Educause Security Discussion mailing list archives

Re: Deepfreeze on vm's?


From: Brandon Payne <brandon.j.payne () SVCC EDU>
Date: Thu, 8 Dec 2011 11:04:26 -0600

I'd like to jumpstart my thread again now the vendor has been removed. If
anyone else has a similar scenario in production, please share your
experiences. Thanks!

-Brandon



On Wed, Dec 7, 2011 at 2:14 PM, Brandon Payne <payneb () svcc edu> wrote:

Yes, I understand its as easy as deleting the problematic VM and a few
minutes later the replica master starts provisioning a new VM; Getting it
back up and running in a matter of minutes.

However, Student/Faculty users will likely be Local Administrators
(allowing the use of installing student book resource cd's, old legacy
software that requires admin to run, etc.), therefore the use of Deepfreeze
has helped tremendously. The idea of having Deepfreeze on the VM and having
the VM reboot on logoff gives a calming feeling.

--
Brandon Payne
Technical Support Specialist
Information Services
Sauk Valley Community College


On Tue, Dec 6, 2011 at 5:14 PM, SCHALIP, MICHAEL <mschalip () cnm edu> wrote:

Agreed.......or, couldn't you just reprovision a new image on the fly?

-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv [mailto:
SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Mike Lococo
Sent: Tuesday, December 06, 2011 4:08 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Deepfreeze on vm's?

On 12/06/2011 06:00 PM, Brandon Payne wrote:
We are looking into VDI for all our computer labs. VMware View to be
exact with WYSE P20 Zero Clients. Roughly about 300 or more vm's for
all the labs.

From a virtual standpoint - do you see the need for Faronics
Deepfreeze on all computer lab vm's? Currently we are using Deepfreeze
on our desktops in all labs and has worked out great. For this
situation, I'm not interested in the security implications of why
Deepfreeze is bad, just if its recommended in a virtual environment.

What are you doing in situations if a user profile gets hosed up with
malware in this vm enviroment?

Why wouldn't you use the native snapshotting facilities that VMWare
provides?  The main feature that deepfreeze delivers in the physical world
is snapshotting and rollback, and that's a feature that VMWare delivers out
of the box.

Cheers,
Mike Lococo

--
This message has been scanned for viruses and dangerous content by
MailScanner, and is believed to be clean.


--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.




Current thread: