Security on Xi Frame

Domains to Whitelist in Restrictive Network Environments

Sometimes users reside behind corporate networks that have strict network access policies. Connection issues can arise if certain domains are being blocked. To avoid this, administrators should reference this following list of domains associated with delivering Frame’s service and consult with the Network Configuration Requirements.

Domains Involved with Serving Frame Sessions

  • frame.nutanix.com

  • *.frame.nutanix.com

  • console.nutanix.com

  • *.console.nutanix.com

  • logs-01.loggly.com (for event logging only)

Anti-virus Software on Frame

Xi Frame images do not include anti-virus or anti-spyware tools. Administrators are responsible for installing and configuring their own choice of AV/AS tools. In most Xi Frame use cases, systems are stateless. As long as administrators are diligent about their work in the Sandbox and Utility servers, “exposed” production systems that are infected will be reverted on reboot. Frame ensures that all base images and back-end systems are scanned before deployment.

While many anti-virus software packages will work on Frame, due to the large number of anti-virus packages, and the possible complexity of configuration, interoperability is not guaranteed. Anti-virus software that prevents components of the Frame service from executing may cause loss of functionality within a Frame session, up to and including a complete inability to connect to sessions. Prior to installing an anti-virus package, a backup of your account’s Sandbox should be taken in the event that issues occur. Since most Frame customers use stateless systems, all anti-virus database updates will download each time a production instance is started. This can be avoided either by maintaining the Sandbox image (updating the Sandbox and publishing to production instances regularly) or using Persistent Desktops.

Any anti-virus software used on Xi Frame should whitelist the following directories and associated sub-directories:

  • C:\ProgramData\Frame\ – Contains libraries and utilities for Xi Frame Service, Server, and logs.

  • C:\Program Files\Frame\ – Contains Xi Frame Service and Xi Server executables which provide communication to the Frame Backplane for orchestration.

  • C:\Program Files\CloudDrive\ – Contains Cloud Drive integration libraries and executables.

If you intend to use Enterprise Profiles, please whitelist following folders and files:

Folders:
  • C:\Program Files\ProfileUnity\ and all subfolders

  • C:\Windows\Temp\ProfileUnity\

  • C:\FADIA-T\

  • C:\ProfileDiskMounts\

Files:
  • C:\Windows\System32\drivers\Cbfltfs3.sys

  • C:\Windows\System32\drivers\Cbfltfs4.sys

  • C:\Windows\System32\drivers\Cbreg.sys

  • C:\Windows\System32\drivers\cbfsfilter2017.sys

  • C:\Windows\System32\drivers\cbfsregistry2017.sys

  • C:\Windows\System32\drivers\cbregistry20.sys

Note

Please ensure that anti-virus “Tamper protection” is disabled during the publishing process.

Security and Compliance

The security and privacy of our customers’ data has always been and will continue to be a top priority. For further details on our security, data protection, and privacy programs, visit our Nutanix Trust page. There you can learn about our:

  • Security

  • Privacy, including how we control cross-border data transfers under GDPR

  • Compliance & Certifications

For our Nutanix License and Services Agreement, visit https://www.nutanix.com/legal/eula

If you have any questions, please contact support through my.nutanix.com.