
to be used.
ConsoleIP_NAME Specify the Console IP, which must be static or the name.
Column/Parameter Description
Specify 1 to disable the command line. Specify 0 to enable command
DisableCMD
line.
BatchFile Specify the contents of the batch file. Only 1 line is supported.
Column/Parameter Description
Specify 1 to Cache Windows Updates. Specify 0 if Windows Updates are
CacheWU
not to be cached.
Specify 1 to use WSUS for Windows Updates. Specify 0 if WSUS will not
WSUS
be used for Windows Updates
Task1StartMessage Specify the message when the task starts. Only 1 line is supported.
Task1DuringMessage Specify the message during the message. Only 1 line is supported.
The Deep Freeze Enterprise Console displays the status of all Frozen, Thawed, and Target
computers on the network and allows the administrator to perform specific tasks on
those computers. Detailed status information is available with selective or group
reporting.
The Enterprise Console allows administrators to remotely perform the following tasks:
• Immediately Target Install computers
• Selectively Freeze, Thaw, or Thaw Lock one or more computers
• Lock or Unlock selected computers
• Restart or shutdown computers
• Stop scheduled maintenance
• Power on computers equipped with a Wake-on-LAN network card
• Update Deep Freeze software
• Schedule tasks directly from the Console
• Send messages to computers
• Import groups and containers from Active Directory
• Generate One Time Passwords
• Schedule Actions
• Customize the Enterprise Console
• Update the License Key
The Enterprise Console can only wake a computer from a powered-down state if the
computer is properly configured to power on when a Wake-on-LAN packet is received.
Status Icons
The Enterprise Console displays the status of the computers on the local area network
with the following icons beside or above the computer name, depending on the view
selected:
Target: Computers that have the Deep Freeze Workstation Seed installed but do not
have Deep Freeze installed; Deep Freeze can only be remotely installed on
computers with this icon
Computers that are Thawed for the period longer than defined in the Thawed Alert
settings
Computers that are Thawed Locked for the period longer than defined in the
Thawed Alert settings
View Columns
Deep Freeze Enterprise Console provides the ability to specify the columns that are
displayed in the Workstations pane. Complete the following steps to display the desired
columns:
1. Go to View > Columns.
2. Select the following columns to display:
Configuration
Configuration Date
Expiry Date
Installation File
IP Address
License Status
Login Name
MAC Address
Operating System
Port
Status
Thawed For
ThawSpace Free
Version
Workgroup
Anti-Virus
You can select the workstations based on the Deep Freeze status on the managed
workstations. The status based selection can be done through the Select menu in the
Deep Freeze Enterprise Console. The Select menu has the following options:
• Select All Frozen – Selects the workstations in Frozen state. Workstations that are
Frozen and Locked are also selected.
• Select All Thawed – Selects the workstations in Thawed state. Workstations that are
Thawed and Locked are also selected.
• Select All Target – Selects all the target computers where Deep Freeze can be installed.
• Select All – Selects all workstations.
The following selection options are available from the Status pane as well:
• Frozen – Selects the workstations in Frozen state. Workstations that are Frozen and
Locked are also selected.
• Thawed – Selects the workstations in Thawed state. Workstations that are Thawed and
Locked are also selected.
• Target – Selects all the target computers where Deep Freeze can be installed.
• History – Displays the history.
• Total – Selects all workstations.
The status pane on Deep Freeze Enterprise Console can also be used to select and display
the workstation count for a particular state.
There are two types of connections from Console to workstation and Console to Console:
1. Local connections – Connections that can only be accessed by the Enterprise Console
that hosts those connections.
2. Remote control enabled connections – Connections that can be accessed by the
Console that hosts as well as other Consoles connected remotely.
The Server Service for Deep Freeze 6.5 will not automatically update the
Server Service for Deep Freeze 6.4 or lower. Both services can be installed on
the same computer, but only one service can run at a time.
A computer can lose communication with the Console for any of the following reasons:
• The computer is powered off manually or is shut down without warning
• The network is experiencing heavy traffic or outages
• The computer’s network settings are changed to point to a new Console
In most cases, communication with the computer is re-established when the computer is
powered on or when the conditions causing the communications breakdown are
rectified. It may take several minutes for the computer to report back to the Console and
re-establish communication. If communication cannot be re-established, contact
Technical Support for troubleshooting steps.
Remote Consoles
A Remote Console is a Console that hosts one or more connections that allow other
Consoles to connect through. Existing connections must be edited to allow them to be
accessed remotely.
Once a Remote Console has been established by the hosting Console it can be accessed
by other Consoles from a different machine.
1. Select the Connect to Remote Console icon in the side bar or by right-clicking on the
network item. Upon selection the Connect to Remote Console dialog appears:
2. In the Connect to Remote Console dialog, specify the connection details such as
Remote Console Name, Remote Console IP, Port number, and Password. This
information is provided by the administrator of the host Console. Once entered, this
information can be retrieved by right-clicking a port in the Network and Groups Pane
and selecting Properties.
The Enterprise Console contains a toolbar at the top of the screen that allows quick
access to the functions of the Console.
Go to View > Classic Look to view the icons in Classic Windows format.
Go to View > Modern Look to view the icons in Modern Windows format.
These commands can also be accessed using the contextual menu, as shown below, that
appears by right-clicking on one or more computers. When a particular action is chosen,
the selected computer performs the action and the status icons update accordingly. If
multiple computers are selected, the action is applied only to the applicable computers.
For example, if you select computers that are Thawed and Frozen and apply the Reboot
Thawed action, only the Frozen computers will be Thawed. The action will not be applied
on the computers that are already Thawed.
Specific icons are disabled if the selected computer does not support that action. For
example, a computer that has a Target icon, will not show the option to be Thawed or
Frozen, because the program has not been installed yet.
3. Click OK. A standard Open File dialog appears to select an .rdx file.
4. Locate a file and click Open to update the configuration on the selected computer(s)
with the settings in the .rdx file. Click Cancel to cancel the configuration update.
Changes to passwords take effect immediately. All other changes take effect
after each computer is restarted. ThawSpace and/or Frozen Drives cannot be
changed through updating the configuration file.
Remote Launch
This feature allows IT administrators to remotely launch executable files on managed
workstations. File types supported are .exe (executables), .msi (MSI installers), .bat/.cmd
(batch script), .vbs (VB script), and .ps1 (PowerShell). When an MSI installer is selected,
Deep Freeze runs it using MSIEXEC.
You can also specify a web URL or FTP location for downloading and installing executable
files. The file will be automatically downloaded from the specified location and launched
on the workstation.
To remotely launch executables on workstations, complete the following steps:
1. An executable can be launched on workstations in one of the following ways:
Right-click on one or more workstations and select Remote Launch from the context
menu.
Scheduled through Deep Freeze tasks.
2. Specify the values for the following fields or alternatively, select a previously specified
value from the history drop-down:
Filename and Path – Specify the filename and path where the file is available on the
target computer. Alternatively, you can browse to select the executable. Or specify
a URL or FTP location. File types supported are .exe, .msi, .bat/.cmd, .vbs, and .ps1.
MSI installers are run in install mode by default. For example, if the executable
MyApplication.exe is available at C:/AppFolder, specify C:/AppFolder/MyApplication.
3. Specify the Command Line Parameters with environment variables (optional):
Arguments – Specify the arguments that you want to apply with this executable. For
example, if the executable is run from the command prompt with the command
C:\AppFolder\MyApplication -o logFile.log, specify -o logFile.log for arguments. For
.msi files, specify the arguments that you would normally specify when launching a
.msi file with MSIEXEC. If you do not specify any argument for a .msi file, Deep
Freeze will automatically append "/i" (install). Deep Freeze also replaces any display
options with /qn, (quiet, no UI).
4. Click OK.
The file is remotely launched on the selected workstations.
2. Browse to select the file path or specify the file path (or alternatively, select a
previously specified value from the history drop-down):
Filename and Path – Specify the filename and path where the file is available on the
console computer. Alternatively, you can browse to select the executable. Or specify
a URL or FTP location. File types supported are .exe, .msi, .bat/.cmd, .vbs, and .ps1.
MSI files are run in install mode by default. For example, if the executable
MyApplication.exe is available at C:/AppFolder, specify
C:/AppFolder/MyApplication.
3. Specify the Command Line Parameters with environment variables (optional):
Arguments – Specify the arguments that you want to apply with this executable. For
example, if the executable is run from the command prompt with the command
C:\AppFolder\MyApplication -o logFile.log, specify -o logFile.log for arguments. For
.msi files, specify the arguments that you would normally specify when launching a
.msi file with MSIEXEC. If you do not specify any argument for a .msi file, Deep
Freeze will automatically append "/i" (install). Deep Freeze also replaces any display
options with /qn, (quiet, no UI).
4. Click OK.
The file is pushed to the selected workstation and remotely launched on the selected
workstations.
Format ThawSpace
Deep Freeze Enterprise Console provides the ability to format a specific ThawSpace or all
ThawSpaces on managed workstations.
Complete the following steps to format ThawSpaces:
1. Select one or multiple workstations.
2. Right-click and select ThawSpaces > Format ThawSpace. Alternatively, you can click
the Format ThawSpace icon in the toolbar.
3. The Format ThawSpace dialog is shown. Select All or select the specific drive to
format.
4. Select I understand there is no going back and everything within the ThawSpace(s) will
be permanently deleted.
5. Click OK.
The Format ThawSpace command deletes all data on ThawSpaces. The data
cannot be recovered once it is deleted. Backup important files before
formatting the ThawSpace.
Delete ThawSpace
Deep Freeze Enterprise Console provides the ability to delete a specific ThawSpace or
delete all the ThawSpaces on managed workstations.
Complete the following steps to delete ThawSpaces:
1. Select one or multiple workstations.
2. Right-click and select ThawSpaces > Delete ThawSpace. Alternatively, you can click the
Delete ThawSpace icon in the toolbar.
3. The Delete ThawSpace dialog is shown. Select All or select the specific drive to delete.
4. Select I understand there is no going back and the ThawSpace(s) will be permanently
deleted.
5. Click OK.
• To view the log file for one or many computers, right-click on the computer(s) and
select Show Log.
• To sort the log file, click on a preferred heading. The following columns are available:
Workstation
Domain
Time
Status
The Status column displays the current status of the computer and how the
computer was rebooted.
For example, if the computer was rebooted to a Thawed state through the console,
the status will display as Thawed (Console).
IP Address
MAC Address
Applied Command (Frozen, Thawed, Restart, Shutdown)
Installation File
• To export the log file click Export As and select Text or CSV. Specify the name of the
file and click OK.
Thawed Alerts
Thawed Alerts notify the administrator if a computer has been left in a Thawed state for a
specified period of time. Deep Freeze Enterprise Console will display the workstation icon
in red and the Thawed For column will display the number of hours the workstation has
been in a Thawed state.
Complete the following steps to set a Thawed alert:
1. Go to Tools > Thawed Alerts.
2. The Thawed Alerts dialog is displayed. Select Enable Thawed Alerts if the workstation is
Thawed for more than x hours. Select the value for x.
Licensing
The License Key can be updated via the Deep Freeze Enterprise Console and the
workstation licenses can be activated either automatically or manually.
To activate the Deep Freeze workstation licenses automatically, complete the following
steps:
1. Launch the Deep Freeze Enterprise Console.
2. Go to Tools > Licensing.
3. The Licensing dialog is displayed.
4. Click Edit and enter the License Key in the License Key field.
5. Click Update License. This converts Deep Freeze from the Evaluation version to a
Licensed version. The License Key Type field displays the License Key. The Expiry Date
displays the date and time when the license expires.
Deep Freeze automatically activates each workstation license via the Enterprise Console
or by connecting directly to the Faronics License Activation Server.
The workstation will connect either via the local console or directly to the
Faronics Activation server and transmit to our secure servers certain
information relating to your computer (including product version, license
key, machine ID, OS version, MAC address, CPU ID, and console machine ID)
as and when an Internet connection is available.
Manual Activation
To activate the Deep Freeze workstation licenses manually, first complete the steps 1-5
above. Thereafter, complete the following steps:
1. Click Activate Now. Two options are available:
Select Activate Online to activate Deep Freeze workstation license over the Internet.
The license on the workstation is activated on clicking Next. The computer must be
connected to the Internet to Activate Online.
Select Activate Offline to activate the Deep Freeze workstation license with Faronics
by email or by phone. Click Next. The Activate Offline screen is displayed:
2. Click Create Offline Activation Request File and click Save. Send the file to
activation@faronics.com to receive an Activation Response File. Browse to select the
Activation Response File received from Faronics. Click Apply Offline Activation Request
File.
The License Key is automatically updated on all computers communicating with the
Enterprise Console. If a computer is offline (shut down or disconnected from the
network), the License Key is updated when the computer communicates with the
Enterprise Console.
License Icon
If you have workstations whose Deep Freeze licenses are not activated by Faronics
License Activation Server, an activation icon appears in the toolbar. You can activate the
workstations with pending activations either online or offline.
