background image

 

 

32 

EULA. In no event shall the immediately foregoing sentence be construed to imply, create, or require any requirement, restriction, 
or obligation of ARXCEO with respect to the Third Party Products or their licensing.  You agree with ARXCEO that you shall not use 
the Third Party Products with any equipment other than the unmodified Equipment.  No fees charged are allocated to the Third 
Party Products, which are provided free of charge.  ARXCEO is not the licensor of the Third Party Products (except for MSXPE, for 
which ARXCEO is the sublicensor), and is not the agent of the licensors thereof.  Such licensors alone remain responsible for the 
licensing, performance, accessibility, operation, and warranties (if any) of such Third Party Products.  Without limiting the 
foregoing in any manner, You shall be deemed on notice of and in agreement with at least those limitations and obligations 
regarding Third Party Products that are listed in any license text included in physical form (e.g., on paper) with the Equipment or 
displayed in connection with or linked to any configuration screen.    You agree to bear full and sole responsibility for any failure to 
comply with the license agreements provided herewith for the Third Party Products, and You agree to defend, indemnify, and hold 
harmless ARXCEO and its officers, agents, employees, directors, subcontractors, shareholders and representatives from and 
against any and all claims, losses, liabilities (including without limitation claims of induced or contributory infringement), expenses 
(including without limitation reasonable attorneys fees), and damages arising out of or related to any and all breaches of such 
license agreements and any infringement of the intellectual property rights of MS or Apache. 

6.  Support and Remediation:  ARXCEO’s standard obligations regarding the performance of the Software are set forth in 

Section 7 of this Agreement. In the event that You desire to obtain extend support services, You may purchase support services on 
a yearly basis calculated from the date of purchase (each year of coverage being a “Support Term”) by (1) notifying ARXCEO of 
your intent to purchase support services for the upcoming Support Term no later than: (A) for the first Support Term, the 
expiration of the Warranty Period, and (B) for all subsequent Support Terms, thirty (30) days prior to the end of the immediately 
preceding  
 
 
Support Term (the “Support Renewal Notice”); and (2) paying the then-current support fee as published on ARXCEO’s website.  In 
the event You fail to provide a timely Support Renewal Notice or otherwise allow a period of time after the Warranty Period to 
occur without a Support Term being in effect, then You shall not be eligible for a later Support Term until the parties mutually 
agree on the terms of a separate Maintenance and Support Agreement, which may include a requirement of an initial fee and 
separate yearly fees. Provided that You have maintained payments and made timely Support Renewal Term notices at all times, 
during any Support Term for which You have paid all fees in advance, ARXCEO shall provide to You all updates to the Software 
(within the same version number as provided on the Equipment as originally purchased) that are incorporated generally into new 
installations of that version of the Software as provided to new customers; and ARXCEO shall use reasonable commercial efforts to 
respond to calls of a technical nature for support and assistance regarding the proper operation of the unmodified Software, by 
providing telephonic instruction or advice regarding possible user error leading to problems, or regarding proposed work-arounds, 
fixes, or alternatives.  The foregoing notwithstanding, at any time following the expiration of five (5) years from the date of 
purchase of the Equipment, ARXCEO may notify You of the “retirement” of the Software, following which all subsequent Support 
Renewal Notices shall be of no force or effect, no new Support Terms shall begin, and ARXCEO shall have no obligation to provide 
the support services after the expiration of the then-current Support Term.  At any time, regardless of whether a Support Term is 
then in effect, in the event that any part or all of the Software, or any of the Third Party Products, in ARXCEO’s sole judgment 
become or are likely to become the subject of any claim of infringement of third party rights, then (i) the license granted with 
respect to any affected part of the Software may be automatically terminated upon notice of such judgment to You, (ii) You shall 
immediately cease use of the affected part of the Software and of any affected Third Party Products, and (iii) if the You remain in a 
Support Term for which the Support Fee has been paid, ARXCEO at its own election and expense will either (a) provide substitute 
software; or (b) modify the Software so that  it  no  longer  infringes  (or  if  the  issue  is  with  a  Third  Party  Product,  so  that  the 
Software uses different, non-infringing software or otherwise ceases to rely upon the infringing aspects of the Third Party 
Software) and operates to ARXCEO’s standards, or if none of the foregoing is feasible in ARXCEO’s sole discretion, then You shall 
be entitled to a refund of the applicable licensing fee from ARXCEO for the portion of the Software affected, prorated according to 
the number of months remaining in a five year period from the date of purchase of the Equipment; except that no refund will be 
provided where the infringement, likelihood of infringement, or failure to comply with standards is related to any modification of 
the Software or use of any software with the Software other than the Third Party Products provided with the Equipment.   

