Attachment J-04 Technical Environment.docx

DOCX document 44 KB Posted

Attached to
U. S. Senate Information Technology Support Contract (ITSC) V Federal contract opportunity
Solicitation number
2025-R-001
Issued by
United States Senate

About this file

This is a technical environment document (Attachment J-04) that details the U.S. Senate's IT infrastructure. The Senate's network operates on Windows Server 2012 R2 through 2022, with Exchange Server 2016 for messaging, supporting approximately 140 separate entities through the Senate Messaging and Authentication Services (SMAS). The environment includes a single Active Directory Forest with geographically dispersed redundant components for disaster recovery.

The technical infrastructure encompasses a three-tiered campus network architecture with core, distribution, and access layers built on Cisco Systems hardware, including 10Gbps connectivity and wireless coverage using 802.11 A/G/N/AC/AX protocols. The Senate maintains two data centers (Limestone and Shield) and supports approximately 440+ state offices through a wide-area network using commercial broadband services. Key systems include Virtual Machine Infrastructure (VMI), Remote Data Replication (RDR) for disaster recovery, enterprise messaging through Microsoft Exchange, and secure remote access via SSL-based VPN with DUO multi-factor authentication.

View the file

Other files for this federal contract opportunity

Other files attached to U. S. Senate Information Technology Support Contract (ITSC) V, newest first.
File Type Posted
SAA Form 30 - Solicitation 2025-R-001 Amendment 005.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V Amendment 005.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Redlined) Amendment 005.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V Amendment 004 (Redlined).pdf PDF
Solicitation 2025-R-001 Amendment 004.pdf PDF
Solicitation 2025-R-001 Amendment 004.pdf PDF
Attachment J-02 US Senate Office Locations (v2).xlsx XLSX spreadsheet
Attachment J-05 Service Level Agreement with Incentives and Penalties (v2).docx DOCX document
2025-R-001 (RFP) Information Technology Support Contract V Amendment 004 .pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V Amendment 004 (Redlined).pdf PDF
Appendix A-2 Representative Hardware List (v2).docx DOCX document
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 003 - Redline Version 4.1.2025).docx DOCX document
Solicitation 2025-R-001 Amendment 003.pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V - Amendment 003 (4.1.2025).pdf PDF
Attachment J-14 Specifications for the Help Desk and Other Work Spaces (Revised 3.14.25).pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 002 - Redline Version 3.14.2025).docx DOCX document
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 002 3.14.2025).pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 001 2.14.2025).pdf PDF
2025-R-001 (RFP) Information Technology Support Contract V (Amendment 001 Redline Version 2.14.2025).docx DOCX document
Appendix A-1 - Past Performance Questionnaire - ITSC V (RFP).pdf PDF
Appendix A-2 Representative Hardware List.docx DOCX document
Attachment J-08 - Senate Standard Hardware Products.pdf PDF
Attachment J-12 Acknowledgement of Receipt AOR Form.pdf PDF
Attachment J-19 Glossary.docx DOCX document
Attachment J-17 Help Desk Statistics.xlsx XLSX spreadsheet
2025-R-001 (RFP) Information Technology Support Contract V (2.10.2025).pdf PDF
Attachment J-10 U.S. Sergeant at Arms Standard Operating Procedures (SOPS) for Cybersecurity.pdf PDF
Attachment J-14 Specifications for the Help Desk and Other Work Spaces.pdf PDF
Attachment J-20 Section 208 Compliance Certificate.pdf PDF
Attachment J-13 Record of Equipment Transfer.pdf PDF
Attachment J-06 Service Level Agreement Ticket Review Process.docx DOCX document
Attachment J-09 Office Profile Data Points.docx DOCX document
Attachment J-01 Supported Washington DC Locations.docx DOCX document
Attachment J-18 IT System Consultants.docx DOCX document
Attachment J-07 Senate Standard Software Products.pdf PDF
Attachment J-02 US Senate Office Locations.xlsx XLSX spreadsheet
Attachment J-03 Inventory of Installed Hardware.pdf PDF
Attachment J-11 Installation Instructions.pdf PDF
Attachment J-05 Service Level Agreement with Incentives and Penalties.docx DOCX document
Attachment J-15 Off-Site vendor procedures.docx DOCX document
Attachment J-16 - Post-Election Office Moves.docx DOCX document
Show all 41

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Section J - Attachment J-04 Technical Environment

Senate Technical Environment

1. Network Operating System and Messaging The Senate’s standard Network Operating Systems are Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, and Windows Server 2022 and the standard messaging platform is Exchange Server 2016. The environment is known as Senate Messaging and Authentication Services (SMAS). The design consists of a single Active Directory Forest.

The Senate environment consists of approximately 140 separate entities that are comprised of Member offices, Committees, Leadership offices, Officers of the Senate, and support organizations.

SMAS provides authentication, messaging, cloud and mobility services for all offices. Resources for offices are provided in a single Active Directory domain, separated by organizational units. All Active Directory domain controllers, Exchange servers and other integrated services (e.g. AirWatch, DNS, etc.) physically reside in central locations and are administered by the SAA. However, rights to administer office specific resources (i.e. user accounts, mailboxes, and computers accounts) are delegated to individual office Systems Administrators. This also allows administration of all office-maintained resources, i.e. user accounts, member servers, workstations, and printers.

For disaster recovery and continuity of operations purposes, all SMAS systems have redundant components at geographically disparate locations.

2. Architecture Design and System Updates SAA technical staff designs, tests and documents all standards for the environment. This includes developing configuration standards for all Active Directory and Exchange systems as well as other integrated services.

Updates and upgrades for SMAS systems are identified, evaluated, tested, and documented by SAA technical staff.

There are three methods for disseminating updates and upgrades. Critical Microsoft updates are provided to all systems on a routine basis leveraging Microsoft Windows Server Update Services. Critical non-Microsoft updates are deployed using the Senate Systems Management Service (SMS), a cross-platform solution built on Microsoft System Center Configuration Manager (for Windows systems) and HEAT LANrev Client Management. Additional software and installation procedures are distributed for deployment of all other updates and upgrades.

For centrally located SMAS systems, the SAA deploys updates and upgrades during scheduled maintenance windows. Senate offices determine the schedule for deploying updates to office-maintained servers.

3. Member Servers The SAA certifies Operating Systems, OS service packs, OS patches, and applications for member servers to ensure compatibility in the Senate environment. The SAA makes recommendations to Senate offices based on the certification process. It is recommended that OS Service Packs and patches be applied proactively once they have been certified by the SAA. Member servers can be configured to utilize the Senate Windows Software Update Service (WSUS) to automatically receive patches and service packs following certification by the SAA for use in the Senate environment. In some cases, the SAA will provide guidelines detailing the steps necessary to effectively configure an application, patch, or service pack to operate properly in the Senate environment.

Excluding SMAS infrastructure servers, there are several standard server types available to most Senate offices. These include physical and virtual file servers, physical and virtual SharePoint servers, physical and virtual web servers, Constituent Services System (CSS) servers, and Remote Data Replication (RDR) servers.

Virtual Machine Infrastructure (VMI) Member servers that reside in the Virtual Machine Infrastructure are managed by Office System Administrators; however, the VMI and related activities (non-OS) are managed by the SAA. Any activities or changes to infrastructure in SAA managed areas will be communicated to Offices and the Help Desk. The SAA will also communicate best practices which relate directly to the VMI to Offices for implementation in a timely manner, this may differ from recommendations provided for physical servers.

CSS servers are primarily located in DC, in either the Member’s Washington, DC office, the PCF or the ACF. Many offices also have a second CSS server located in their primary state office. In those offices, the CSS application is configured to replicate data between the two CSS servers, thereby providing the Member with a CSS COOP solution, while also providing a local CSS server for the users in the primary state office.

4. Remote Data Replication (RDR) The RDR solution leverages asynchronous data replication technology to transmit data to an alternate location for disaster recovery while efficiently utilizing the available bandwidth. This solution has several key functions including data replication (flat files, database files, and other open files), DNS name failover, and application failover. The solution can be configured simply to replicate data, which can be made available manually in case of a COOP event. In addition, it is also possible to set up DNS name failover for any server utilizing the solution so that another server can assume the identity and role of that server. Further, the secondary server can be configured to assume the identity and also failover the applications running on the Capitol Hill office server.