Complete the following steps to activate the workstations using the activation icon:
1. Click the drop-down on the activation icon.
2. Select Activate All Workstations Online. Deep Freeze Console contacts the Faronics
Licensing Server and activates the licenses. An Internet connection is required to
activate online.
3. Alternatively, select Activate All Workstations Offline. For more information about
offline activation, go to Manual Activation.
2. Double-click the preferred task or select the task and click Next. The following tasks
are available for Deep Freeze:
Restart
Shutdown
Wake-On-LAN
Reboot Frozen
Reboot Thawed
Reboot Thawed Locked
Send Message
Run Windows Updates
Remote Launch
Push and Launch
Update
Format ThawSpace
3. In the following screen, enter a name for the task and choose the preferred task
execution schedule: Daily, Weekly, Monthly, or One time only. Task names must be
unique. No two tasks can have the same name. Click Next.
4. Depending on the choice of task execution, the time and date configuration options
that follow will vary. Click Next.
The default start time for a task is five minutes from the current time.
To schedule a Combination Task in the Enterprise Console using the Scheduled Task
Wizard, complete the following steps:
1. Open the Scheduled Task Wizard in one of the following ways:
Click Scheduler in the Network and Groups pane and click the Add Task icon
Right-click on Scheduler in the Network and Groups pane, and choose Add Task
4. Depending on the choice of task execution, the time and date configuration options
that follow will vary. Click Next.
5. Select the task from the drop-down and specify the time. Click the + sign to add
another task. Repeat the process to add up to 5 tasks for a maximum of 20 hours. Click
Next.
After a task has been scheduled, it appears under the Scheduler in the Network and
Groups pane of the Console.
To assign computers to a task, select the preferred computers from the Workstations
pane in the Console and drag them onto the preferred task. Or, drag a group onto the
task.
To see which computers are assigned to a specific task, click on the task. The assigned
computers appear in the Workstations pane.
To delete a computer from a task, right-click on the computer and select Remove from
Task.
Adding a Task
To add a task, right-click on Scheduler and select Add Task.
Editing a Task
To edit a task, right-click on the task and select Edit Task.
Pausing a Task
To pause a task, right-click on the task and select Pause Task.
Resuming a Task
To resume a task, right click on the task and select Resume Task.
Deleting a Task
To delete a task, right-click on the task and select Delete Task.
Scheduled tasks will still execute even if the Enterprise Console is closed
provided the local service is enabled and the network connections are not
shutdown upon exiting the Enterprise Console.
Adding a Group
The Add Group dialog allows you to configure multiple filters to sort the workstations
into different groups. This filter automatically updates the list of workstations based on
the changes in the selected parameters.
Complete the following steps to add a group with a Filter:
1. Right-click User Defined Groups in Network and Groups pane.
2. Select Add Group. The Add Group dialog is displayed:
The following table shows the Column, Comparison, Option, and Values.
Select Column Select Comparison Select Option Specify Value or Regular Expression
Equals
And Specify the Value or Regular
Workstations Not Equal To
Or Expression.
Regular Expression
Select Column Select Comparison Select Option Specify Value or Regular Expression
Equals
And Specify the Value or Regular
Workgroup Not Equal To
Or Expression.
Regular Expression
Equals
Greater Than
Greater Than or Equal To And Specify the Value or Regular
IP Address
Less Than Or Expression.
Frozen
Frozen and Locked
Thawed
Thawed and Locked
Equals Applying Windows Update
And
Status Not Equal To Applying Batch File
Or
Regular Expression Thawed Period
Maintenance Mode
License Expired
Workstation Seed
Unknown
Equals
And Specify the Value or Regular
Configuration Not Equal To
Or Expression.
Regular Expression
Equals
Greater Than
Greater Than or Equal To And
Configuration Date Specify the Date.
Less Than Or
Less Than or Equal To
Regular Expression
Equals
And Specify the Value or Regular
Installation File Not Equal To
Or Expression.
Regular Expression
Select Column Select Comparison Select Option Specify Value or Regular Expression
Equals
Greater Than
Greater Than or Equal To And Specify the Value or Regular
Version
Less Than Or Expression.
Equals
And Specify the Value or Regular
Operating System Not Equal To
Or Expression.
Regular Expression
Equals
And Specify the Value or Regular
MAC Address Not Equal To
Or Expression.
Regular Expression
Equals
And Specify the Value or Regular
Login Name Not Equal To
Or Expression.
Regular Expression
Equals
Greater Than
And
Thawed For Greater Than or Equal To Specify the Value.
Or
Less Than
Less Than or Equal To
3. Enter the LDAP server information of the import location. The option to login
anonymously is also available. If this checkbox is not selected, a user name and
password is required.
4. Select Secure LDAP if your network uses Secure LDAP. (For more information on Secure
LDAP go to https://support.microsoft.com/en-ca/kb/321051)
5. Click Connect. The Active Directory hierarchy appears. Select the required entries and
click Import.
History
Computers can be added to a group by dragging them from the Workstations pane to the
preferred group, or by using an automatic filter set during the creation of the groups.
Automatic group filtering allows computers to be added to user-defined groups
automatically. The computers are added based on their computer name.
Wildcards (*, ?) can be used to add computers based on a specific segment of the name.
Example: Lab1-* adds all computers with names starting with Lab1- .
Deep Freeze provides the following custom actions that can be accessed via the Actions
menu. Additional actions can be created to suit specific needs. Deep Freeze provides
three default actions. Additional Custom Actions can be configured by importing the
appropriate .xml file in the Deep Freeze Console. For more information on Custom
Actions, the structure of the custom action file and details about various parameters,
refer to Appendix E.
Configure
1. Go to Action > Custom Actions.
2. Select Remote Execute.
3. Enter the PSExec Location or browse to select the location.
4. The Executable path and the Working Directory are added automatically. The
Executable path and Working Directory can be modified later.
5. Click Close.
Execute
1. Select the computers from the Workstations pane.
2. Select Action > Remote Execute.
3. The Remote Execute dialog is displayed.
4. Enter the User Name, Password and Command.
5. Click OK.
Configure
1. Go to Action > Custom Actions.
2. Select Push and Install MSI file.
3. Enter the PSExec Location or browse to select the location.
4. The Executable path and the Working Directory are added automatically. The
Executable path and Working Directory can be modified later.
5. Click Close.
Execute
1. Select the computers from the Workstations pane.
2. Select Action > Push and Install MSI file.
3. The Push and Install MSI file dialog is displayed.
4. Enter the User Name, Password, File Name and Drive Letter.
5. Click OK.
Remote Launch
You can remotely launch executable files on managed workstations.