7. LIMITED WARRANTY. ARXCEO warrants that the Software as installed on the date of purchase will, for a period of ninety 

(90) days from that date, provide operation of or access to the material functions of the Equipment, when used as directed in the 
documentation for the Equipment.  As the exclusive remedy for any breach of warranty, ARXCEO will at its sole discretion and 
election either (1) provide substitute or replacement software for loading onto the Equipment, (2) repair the Software or instruct 
operational work-arounds to minimize the impact of any error while retaining major functionality of the Software; (3) instruct 
return of the Equipment and Software and refund the purchase price upon receipt of the same; or (4) treat the failure as a failure 
of hardware and respond under any maintenance and support contractual terms related to the Equipment, or under any warranty 
applicable to the Equipment.  Without limiting such other remedies as may be available to ARXCEO (including without limitation 
remedies in the nature of breach of contract, infringement, or other legal theory), the warranty is void in the event of any 
modification of the Equipment or Software or the use of the Software on any hardware other than the Equipment. EXCEPT AS 
EXPRESSLY STATED IN THIS SECTION, THE SOFTWARE IS PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER 
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A 
PARTICULAR PURPOSE.  EXCEPT AS EXPRESSLY STATED IN THIS SECTION, ARXCEO HEREBY EXPRESSLY DISCLAIMS, TO THE 
MAXIMUM EXTENT PERMISSIBLE BY LAW, ALL WARRANTIES, WHETHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO 
IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. WITHOUT LIMITING THE DISCLAIMER 
ABOVE, ARXCEO DOES NOT WARRANT THAT THE SOFTWARE OR FUNCTIONS OF THE SOFTWARE WILL MEET YOUR 
REQUIREMENTS OR THAT THE OPERATION OF THE PROGRAM WILL BE UNINTERRUPTED OR ERROR FREE, THAT DATA OUTPUT 
WILL BE WITHOUT ERROR, OR THAT PROGRAMS DEFECTS WILL BE CORRECTED.  

8.  LIMITATION OF LIABILITY. ARXCEO’s entire liability in connection with the Software is strictly limited to, and in no event 

shall exceed, the amount of payment made by you to ARXCEO for the specific Equipment on which any Software in issue is 
installed,  as  evidenced  by  a  copy  of  your  purchase  receipt.  IN  NO  EVENT  WILL  ARXCEO  OR  ITS  VENDORS  BE  LIABLE  FOR  ANY 
DIRECT, CONSEQUENTIAL, PUNITIVE OR INCIDENTAL DAMAGES, OR ANY DAMAGES, HOWEVER CATEGORIZED, FOR LOSS OF 

Summary of Contents for ALLY IP1000

Page 1: ...User Guide...

Page 2: ...ceo logo are trademarks or registered trademarks of Arxceo Corporation Microsoft and Windows Embedded XP are registered trademarks of Microsoft Corporation Other brands trademarks or trade names may b...

Page 3: ...000 Back Panel 6 Management 7 Command Line Management 8 Confirmation 8 Intrusion Protection Information 10 Reviewing Intrusion Messages in the Event Log 12 Appendix A 13 Appendix B 18 Appendix C 25 Cu...

Page 4: ...from infected internal systems can be provided by deploying Ally products at common gateways or network traffic intersections In the Perimeter Protection position there are only a few steps to perfor...

Page 5: ...s case you will need to change the software Network Adapter Configuration to match this physical setup by using either the Ally Management Console or the command line interface To make certain this fe...

Page 6: ...0 introduces a potential point of attack The Ally IP1000 Inside and Outside Adapters do not use an IP or MAC address This unique approach helps protect the Ally IP1000 and your network from attacks Ho...

Page 7: ...ator Password arxceo 4 The first time the Ally Management Console is accessed you will be required to accept the End User License Agreement EULA If you do not accept the terms of the EULA the product...

Page 8: ...al console unattended logout of the system by entering the logout command in the command window This will password protect the console Confirmation The next step to Plug and Protect is to ensure no kn...

Page 9: ...te blacklists and whitelists for both the Outside and Inside adapters Arxceo recommends performing the following three steps as a component of your scheduled systems security maintenance 1 Review Blac...

Page 10: ...ine that you are blacklisting on SYN requests rather than ACK responses IP Fragments Due to physical differences between various networking hardware IP packets may be broken into various fragments whe...

Page 11: ...tion oriented sessions such as HTTP and TCP IP the Ally appliance prevents any connection into the network unless the original source IP address remains unchanged throughout the session For example on...

Page 12: ...e most recent 100 event log messages Additionally the Ally IP1000 event log messages can be viewed on the local console using the Windows Event Viewer To access the Windows Event Viewer 1 At the Ally...

Page 13: ...dapters Device ALLY has been started Network adapter Network Adapter Number is assigned to handle inside network traffic Network adapter Network Adapter Number is assigned to handle outside network tr...

Page 14: ...from the same IP address in Outside Scan Timeout Number seconds will cause that IP address to be placed on the outside adapter s blacklist 16 Configuration Blacklist Time Period An IP address will rem...

Page 15: ...formation Reply packets are passed through without analysis or discarded 35 Configuration ICMP Address Mask Policy ICMP Address Mask Request packets are passed through without analysis or discarded 36...

Page 16: ...card Fragmented Packet A fragmented packet from IP address Source IP Address to Destination IP Address with IP id IP ID was discarded 54 Detection Discard Outbound Management An outbound connection re...

Page 17: ...ole User or User Name set the ALLY SNMP Syslog agent s configuration variable Variable Name to New Variable Value 64 Configuration Event SNMP Syslog Agent Reload The ALLY SNMP Syslog agent was directe...

Page 18: ...passed through without inspection or intervention When Pass Through Mode is enabled the other Ally IP1000 configuration parameters are ignored and NO PROTECTION is provided General Filtering Options...

Page 19: ...tering Options at Inside to Outside Address Authentication Disabled First Connection per Session All Connections First Connect per Session TCP Policy id Maximum Number of Inside to Outside Concurrent...

Page 20: ...established This setting is especially useful when the applications communicating through the Ally create multiple connections from a specific source IP address to a single destination IP address and...

Page 21: ...ed 32 bit integers 25 5 Port Scan Prevention is one of the Ally IP1000 features designed to provide anti reconnaissance protection This feature limits the number of TCP connection requests from a spec...

Page 22: ...UDP Policy Discard All Analyze Allow All Analyze Selecting Analyze activates the UDP policy parameters i e the next 4 entries in this table General Filtering Options av DNS Policy Discard All Analyze...

Page 23: ...rd All Analyze Allow All Analyze Selecting Analyze activates the ICMP policy parameters i e the next 12 entries in this table General Filtering Options ai ICMP Echo Request Policy Discard All Allow Al...

Page 24: ...card All Allow All Allow All Address Resolution Protocol ARP is the protocol that converts IP addresses to MAC addresses Typically ARP traffic should be allowed to pass through the Ally IP1000 Non IP...

Page 25: ...ration Event Detection and Information Configuration and Configuration Event messages are always written to the event log while Detection and Information messages can be optionally disabled Use the Al...

Page 26: ...on Maximum Concurrent Connections N A mmun mmuy 9 Configuration IP Fragment Policy N A mfrn mfry 10 Configuration Log Invalid TCP Flags N A mlfn mlfy 11 Configuration Log Invalid TCP Option N A mlon m...

Page 27: ...eply Policy N A 33 Configuration ICMP Information Request Policy N A 34 Configuration ICMP Information Reply Policy N A 35 Configuration ICMP Address Mask Policy N A 36 Configuration ICMP Address Mask...

Page 28: ...sy 55 Detection Discard ARP Packet la mdan mday 56 Detection Discard ICMP Packet ldi mdin mdiy 57 Detection Discard UDP Packet ldu mdun mduy 58 Detection Discard DNS Packet ldns mddn mddy 59 Configura...

Page 29: ...zed Arxceo Reseller for hardware and software support for your Ally IP1000 Additional information is available on our website at www arxceo com Further support or additional questions may be directed...

Page 30: ...f Button System Reset Button LEDs Power Hard drive activity 2 network activity System overheat Power Supply 200 Watt AC Power Supply Thermal Control with PFC Cooling 1 x 100mm blower fan in chassis Op...

Page 31: ...violation of this provision is void You may not lease rent merge time share or use the Software in the operation of any service bureau You agree not to reverse engineer decompile or disassemble the S...

Page 32: ...e no obligation to provide the support services after the expiration of the then current Support Term At any time regardless of whether a Support Term is then in effect in the event that any part or a...

Page 33: ...icts of laws The parties hereby consent to the exclusive jurisdiction of the courts residing in the State of Alabama The headings in this Agreement are inserted for convenience only and shall not be u...

Page 34: ......

Reviews: