J-30_-_EITSS_Current_Environment_Summary-FINAL.pdf
PDF 730 KB Posted
- Attached to
- Enterprise IT Shared Services (EITSS) Federal contract opportunity
- Solicitation number
- 693JK419R500005
About this file
This document provides an overview of the current information technology environment and requirements for the Department of Transportation's Enterprise Information Technology Shared Services contract opportunity. The Department of Transportation Office of the Chief Information Officer is seeking proposals for a contractor to provide infrastructure and standard operations support for the DOT Common Operating Environment, which includes services such as a 24/7 service desk, desktop support, hosting, storage, networking, software deployment and patching support. Proposals are due in person on January 8, 2019 between 10:00 am and 3:00 pm Eastern Time at the DOT headquarters in Washington, D.C. Offerors should submit 20 thumb drives containing their technical and business volume proposals within a sealed envelope with company and point of contact information. The requirement is set aside for small businesses with a NAICS code of 541513 and size standard of $27.5M, requiring any small business prime to perform 51% of the work.
J-30 - EITSS Current_Environment_Summary-FINAL
View the file
Other files for this federal contract opportunity
Show all 50
Enterprise IT Shared Services (EITSS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. Department of Transportation
Office of the Chief Information Office
Enterprise Information Technology Shared Services (EITSS)
Attachment: OCIO Current Environment Description
August 2018
DISCLAIMER: This document describes the current DOT Common Operating Environment managed by the CIO. It is provided as a point in time reference to offerors for background, context, planning, and pricing purposes for the EITSS acquisitions. The awardee shall support all current and future government-furnished technology, tools, systems, equipment, and processes. This document shall not in any way limit, restrict, or otherwise imply awardee support shall be limited to only the environment described in this document.
INTRODUCTION
The Information Technology Shared Services (OCIO) organization reports to the Office of the Chief Information Officer (OCIO), which is located under the DOT Office of the
Secretary (OST).
OCIO provides expert guidance and knowledgeable professionals to gather requirements, design and develop plans, and implement and manage customer information technology
(IT) needs.
This support includes the full range of services provided to the customer base including managed Service Desk support, Desktop support, Seat and Infrastructure Management, Application Hosting, and Email and User Collaboration tools. These services are designed to support and deliver the optimum IT experience to its associated DOT Operating
Administrations (OAs).
OCIO provides service to most OAs across the Department. The intent is that in the future
OCIO will provide all services to all OAs except for Federal Aviation Administration
(FAA). The OCIO services (high level) and the DOT OAs are listed below.
OCIO Services:
• 24/7 Service Desk Support
• Desktop Support Services
• Mobile Device Services
• Telephony Services
• Video Services
• Microsoft O365 Email & Messaging Services
• 24/7 Infrastructure Operations
• Hosting as a Service
• Compute as a Service
• Network as a Service
• Telecommunications (voice/data)
• Storage & Backup as a Service
• Security as a Service (CISO/OCIO)
• Platform as a Service
• Software as a Service
• Data Center Operations and DR
• Enterprise Monitoring Services
• Hybrid On Premise/Cloud Environment
Department of Transportation Operating Administrations
OA Acronym OA Name
FHWA Federal Highway Administration
FMCSA Federal Motor Carrier Safety Administration
FRA Federal Railroad Administration
FTA Federal Transit Administration
MARAD Maritime Administration
NHTSA National Highway Traffic Safety Administration
OST-R Office of Research & Technology
OIG Office of the Inspector General
OST Office of the Secretary
PHMSA Pipelines & Hazardous Materials Safety Administration
SLSDC Saint Lawrence Seaway Development Corporation
TECHNICAL BACKGROUND
SERVICE DESK CURRENT ENVIRONMENT
The OCIO Service Desk hours of operation in the future acquisition will be 24x7, with core hours of 7:00am to 7:00pm, Monday through Friday. Currently, the Service Desk uses a contractor- provided Remedy incident management tool, but OCIO is exploring other service management tools in order to provide better service to DOT’s approximately 12,500 users. Service Desk call volume currently averages 13,500 incoming requests per month.