Complete the following files to remotely launch files on managed workstations:
1. Select one or more workstations from the Workstation pane.
2. Right-click and select Actions > Remote Launch. The Remote Launch dialog is
displayed:
Console Customizer
The Console Customizer lets you specify which features and commands you want to be
available in the Console, and save the result as a new Console that can be distributed in
your organization.
The available settings are grouped into categories (Console functions, Workstation
commands, Deep Freeze commands, Workstation install/uninstall commands, and
Scheduler commands). Click on the plus (+) icon to the far left of each category to
disclose the full list of settings available in that category.
Select or clear the individual checkboxes as required. Alternatively, select or clear the
entire categories at once. Settings that are cleared will not be available in the new
Enterprise Console you create. For an example on how to use the Console Customizer in
a practical scenario, refer to Appendix D.
Complete the following steps to create Consoles with limited functionality:
1. Select Tools > Console Customizer.
2. The Console Customizer is displayed.
To shut down the Deep Freeze Console select File > Exit or click the close window button.
Upon exit, you can choose to:
• Minimize the Console to the system tray.
This does not stop the Console and keeps the connections active. The Deep Freeze
Console icon appears in the system tray. Scheduled tasks will still execute. To reopen
the Deep Freeze Enterprise Console, right-click its icon located in the taskbar and
select Restore Deep Freeze Console.
• Close Deep Freeze Console and leave the network connections running
This closes the Console but keeps the connections to the computers active. Scheduled
tasks will still execute.
• Close Deep Freeze Console and shut down network connections.
This stops Console processes, closes the connections (including local service), and
scheduled tasks will not start to execute. However, scheduled tasks that have started
executing will continue.
The dialog will not appear on future exits once the Set Default option has been selected.
To edit these settings select Tools >Exit Options.
After a customized installation program file has been created using the Configuration
Administrator, Deep Freeze can be deployed to computers using an Attended Install, a
Target Install, the Silent Install System, or as part of an imaging process.
All background utilities and anti-virus software should be disabled and all
applications should be closed prior to installation. These programs may
interfere with the installation, which could result in Deep Freeze not
functioning correctly.
The computer restarts after any type of installation is completed. Deep Freeze must be in
a Thawed state for any type of uninstall to succeed.
Any existing ThawSpace will be deleted during an uninstall if:
• The option to retain existing ThawSpace was not checked in the Configuration
Administrator.
• The ThawSpace was not created with Deep Freeze Enterprise Version 5 or later.
Click Uninstall to uninstall Deep Freeze. Uninstall can only be clicked if Deep
Freeze has previously been installed and the computer is currently Thawed. If
there is an existing ThawSpace, Deep Freeze displays a dialog asking if it
should be retained or deleted.
The Enterprise Console can be used to uninstall Deep Freeze completely or to uninstall
Deep Freeze but leave the Workstation Seed. A computer must be in a Thawed state in
order to uninstall the program.
To uninstall Deep Freeze on a computer and leave the Workstation Seed, right-click on
the Thawed workstation(s) and select Uninstall (Leave Seed), as shown above. Or click the
icon on the toolbar.
To completely uninstall Deep Freeze and the Workstation Seed, select the computer(s) to
be uninstalled and click the Uninstall icon on the toolbar.
The computer must be Thawed before Deep Freeze can be uninstalled. The
Enterprise Console prompts for confirmation. Once the uninstall is
confirmed, Deep Freeze uninstalls and the computer restarts.
Deep Freeze can be rapidly installed to many computers over a network using the Silent
Install System. Any deployment utility that allows execution of a command line on a
remote computer can implement the Silent Install System. After the Silent Install is
complete, the computer immediately restarts. The command line has the following
options:
Syntax Description
[/Install] Install Deep Freeze using installation file
Deep Freeze must be prepared for deployment before finalizing a master image. To
prepare the master image for deployment complete the following steps:
1. Restart the computer into a Thawed state.
2. Launch Deep Freeze using the keyboard shortcut CTRL+SHIFT+ALT+F6. Alternatively,
press SHIFT and double-click the Deep Freeze icon in the System Tray.
3. Enter the password and click OK.
4. Click Set Clone Flag in the Boot Control tab.
5. The message The flag has been set successfully. Do you want to reboot your computer
now? is displayed. Click Yes to reboot the computer immediately. Click No to reboot
the computer later.
The Set Clone Flag command is important during imaging since it boots the
computers into a Thawed state if Deep Freeze is unable to read its
configuration file after the image is successfully installed.
If the Clone Flag is not set, and if Deep Freeze is unable to read its
configuration file, all drives are Frozen after the image is successfully
installed.
If you are using Sysprep, make sure you set the Clone Flag after preparing the
system for imaging and just before starting Sysprep.
After imaging, the computers require an additional restart for Deep Freeze to correctly
detect the changes in disk configuration. If the computers are imaged in an unattended
mode, steps should be taken to ensure the computers are restarted to allow the
configuration to update.
To return to the Frozen state after imaging is complete, set Deep Freeze to Boot Thawed
on next n number of restarts (in the master image) so that after n number of restarts, the
computer is automatically Frozen. Alternatively, use Deep Freeze Command Line Control
to Freeze selected computers.
Target Install
Deep Freeze can also be deployed using a Target Install from the Enterprise Console.
Deep Freeze allows you to check if there are newer versions available.
Go to Help > Check for updates. This checks if there are newer versions of Deep Freeze
available.
If a new version is available, click Download the latest version to update Deep Freeze.
Topics
Login Screen
Status Tab
Password Tab
Network Tab
ThawSpace Tab
Permanent Software Installations, Changes, or Removals
Login Screen
Status Tab
Clone
The Clone pane is used to prepare master images for the deployment process. For more
information, refer to the Installing Using Imaging section.
License
1. To update the License Key, click Edit and enter the License Key in the License Key field.
2. Click Update License. This converts Deep Freeze from the Evaluation version to a
Licensed version. The License Key Type field displays the License Key. The Expiry Date
displays the date and time when the license expires.
3. Click Activate Now. Two options are available:
Select Activate Online to activate Deep Freeze License online. This option is same
as step 1. Click Next after selecting this option. Deep Freeze is activated online on
clicking Next.
Select Activate Offline. This option allows you to activate by phone or email. Click
Next after activating. The Activate Offline screen is displayed:
4. Click Create Offline Activation Request File and click Save. Send the file to
activation@faronics.com to receive an Activation Response File. Browse to select the
Activation Response File received from Faronics. Click Apply Offline Activation Request
File.
The License Key is automatically updated on all computers communicating with the
Enterprise Console. If a computer is offline (shut down or disconnected from the network),
the License Key is updated when the computer communicates with the Enterprise
Console.
