Network Communication between the Deep Freeze Enterprise Console and computers with Deep Freeze installed can use two different modes: LAN Mode or LAN/WAN Mode. • LAN – Select LAN to configure Deep Freeze to communicate within a Local Area Network (LAN). LAN mode is a self-configuring mode that requires only a port number. The default port is 7725. The port number can be changed if it is in conflict with other programs on the LAN. In LAN mode, the Deep Freeze target computer and the Enterprise Console find each other through UDP broadcasts. These broadcasts only occur when computer or the Enterprise Console is started, ensuring that there is little network traffic associated with target computer and Console communication. • LAN/WAN – Select LAN/WAN to configure Deep Freeze to communicate in both a LAN and a WAN (wide area network). LAN/WAN can be used in either a LAN or WAN environment and over the Internet. This mode uses an IP address or the computer name, along with a port number, to allow communication between the Enterprise Console and the managed computers. The following two methods are available to identify the Console: • Specify the Console IP, which must be static • Specify the Console Name, in which case the IP can be dynamic (if valid DNS name resolution is available as part of the domain infrastructure). When the Enterprise Console is behind a firewall or a NAT (network address translation) router, the firewall or router must be configured to allow traffic to pass through to the Enterprise Console. Depending on the firewall or router, computers may need to be configured with the IP address of the firewall so that traffic can be forwarded. Deep Freeze automatically configures the required exceptions in the Windows Firewall. It is not required to configure the Windows Firewall manually. For more information on configuring and using Deep Freeze in a specific network environment, refer to Appendix B or contact Technical Support. If a port number other than the default of 7725 (registered to Deep Freeze) is used, care should be taken to ensure that there are no conflicts with applications already running on the network. Well-known ports (0–1023) should be avoided and any Registered Ports (1024–49151) should be checked for conflicts before deployment. It is recommended to use ports in the unallocated range above 49152. Using Port Segmentation, you can isolate a lab or building by port number by configuring the Port Number on the workstations and in the Deep Freeze Enterprise Console. Using this method, you can provide management functions for a specific set of workstations and not your entire organization. UDP and TCP port exceptions for these ports will be required. For more information, refer to Example 3 – Multiple Ports, Console Accessed Remotely. A complete listing of the ports assigned to various applications can be found on the Internet Assigned Numbers Authority web site at http://www.iana.org/assignments/port-numbers.