DESKSIDE SUPPORT CURRENT ENVIRONMENT
OCIO deskside and technical support is provided to over 250 locations nationwide, with on-site technicians at roughly 15 field site locations. Most sites do not have dedicated on-site support but are supported remotely and technicians are dispatched if necessary. OCIO anticipates that they will provide desktop and infrastructure support to all field sites with the ability to send a direct dispatch technician to all sites as necessary.
There are approximately 16,000 OCIO-supported end user devices attached to the DOT network. (This includes workstations and mobile devices.) The majority of end user desktops are Windows 7 and Windows 10 installed primarily on the following models.
Other models do exist in the environment but these are the most prevalent models.
• Dell Latitude E7470
• Dell Latitude E6440
• Dell Latitude E6430
• Dell Latitude E7450
• Dell OptiPlex 9020
• Dell Latitude E7440
• Dell Latitude E6540
• Dell Latitude 7480
• Dell Latitude E5570
• Dell Latitude E6420
• Dell OptiPlex 7040
• Dell OptiPlex 7010
• Dell Latitude E6330
• Microsoft Surface Pro 4
• Microsoft Surface Pro 3
For Mobile devices, OCIO is phasing out BlackBerry smartphones and transitioning to iPhones. The current number of OCIO-provided and managed mobile devices is over 4,000.
OCIO has migrated almost all devices to Microsoft Intune. Intune migration is nearly completed and is expected to be completed by the end of 2018.
IMAGES CURRENT ENVIRONMENT
OCIO currently manages a core image for end user software, spread across multiple hardware platforms. The primary operating system across all hardware platforms is
Microsoft Windows and Microsoft Office with O365.
The OCIO baseline image consists of approximately 20 desktop standard applications, which includes but is not limited to the following:
• Active Identity Client
• Adobe Acrobat Reader
• Adobe Flash Player
• Adobe Shockwave
• Beyond Trust Privilege Manager Client
• Enhanced Mitigation Experience Toolkit
• IBM Endpoint Manager Client
• Internet Explorer
• Google Chrome
• Java
• Microsoft Office 365 Pro Plus
• Microsoft Silver Light
• Microsoft Skype for Business
• Secure Zip
• Symantec Endpoint Protection
• VMware Horizon View
• SCCM Client
• Cisco Any Connect
• Cisco NAC Agent
• McAfee Drive Encryption
Tools used by OCIO for Image Development and Management include Microsoft
Deployment Toolkit (MDT) and Microsoft System Center Configuration Manager. The
DOT standard image is updated quarterly.
USER COMMUNICATIONS AND COLLABORATION CURRENT ENVIRONMENT
DOT communication and collaboration services include email through Microsoft O365, Instant Messaging & Presence through Microsoft Skype for Business, and document collaboration through shared Windows file systems and SharePoint. These services are provided to all DOT users and locations including those in the field. Other communication and collaboration services are available to DOT but are not managed by OCIO at this time, but OCIO does plan to expand its Communication and Collaboration services in the near future to include video conferencing and other document sharing services.
EMAIL AND COLLABORATION TECHNOLOGY BACKEND
OCIO has deployed a cloud based Email solution to all DOT customers, currently hosted in a hybrid Microsoft Government Community Cloud (GCC), and implemented across the various
DOT Data Centers. There are also currently some on-premise DOT infrastructure email system components requiring support as well. These include Iron Ports, F5 Load
Balancers/Routers, SAN Storage, Domain Controllers and Mobile Device management service.
Mailboxes Support Metrics
85 Mailboxes on premise
3490 Shared mailboxes in O365
1243 Resource mailboxes in O365
12944 User mailboxes in O365
Category Email and Collaboration Applications, Devices, and/or
Services
Email Microsoft Office 365 – Exchange Hybrid Environment;
Microsoft Outlook (client software).
Mobile Devices * Currently supported mobile devices include Blackberry, Apple iPhone and iPad/iOS, Windows Phones and Tablets, etc.
Special Requirements for the Visually
Impaired and
Physically
Handicapped
JAWS, Magic, ZoomText, Dragon NaturallySpeaking.
eDiscovery, Legal Hold and Litigation solutions
Microsoft Office 365 with Legal Hold
Mobile Device
Management (MDM) tools
Microsoft Intune
Mailbox attributes Shared mailboxes, delegation for mailboxes, calendars, meeting requests/acceptance/rejection, “send as” permissions, encryption, conferencing rooms, shared resources, Online Archive mailboxes.
Voice Service Voice telephony environment is provided by services using
Genband technology.
Other features Global Address Listing (GAL), Iron Port email filtering
Other Integration with custom tools, Whitelist/blacklist filtering, Data Loss Prevention controls, encryption gateway tools, safe and blocked senders, custom routing of outbound mail, Transport Layer Security (TLS), backup and recovery tools, email archive.
* NOTE: This table includes Government Furnished Equipment (GFE) and Bring Your
Own Device (BYOD). It is important to note that the use of BYOD is only allowed for a select group of individuals.
NETWORK CURRENT ENVIRONMENT
OCIO is the Department’s shared services enterprise backbone built to deliver an enterprise-wide approach to IT infrastructure and common administrative systems that enable innovation and collaboration throughout the Department. OCIO shared services WAN infrastructure is comprised of Cisco routers running Border Gateway Protocol (BGP) that interconnect via MTIPS private WAN Cloud, AT&T Netbond and Microsoft Express Route for Cloud services connectivity. Connectivity is provided through the DOT HQ building in
Washington, DC to routers, switches and firewalls for the DOT modes (FHWA, FMCSA, OST, OST-R, OIG, FTA, FRA, PHMSA, NHTSA, MARAD). OCIO is solely responsible for enterprise shared services, the Department’s transit backbone and network infrastructure for each mode
Headquarters and field location.
OCIO achieves the following primary objectives for the Department:
• Establishes high speed, high availability enterprise network with direct peering's from:
o Office of the Secretary, Information Technology Infrastructure and
Operations (OS/OCIO) o Federal Highway Administration (FHWA) o Federal Motor Carrier Safety Administration (FMCSA) o Office of the Inspector General (OIG) o Federal Transit Administration (FTA) o Federal Rail Administration (FRA) o Pipeline and Hazardous Materials Safety Administration (PHMSA) o National Highway Traffic Safety Administration NHTSA o MARAD (Maritime Administration) o Saint Lawrence Seaway Development Corporation (SLSDC)
• Provides a unified network that supports DOT enterprise applications and unified communications
OCIO enterprise shared services infrastructure is comprised of Cisco, Checkpoint and F5 routers, switches, firewalls, and other security devices, including intrusion detection systems (IDS), intrusion prevention systems (IPS), advanced threat protection (ATP), data leak protection (DLP) appliances, wireless intrusion protection services (WIPs), and vulnerability and compliance scanners. Check Point firewalls, IDS/IPS, and WAFs are employed to secure Internet-facing systems and services and other border external and internal threats and exfiltration, respectively. Overlaying the DOT network infrastructure are network applications connections. F5 load balancers, and an RSA token-based
Authentication Manager. These devices add security and resiliency to the network.
OCIO has over 200 Managed Trusted Internet Protocol Service (MTIPS) connections at 200 locations across the United States. There are over 200 routers and several firewalls. Virtual private network (VPN) servers support site and user remote connectivity. OCIO supports approximately 800 Wireless Access Points.
WIDE AREA NETWORK (WAN) / METROPOLITAN AREA NETWORK (MAN)
SUMMARY
OCIO uses the AT&T MTIPS, Multiprotocol Label Switching (MPLS) for connectivity to regional and field sites. Each regional office and remote site is connected to the AT&T
MPLS network via T1, DS3, 1-100 MB circuits. These circuits are aggregated to two aggregation points at DOT HQ points of presence (PoPs). The aggregation points currently utilize 2GB MTIPS circuits for internet connectivity. BGP is deployed within the AT&T PIP
MPLS cloud. Each regional office utilizes a branch router, a Cisco aggregation switch, and access-layer switches.
STORAGE CURRENT ENVIRONMENT
OCIO manages and maintains a multi-vendor Storage and Backup infrastructure which consist of hardware and software from Dell/EMC, NetApp, Microsoft and Veritas. The
OCIO storage team currently manages and protects over 2 Petabytes of data using various protocols including Fibre Channel (FC), Fibre Channel Over Ethernet (FCOE), Internet Small
Computer Systems Interface (iSCSI) and 10 Gigabyte Ethernet (10Gbe). The Storage network fabric consist of Brocade and Nexus 5K Switches. Several replication and DR technologies are currently in pilot phase.
These include EMC RecoverPoint, Azure Site Recovery (ASR), and VMWare Site Recovery
Manager (SRM). The OCIO Storage team also manages the backup environment which includes Netbackup and other EMC Backup technologies. The OCIO storage team has 2
PB of allocated storage and backs this data up weekly.
Backup Technology Number of Clients (Approximate)
NetBackup 650
Azure Backup 100
Avamar 150
Azure DPM 75
Azure MARS 25
HOSTING CURRENT ENVIRONMENT
The current OCIO hosting environment is a virtual and physical hosting environment for many applications and infrastructure services. The primary application hosting facility is located in the Washington, DC Metropolitan area with field sites spread out across the
United States and a Disaster Recovery (DR) site in the South-West region of the United
States. The DR site currently provides primary DR instances for a number applications. This
COE environment is currently covered by a FISMA High Authority to Operate (ATO).
The HQ and DR hosting environments utilizes VMware ESXi clusters, in addition to some physical servers for production, non-production and DR environments. The field office hosting environments utilizes Hyper-V on physical hosts for file, print, authentication, DNS, and other local field services. Over 70% of all OCIO servers are virtual machines.
OCIO hosting service offerings include the following:
- Server Platform as a Service (PaaS) – All servers under PaaS are hosted and managed by OCIO. The PaaS offering includes the following support:
o Customer support Monday through Friday 7AM to 7PM with after-hour notifications.
o Structured and mature change management process to control server changes and minimize the risk of outages.
o Disaster recovery planning, testing and preparedness for mission critical servers.
o Problem diagnosis/resolution, including third-party vendor support calls and follow- up.
o Performance and capacity planning.
o Hardware maintenance.
o Automated security, operating system and application patching for Windows, UNIX and Linux operating systems, Microsoft Office, Exchange, SQL and other
Microsoft products.
o Anti-Virus software updates including the AV engine (client) and the virus definition o files (data). Periodic security scans on all supported servers to ensure no system o vulnerabilities have been introduced.
o Resolution of server operations problems.
o 7x24x365 performance and availability monitoring and reporting for all supported o servers.
o Advanced server monitoring is available, using automated tools to monitor and report on configuration and attribute changes; network connectivity; service availability; system logs; CPU, memory and disk space thresholds o This service may require advanced monitoring software at additional cost to the customer.
- Server Infrastructure as a Service (IaaS) – All servers under PaaS are hosted by
OCIO on OCIO hardware, but the servers are managed by the customer. The IaaS service offering includes the same features as the PaaS, but for the platform only. The customer is responsible for the management, monitoring, and all other maintenance and protections of the servers.
The server environment is split across all these service offerings.
• 75% of servers provide critical Infrastructure Support
• 20% of servers fall under the PaaS offering
• 5% of servers fall under the IaaS offering
- Database Hosting as a Service – All databases under this service offering are hosted and managed by OCIO. This is limited to Oracle and SQL databases at this time.
SOFTWARE AND PATCH DEPLOYMENT ENVIRONMENT
The current OCIO software and patch deployment environment utilizes Wise Package Studio to package updates, which are then pushed out via Microsoft System Center Configuration
Manager. Application patches and updates are released as they become available from the vendors. Windows patches are released at least once a month and roughly 5-7 updates to other applications are released on a weekly basis. The schedule for the release of these updates is managed by the Release Team, but the packages are tested and pushed by the Infrastructure
Operations team. OCIO does maintain an air gapped test lab and a pre-prod environment in addition to the production environment. The air gapped test lab network is not a one for one replica of the production environment but is used for testing some infrastructure upgrades where appropriate. Patches and updates are generally tested on a small group of production machines before being released to pilot groups and then to the full production environment.
DOT VDI OVERVIEW
The Department of Transportation (DOT) offers Virtual Desktop Infrastructure (VDI) to allow
DOT users to work remotely. This environment utilizes VMware Horizon View to provide remote desktops, and can support up to 2,000 users concurrently. Desktops are non-persistent and currently use Windows 7, but the Windows 10 image is currently in development. Most
DOT users access VDI using their home workstations, but DOT does have a small number
(under 50) of thin clients. On average telework days, the VDI environment usually has 1,200 users actively logged on. On recent peak telework days in 2018, as many as 1,600 users have been logged in concurrently.
DOT uses the following technologies to support the VDI environment:
• Liquidware Labs Profile Unity for User Profiles
• VMware Horizon View for Clients and Backend
• Cisco UCS for Compute
• Quest Foglight for Monitoring
• F5 for Load Balancing
• Microsoft App-V & VMware ThinApp Application Virtualization
Virtual Desktop Infrastructure High Level Diagram
The following applications have been virtualized and are available in VDI:
Adobe Acrobat Professional
Adobe Dreamweaver CS6
Adobe Fireworks CS6
Adobe Illustrator CS6
Adobe InDesign CS6
Adobe Photoshop CS6
AOL AIM
ArcGIS Desktop 10.2
ArcGis Desktop 10 ArcGIS Explorer
BMC Remedy (assuming Remedy client)
Bosch Crash Data Retrieval CDR v17.0 ccmMercury
Cisco Agent Desktop Citrix
Cold Fusion builder 2
Dreamweaver CS6
FileMaker Pro 15
Full Shot v8.0
Google Chrome
Google Earth GoToMeeting Hyperion 11.1.2.3
IBM SPSS Statistics 2.0
ICAM PKCS7 Signer
Internet Explorer 8
Internet Explorer 10
Inkscape
Madymo
McAfee Endpoint Encryption Manager
Microsoft Access 2003
Microsoft MapPoint 2006
Microsoft Project Pro 2010 Winscp
Microsoft SQL Report Builder 2012
Microsoft SQL Studio 2012
Microsoft SharePoint Designer 2010
Microsoft Visio 2010
MobaXterm
Movavi
Mozilla Firefox
MySQL Workbench v6.3.8
Notepad++ Total
NS5
RISPC 4
RVTools
Safari
SAS Enterprise Guide 5.1
SAS 9.3
SAS 9.4
SAS Enterprise Guide 6.1
SCCM 2007
Snagit
SQL Developer SUDAAN
Tableau Reader 8.0
Tableau Reader 8.2
TEMA Image Systems
VideoMaCH
VLC Media Player
VMware vSphere 5.5
VMware vSphere 6.0 Update 2 Client
VMware vSphere CLI 6.3
WesVAR 5.1
Microsoft Office Suite (Excel, Internet Explorer, PowerPoint, Word)
ACTIVE DIRECTORY TOPOLOGY
Storage Environment Metrics
Tier Level Model Number Purpose HQ Capacity Stennis Capacity
1 – Gold EMC VMAX/VNX-VG50 10K
(Formally Celerra)
File & Server Storage 400 TB 200 TB
2 – Silver NetApp 3240 VDI File, Server, and OS Storage 120 TB 120 TB
3 – Bronze NetApp FAS 3160 File Storage
& Field Office Backups
12 TB N/A
1 – Silver Violin 6200 VDI Virtual Desktops (SSD) 15.6 TB 15.6 TB
2 – Silver EMC VNX
(NHTSA)
File & Server Storage 350 TB N/A
2 – Silver EMC VNX
5600 (OST)
File & Server Storage 100 TB 100 TB
3 – Bronze NetApp
FAS2554
(OST-R
Storage)
Server & Application Storage 24 TB N/A
2 – Silver EMC VNX
5600 (S83)
File & Server Storage 211 TB
(Pending configuration)
211 TB
(Pending configuratio
n) 3 – Bronze NetApp
AV400 (S83)
VDI File, Server, and OS Storage 100 TB 100 TB
2 – Silver EMC VNXe
3200 (FTA)
File & Server Storage 85 TB
(Pending configuration)
85 TB
(Pending configuratio
n) 3 – Bronze NetApp
AV400
(OST)
VDI File, Server, and OS Storage N/A 100 TB
3 – Bronze NetApp FAS
3240 (VDI)
VDI Storage 122 TB 126TB
File details come from the government source that posted it. Updated .