Password Tab
Network Tab
The Network tab can be used to configure the network options on a computer.
To choose either the LAN or the WAN method of communication, click the preferred
option.
The default port number can be changed by clearing the Use Default Port checkbox and
entering the required port number.
For more information on network configuration, refer to Appendix B.
ThawSpace Tab
ThawSpace is a virtual partition on a computer that can be used to store programs, save
files, or make permanent changes. All files stored in the ThawSpace are saved after a
restart, even if the computer is Frozen.
ThawSpace is only available if it was set to be created in the Deep Freeze Enterprise
Configuration Administrator.
After uninstalling Deep Freeze, all the ThawSpaces become visible. When Deep Freeze is
reinstalled, the ThawSpaces are Visible or Hidden as per the original settings in the
ThawSpace tab.
Any existing ThawSpace is deleted during an uninstall if any of the following apply:
• The option to retain existing ThawSpace was not selected in the Configuration
Administrator
• The ThawSpace was not created with Deep Freeze Version 5 or higher
Computers must be Thawed for any permanent changes to take effect. Installation of
software often requires one or more restarts to complete the installation.
Deep Freeze helps administrators overcome challenges with maintaining the
configuration of their computers in a production environment. Deep Freeze protects
computers from unauthorized changes, viruses and malware, that can leave computers in
a non-functional state. Deep Freeze also provides features to retain user data while
protecting the computer.
For more information on how to implement Deep Freeze and ensure that the user data is
retained, refer to Deep Freeze – Retaining User Data available at
http://www.faronics.com/library.
Managing Anti-Virus
This chapter describes installing and using Anti-Virus with Enterprise Console.
Topics
Anti-Virus Overview
Migrating to the New Anti-Virus
Enable Anti-Virus on Enterprise Console
Install Anti-Virus Client on the workstation
Anti-Virus Configuration
Using Faronics Anti-Virus from the Enterprise Console
Scheduling Anti-Virus Tasks
Using Anti-Virus on the Workstation
Check for Anti-Virus Updates
Update Faronics Anti-Virus
Updating Anti-Virus Definitions
Uninstall Anti-Virus Client from the Enterprise Console
Disable Faronics Anti-Virus from the Enterprise Console
Anti-Virus Overview
Anti-Virus can be installed and used via the Enterprise Console. Using Anti-Virus is
optional. Deep Freeze Enterprise can also be used independently without using
Anti-Virus.
The following sections are explained:
• Enable Anti-Virus on Enterprise Console
• Install Anti-Virus Client on the workstation
• Anti-Virus Configuration
• Using Anti-Virus from the Enterprise Console
• Scheduling Anti-Virus Tasks
• Using Anti-Virus Client on the workstation
• Check for Updates
• Update Faronics Anti-Virus
• Uninstall Anti-Virus Client from the workstation
• Disable Anti-Virus on the Enterprise Console
Anti-Virus is now part of the Enterprise Console and can be enabled from within. You
need to purchase a separate license for Anti-Virus.
Complete the following steps to enable Faronics Anti-Virus:
1. Launch the Deep Freeze Enterprise Console.
2. Go to Tools > Licensing > Faronics Anti-Virus License.
3. Select I would like to use Deep Freeze Console to manage Faronics Anti-Virus.
4. Click Edit.
5. Enter the License Key and click Update License.
6. Click Close. The Anti-Virus installer files are downloaded. The Anti-Virus columns are
displayed in the Workstation pane. The Anti-Virus sub-node is added under Available
Configuration in the Network and Groups pane.
Before installing Anti-Virus on the workstation, ensure that Deep Freeze Workstation
Install File or Deep Freeze Seed has been deployed to the workstation and the
workstation is in a Thawed state.
Complete the following steps to install Anti-Virus onto the workstation:
1. Select a workstation (or multiple workstations) from the Workstations pane >
Anti-Virus tab.
2. Click the Anti-Virus icon in the menu bar and select Install Faronics Anti-Virus.
3. Select the Remove any incompatible antivirus products before installing Faronics
Anti-Virus checkbox to remove existing anti-virus programs.
4. Click OK to confirm the action.
The workstation reboots and Anti-Virus client is installed on the workstations.
The Anti-Virus options are enabled in the Anti-Virus tab.
Anti-Virus Configuration
An Anti-Virus configuration contains all the settings on how Anti-Virus runs on the
workstation(s). A configuration contains the action taken by the program, schedule,
proxy servers, error reporting and the functionality allowed to the user on the
workstation(s). The following sections explain how an Anti-Virus configuration is created
and applied.
Show taskbar icon – Select the checkbox to display Faronics Anti-Virus icon on the
taskbar at the workstation(s). If this checkbox is not selected, Faronics Anti-Virus will
be hidden to the user.
> Allow manual scanning – Select the checkbox to allow users to manually initiate
Faronics Anti-Virus scanning at the workstation(s).
> Allow user to take action on scan results – Select the checkbox to allow the
workstation user to take action on the scan results.
> Allow user to abort a scan initiated locally – Select the checkbox to allow users
to abort the scan initiated locally at the workstation.
Logging Level – Select the logging level. Select None for no logging. Select Error to
log the error message. Select Trace for trace. Select Verbose for detailed logging.
Number of logging files – Specify the number of logging files. The logging
information is stored in the files serially. For example, if there are 3 files A, B and C,
Faronics Anti-Virus first writes the error logs to file A. Once file A is full, it starts
writing to file B and finally file C. Once file C is full, the data in file A is erased and
new logging data is written to it.
File size – Select the size of each file in MB.
Integrate into Windows Security Center – Select the checkbox to integrate Faronics
Anti-Virus into the Windows Security Center. Windows Security Center will notify
you via the System Tray if Faronics Anti-Virus is active or inactive.
• Updates pane
Enable Proxy – Select the checkbox if the workstation(s) require a proxy to reach
Faronics Core Server or Updates Web Server. Specify the Address and Port.
My proxy server requires authorization (logon credentials) – If the server requires
authentication, specify values for the following fields:
Authentication Type – Select the authentication type.
> Username – Specify the username.
> Password – Specify the password.
> Domain – Specify the domain.
Select the checkbox to scan USB drives upon insertion and select one of the following
options:
Do not perform USB scan if another scan is already in progress – Select this option
to ensure that an active scan is not interrupted when a USB drive is inserted. The
USB drive must be manually scanned once the active scan is complete.
Interrupt active scan for USB scan – Select this option to interrupt an active scan to
scan the USB drive when it is inserted. Once the active scan is interrupted, it will not
resume automatically and must be restarted manually.
Suppress USB scan in progress dialogue – Select this option to hide indications that
Anti-Virus is scanning USB drives when they are inserted; no Anti-Virus interface
will open, and the system tray icon will not display tooltips indicating a scan in
progress. Users will be notified at the end of a scan if a virus was found, but if no
viruses were detected there will be no notification that the scan occurred.
Note that if the Scan USB drives upon insertion option is not selected, this option
is ignored.
Quick Scan:
Enable Quick Scan – Select the checkbox to enable Quick Scan.
Start – Specify the start time.
Stop – Specify the end time. The maximum duration between the Start time and
Stop time is 23.59 hours. The scan ends if all the files are scanned before the Stop
time. If the scan is not complete before the Stop time, it is aborted at the Stop time.
Alternatively, select When scan is complete to ensure that scan is completed.
Days – Select the days when the scheduled Quick Scan will take place.
Deep Scan:
Enable Deep scan – Select the checkbox to enable Deep Scan.
Start – Specify the start time.
Stop – Specify the end time. The maximum duration between the Start time and
Stop time is 23.59 hours. The scan ends if all the files are scanned before the Stop
time. If the scan is not complete before the Stop time, it is aborted at the Stop time.
Alternatively, select When scan is complete to ensure that scan is completed.
Days – Select the days when the scheduled Deep Scan will take place.
Options:
Randomize scheduled scan start times by x minutes – Specify the number of
minutes. The scheduled scan start time is randomized to reduce the impact on
network traffic. Faronics Anti-Virus reports to Faronics Core when the scanning
starts. This might impact the network traffic if the scan for multiple systems start at
the same time.
Missed scan options at start-up – Select one of the following options on how a scan
will be performed if the workstation was not ON during a scheduled scan:
Do not perform quick scan – Select this option if you do not want to perform quick
scan on startup.
Perform quick scan approximately x minutes after start-up – Specify the number of
minutes after start-up when Faronics Anti-Virus must perform a quick scan.
Prompt user to perform Quick Scan – Select this option to prompt the user to
perform a quick scan.
• Scan Exceptions pane:
Folders or files that are known to the safe and free of infections can be added to the
Scan Exceptions tab. Files added to the Scan Exceptions tab will always be scanned by
Faronics Anti-Virus. However, Faronics Anti-Virus will never report the files as
malicious or infected. This feature is useful since files and folders that are known to be
safe by the Administrator will not be reported as malicious.
A. Click Add.
B. In the Add dialog, select File by full path or Entire folder. Click Browse to select the
file or folder and click OK.
• Enable Active Protection – Select this option to enable real-time protection. Active
Protection is the real-time scanning by Faronics Anti-Virus in the background without
any impact on system performance. If there is a risk of real-time virus infection from
the Internet, select this option.
Allow users to switch off Active Protection – Select this option to allow users to
switch off Active Protection. If users install or use software that might be mistaken
from a virus (for example, running advanced Macros in Microsoft Office or complex
batch files), select this option.
Show Active Protection alert – Select this option to display an alert if a threat is
detected during Active Protection. Do not select this checkbox if you do not want
an alert to be displayed.
Click Add to add a new Program Rule. Specify or select the options and click OK. The
following parameters are displayed:
Other ICMP Select Allow or Select Allow or Select Allow or Select Allow or
OtherIcmp
packets Block Block Block Block
Domain Name Select Allow or Select Allow or Select Allow or Select Allow or
DNS
System Block Block Block Block
Virtual Private Select Allow or Select Allow or Select Allow or Select Allow or
VPN
Network Block Block Block Block
Lightweight
Select Allow or Select Allow or Select Allow or Select Allow or
LDAP Directory Access
Block Block Block Block
Protocol
Microsoft File and Select Allow or Select Allow or Select Allow or Select Allow or
NETBIOS
Printer Sharing Block Block Block Block
Click Add to add a new Advanced Rule. Specify or select the options and click OK. The
following parameters are displayed in the Advanced Rules pane:
Click Add to add a new Trusted Zone. Specify or select the options and click OK. The
following parameters are displayed:
Once Faronics Anti-Virus Client is installed on the workstation, various actions can be
performed on the workstation via Deep Freeze Console.
Anti-Virus Commands
There are two ways the same commands via Deep Freeze Console:
• Anti-Virus menu (in the menu bar)
• Anti-Virus context menu (right-click context menu)
The menu commands are explained further in this section.
The following commands are available in the Anti-Virus menu:
The same commands are available from the Workstations pane > Anti-Virus tab >
Right-click context menu:
Quick Scan
Quick Scan checks the commonly affected areas of your computer. This is shorter in
duration than the Deep System Scan. Quick Scan also uses less memory than the Deep
System Scan.
• To start a Quick Scan
Select one or more workstations. Right-click and select Start Quick Scan.
• To stop a Quick Scan
Select one or more workstations. Right-click and select Stop Scan.
• To pause a Quick Scan
Select one or more workstations. Right-click and select Pause Scan.
• To resume a Quick Scan
Select one or more workstations. Right-click and select Resume Scan.
Deep Scan
Deep Scan performs a through scan of all areas of the computer. The time taken for the
scan depends on the size of your hard drive
• To start a Deep Scan
Select one or more workstations. Right-click and select Start Deep Scan.
• To stop a Deep Scan
Select one or more workstations. Right-click and select Stop Deep Scan.
• To pause a Deep Scan
Select one or more workstations. Right-click and select Pause Scan.
• To resume a Deep Scan
Select one or more workstations. Right-click and select Resume Scan.
Fix Now
The Fix Now option downloads the latest virus definitions and performs a quick scan on
the workstation.
• To Fix Now
Select one or more workstations. Right-click and select Fix Now.
Active Protection
Active Protection (AP) is a real-time method for detecting malware. AP sits quietly in the
background as you work or browse the Internet, constantly monitoring files that are
executed (run) without causing noticeable strain to your system.
• To Enable Active Protection
Select one or more workstations. Right-click and select Enable Active Protection.
• To Disable Active Protection
Select one or more workstations. Right-click and select Disable Active Protection.
Firewall
A Firewall provides bi-directional protection, protecting you from both incoming and
outgoing traffic. A Firewall protects your network from unauthorized intrusion.
• To Enable Firewall
Select one or more workstations. Right-click and select Enable Firewall.
• To Disable Firewall
Select one or more workstations. Right-click and select Disable Firewall.
Send Message
The Send Message option is used to send message to online workstations.
• To send a message
Select one or more workstations. Right-click and select Send Message.
The following Anti-Virus tasks can be run from the Deep Freeze Console based on a
pre-defined schedule.
• Disable Active Protection
• Enable Active Protection
• Start Quick Scan
• Start Deep Scan
The procedure to schedule tasks is explained in detail in the section Scheduling Deep
Freeze Tasks.
The features available in Anti-Virus on the workstation fully depends on the settings
selected in the Anti-Virus Configuration. For more information about Anti-Virus
Configuration, refer to Anti-Virus Configuration.
2. In the Scan Status pane, click Scan Now. The Scan tab is displayed. Alternatively, you
may also click the Scan tab.
3. Click Risk Details. The following information about each infected file is displayed:
Name
Date Added
Age (Days)
4. Select the following actions:
Details – Select a file and click Details to view details of the infected file. This also
displays the recommended action.
2. In the Update Status pane, click Update Now. The Update Now dialog is displayed.
3. Click Install Updates. The virus definitions are updated on the workstation.
Active Protection > Disable Active Protection > [Select the option] – Select the
duration for which Active Protection is to be disabled. Select 5 minutes, 15 minutes,
30 minutes, 1 Hour, Until Computer Restart or Permanently. This option is displayed
only if it has been selected in the Anti-Virus policy.
• Scan Now > [Select the option] – Select Cancel Scan, Quick Scan or Deep Scan. This
option is displayed only if it has been selected in the Anti-Virus policy.
• Firewall Protection > Enable or Disable
Deep Freeze Console allows you to check if there are newer versions of Faronics
Anti-Virus available.
Go to Help > Check for updates. This checks if there is a new version of Faronics Anti-Virus
available.
If a new version is available, click Download the latest version to update Faronics
Anti-Virus.
If you have checked for updates and a new version of is available, complete the following
steps to update a new version on the workstation:
1. Go to Anti-Virus tab in the Workstations pane.
2. Select a workstation (or multiple workstations) from the
3. Right-click and select Update Faronics Anti-Virus.
The Anti-Virus Definition Server is installed along with Faronics Anti-Virus on the same
computer where the Deep Freeze Console is installed. The Anti-Virus Definition Server
downloads the latest virus definitions and distributes to the workstations managed by
Deep Freeze.
Complete the following steps to update virus definitions:
1. Launch Deep Freeze Console.
2. Go to Tools > Anti-Virus Definition.
3. The following settings and action are available:
Complete the following steps to uninstall Faronics Anti-Virus on the workstation from the
Enterprise Console:
1. Go to Anti-Virus tab in the Workstations pane.
2. Select a workstation (or multiple workstations) from the
3. Right-click and select Uninstall Faronics Anti-Virus.
If Anti-Virus Client is uninstalled from the workstation, the Deep Freeze Seed
will be left behind.
The Deep Freeze Seed cannot be uninstalled when Anti-Virus Client is
installed on the workstation.
Anti-Virus can be disabled on the Deep Freeze Console in case it is not required to be
used.
Complete the following steps to disable Faronics Anti-Virus from the Deep Freeze
Console:
1. Go to Tools > Licensing > Faronics Anti-Virus License.
2. Clear the I would like to use Deep Freeze Console to manage Faronics Anti-Virus
checkbox.
3. Click Close.
4. Restart the Enterprise Console for the settings to take affect.
Topics
Deep Freeze Command Line Control (DFC) offers network administrators increased
flexibility in managing Deep Freeze computers. DFC works in combination with
third-party enterprise management tools and/or central management solutions. This
combination allows administrators to update computers on the fly and on demand.
It is important to note that DFC is not a stand-alone application. DFC integrates
seamlessly with any solution that can run script files, including standard run-once login
scripts.
DFC commands require a password with command line rights. OTPs cannot be used.
List all commands by calling DFC without parameters.
The files are copied to (32-bit)
<WINDOWS>\system32\DFC.exe
Syntax Description
SUCCESS or Boolean FALSE, for commands returning a Boolean
0
result
1 Boolean TRUE
Syntax Description
Restarts computer in a Thawed state; only works
DFC password /BOOTTHAWED
on Frozen computers.
DFC get /CLONE Sets the clone flag for the purpose of imaging.
Syntax Description
Restarts computer in a Thawed state with keyboard
DFC password
and mouse disabled; only works on Frozen
/BOOTTHAWEDNOINPUT
computers
Syntax Description
Activates the workstation after checking with the
DFC password /ACTIVATE
Faronics License Activation Server.
Complete the following steps to run the commands for Faronics Anti-Virus:
1. On the workstation, go to <System Directory>:\Program Files\Faronics\Faronics
Anti-Virus Enterprise via command prompt.
2. Enter AVECLI/[Command]
The following commands are available:
Syntax Description
definitionversion Displays Virus Definition version.
Syntax:
AVECLI/definitionversion
The key to setting up the Deep Freeze architecture is knowing which ports to use. The
important factor is knowing which ports are in use on the network and using ports that
will not conflict with those. The default port, 7725 has been officially registered to Deep
Freeze.
The following three components make up the Deep Freeze architecture:
• Client (with seed installed)
• Remote Console (local service enabled)
• Console (connects to the Remote Console)
As long as the clients and Remote Console connection use the same port there should
not be any port conflicts between the different components:
Ports can also be used to divide the clients. If the local service is setup to run three ports
(7725, 7724 and 7723), Enterprise Consoles can connect to the three different ports to see
a different set of clients under each port.
In the diagram above, the client(s) use both the TCP and UDP protocols to communicate
with the Remote Console. The Console(s) that connects to the Remote Console uses only
the TCP protocol to communicate with the Remote Console. It is important to remember
the ports and protocols being used in order to prevent firewalls, switches or routers from
blocking them.
The following examples show different scenarios involving local service or Remote
Console.
• Example 1 – Single Subnet
• Example 2 – Multiple Subnets, One Local Service
• Example 3 – Multiple Ports, Console Accessed Remotely
• Example 4 – Multiple Subnets, Multiple Local Services
Each example explains how different Deep Freeze components interact in different
networking environments.
In the following examples, the client machines have either the Deep Freeze
workstation installation or Workstation Seed installed. Both installs contain
the communications component which talks to the Console/Remote
Console. The difference between the workstation install and Workstation
Seed is that the workstation install actually installs Deep Freeze while the
Seed has only the communication component.
In this environment, all client machines are contained in the same subnet as the Console
machine. This environment does not require a remote controlled Console, although one
could be used. In this example, the Remote Console is not used. This is the simplest
networking environment. It is also the easiest to configure.
The following diagram shows the network topology:
The client machines, represented by the computer icons, are located on the same subnet
as the Deep Freeze Enterprise Console machine represented by the Deep Freeze Console
icon.
In this scenario, clients are using port A while the Console has set up a local service
connection for the same port. This port is configured in the Advanced Options tab, before
creating the Workstation Install file or Workstation Seed.
In this environment, the clients are located across more than one subnet. There is still only
one Console being used. This environment does not require a Remote Console, although
one could be used. The following diagram shows the network topology:
In this scenario (similar to Example 1 – Single Subnet) both the clients and the connection
hosted by the Console are using the same port. This port is configured in the Deep Freeze
Enterprise Configuration Administrator in the Advanced Options tab, before creating the
Workstation Install file or Workstation Seed.
In order for the clients to be seen, they need to be configured to use a LAN/WAN
connection. When the LAN/WAN option is selected, a Console IP field appears. Specify
the IP of the machine that will run the Enterprise Console. An example of these settings
are shown in the Advanced Options tab below:
In this environment the clients are again located across multiple ports. In this case, more
than one Console is being used. Multiple Consoles are accessed using a local service
whose administrator (host) has released the connection information. The following
diagram shows the network topology:
In this scenario, the host has set up a connection using the local service. Looking at the
above diagram, three other Consoles connect to the host in order to see the clients
according to their ports. The Consoles do not have to be a part of individual subnets as
long as they can see the host.
More specifically, The Console connected through port A/B can see the host Console as
well as each individual computer assigned to ports A and B. The other Consoles
connected through port B can see the host and only the computers assigned to port B.
The benefit of this setup is that it allows all the packets sent from the clients in Location 1
to be contained at that location. The less distance a packet must travel, the less chance
there is of the packet failing.
The administrator in the lab can connect to the local service in the same location 1 but
cannot connect to the local service in the library. The reason for this is that the lab
administrator does not know the password to access the local service for the library. The
same goes for the administrator in the library. If technical support knows the password to
both local services (lab and library) the local service at both locations can be connected
to, in order to administer all the clients.
1. The Console and clients do not contain the correct network settings.
If the Console is set up to run under one port and the clients are using another, they will
not be able to see each other. Also, if the computers are configured for LAN/WAN, the IP
must be equal to the IP of the machine where the Console is running.
The default LAN setup works as long as all the machines running the computer and
Console exist on the same subnet. However, if a VLAN is being run, or if there are several
subnets where the clients exist, the computer install must be configured to run under the
LAN/WAN settings.
2. Something on the network is blocking the port used between the Console and the
clients.
Check for a connection using a ping. The clients are unable to send packets to the
Console/Remote Console because there does not seem to be a route to the host.
Attempting to ping the IP of the Console/Remote Console does not seem to work. To
resolve this issue, make sure the two machines can connect to each other.
If a server, router, or switch on the network is not allowing the port to get through, the
clients will not be seen. By default, 7725 is the port being used.
3. The workstations were created under a different Customization Code than the
Console.
When the Deep Freeze Enterprise Configuration Administrator is first run, a prompt for a
Customization Code appears. This code is very important as it encrypts the software. This
means that any workstations created are encrypted with this Customization Code. If a
Console was created using another administrator that was installed with a different
Customization Code, it cannot see workstations created under the original code. The
workstations and Console must be created under a Configuration Administrator installed
using the same exact Customization Code.
The Deep Freeze Enterprise Console includes the ability to create a new Enterprise
Console with limited capabilities. A customized, limited console can be distributed in your
organization to allow certain users to perform desired tasks, while ensuring they do not
have access to the full capabilities of the Enterprise Console.
In this example, we will create a limited Console suitable for distribution to a teacher or
computer lab instructor. In this scenario, we want the teacher to be able to restart
machines, lock the keyboard and mouse on demand, and send messages to the students.
However, we do not want the teacher to be able to boot the machines into a Thawed
state, uninstall Deep Freeze, or perform other IT-exclusive tasks.
The Console Customizer can be launched from Tools > Console Customizer.
We will leave Console functions > Activation selected. This will ensure that if the new
Console is moved to a different computer, a One Time Password will need to be entered
on the computer the new Console is moved to. If this security precaution is not a concern
in your environment, do not select this option.
Console functions > One Time Password is not selected because we do not want a teacher
to be able to reboot the computer in Thawed mode under any circumstances. If a teacher
reboots the computer in Thawed mode, students might install unnecessary software on
the computer which will be retained even after a reboot.
We will leave all options under Workstation commands selected because we want a
teacher to be able to send messages to students, and to shutdown, restart, and wake
computers as required.
We will only leave three options under Deep Freeze commands selected: Unlock, Lock,
and Reboot in Frozen state. This will allow a teacher to lock (and unlock) the keyboard and
mouse on student computers as required, as well as to reboot computers Frozen (just in
case a computer is ever accidentally left Thawed by IT staff). Leaving all other options
cleared will ensure a teacher is unable to permanently modify a computer.
Finally, we will clear all Workstation install/uninstall commands and all Scheduler
commands because we don’t want our teacher to use any of these options.
Once all options have been selected, click Save As to save a new Enterprise Console. A
standard Save As dialog is displayed:
Save the new limited Enterprise Console and distribute it to the required users.
In the above example, the custom action file contains the command for running Remote
Desktop on the Console computer and connect the remote computer specified in the
parameter %%WKSNAME%%.
The DFEntConsoleCustomActions.xml file contains 3 samples:
• Control with RDC
• Remote Execution
• Push and Install MSI file
For more information on using the above samples, refer to the Configure Custom Actions
section. You can edit the The DFEntConsoleCustomActions.xml file as per your needs.
Parameter Usage
<?xml version=”1.0” encoding=”UTF-8”?>
<CUSTOMDEFINEDACTIONS>
Parameter Usage
If the sub-items are defined then action for this
</SUBITEMS>
items will be ignored
<ENGLISH>USERNAME Param
Text in various languages
(ENGLISH)</ENGLISH>
<GERMAN>USERNAME Param
Text in various languages
(GERMAN)</GERMAN>
<JAPANESE>USERNAME Param
Text in various languages
(JAPANESE)</JAPANESE>
<SPANISH>USERNAME Param
Text in various languages
(SPANISH)</SPANISH>
<FRENCH>USERNAME Param
Text in various languages
(FRENCH)</FRENCH>
<CHINESE>USERNAME Param
Text in various languages
(CHINESE)</CHINESE>
</CAPTION>
</USERNAME>
</PARAMS>
<FILENAME>c:\a1com
Defines filename
mand.log</FILENAME>
<EXECUTE>c:\windows\vpn.exe
Defines command which will be executed. Here,
%%IP%% %USERNAME% %PASSWORD% parameters and/or console items can be used
%%WKSNAME%%</EXECUTE>
Console Parameters
The following console parameters can be passed to the executed application or script
through the Enterprise Console:
Parameter Usage
%%WKSNAME%% Workstation name
%%IP%% Workstation IP