5. Enterprise Messaging

5.1 Senate Internal E-Mail

The Senate is currently using Microsoft’s product line as the primary electronic messaging platform for all customer offices. Microsoft Windows Server 2016, Exchange Server 2016 and Active Directory are configured to provide services for each Senate office. Outlook is the supported e-mail client for Windows and Mac computers.

5.2 Internet E-Mail

Both inbound and outbound Internet mail is processed through Proofpoint appliances and Message Systems appliances running Proofpoint and Message Systems software located in Limestone and Shield. Internet SMTP mail addressed to Senate Offices is scanned for viruses and given a spam score, then routed to mailboxes on the Senate Exchange architecture

5.3 Web Form Based E-Mail (structured)

Most Senate offices have placed input forms on their external Web sites for constituents to correspond with that Senate office. These Web forms generate fully structured (tagged) SMTP mail messages that are routed directly to current applications that can accept SMTP mail.

5.4 Constituent Services Systems (CSS)

Current CSS applications accept SMTP mail directly; primarily structured (tagged) email generated through a webform on the Senate office’s website, and sometimes also raw email sent directly to a published email address. All outbound CSS generated email is in the SMTP format and is routed through dedicated MTAs.

6. Campus Infrastructure The Senate’s campus network is a three-tiered architecture, consisting of a core, distribution, and access layer. The core layer is a purely routed environment built upon redundant Cisco Systems Catalyst 6800 series product and interconnects the various distribution blocks using 10Gbps. The distribution blocks are divided to support each Senate building and interface the access layer with the core layer. Each distribution block consists of 2 Cisco Catalyst 6800 switch/routers and interconnects with the core layer via dual 10Gbps fiber-optic links. The Senate maintains two data centers called Limestone and Shield. The data centers use multiple distribution blocks comprised of Cisco Nexus 7700 devices to support Senate shared services and access to public and wide-area resources. These data center distribution blocks connect to the internal core network in a similar, redundant fashion as the Senate buildings. The Limestone and Shield data center facilities are connected using multiple 10Gbps links over an optical network maintained by SAA Network staff and multiple 10Gbps VPLS links. Finally, the Senate network supports two other remote locations via either the WAN or directly connected dark fiber, those being the Senate Post Office and the Printing, Graphics and Direct Mail (PGDM) facility.

The access layer of the network provides direct support to the Senate office LANs. Each Senate office, consisting of Senators and Committees, is supported by a logically and physically separate network. The access layer consists primarily of Cisco Catalyst 4500 series and Catalyst 9200 series products. The access layer is a purely Ethernet switching environment, providing 10/100/1000Mbps Ethernet connectivity to LAN clients and servers. Each office is divided into a separate virtual LAN (VLAN) and utilizes the distribution layer as an aggregation point for the VLAN as well as routing functions to interconnect with the internal core network. Access layer switches are connected to distribution blocks via redundant gigabit fiber links.

The Senate’s campus network also consists of a complete wireless infrastructure that provides coverage for all of the Senate office buildings, much of the Senate side of the U.S. Capitol and Capitol Visitor Center (by demand), the primary and alternate data centers, and offsite locations such as the Senate Post Office and PGDM facilities. The wireless coverage uses the 802.11 A/G/N/AC/AX protocols and authentication is managed by a combination of Cisco ISE and RSA authentication servers.

7. Wide-Area Network (WAN) Senate state office locations are supported by a wide-area network leveraging commercially available broadband Internet services. There are approximately 440+ state offices and all traffic passes through the Senate campus networks when communicating with shared services, Internet resources, or other state offices.

The internal state office network is supported by a Cisco 4000 series router and a Catalyst 9200 series Ethernet switch. The Catalyst 9200 platform supports 10/100/1000Mbps connections to the endpoint devices. In addition, offices are offered the option of purchasing wireless access points similar to the campus access points that support access to the network using 802.11 A/G/N/AC/AX.

8. Remote Communication The Senate supports high-speed broadband users in concert with secured SSL based VPN sessions. Initial network-based user authentication is accomplished via the use of DUO token devices which provide highly multi factor authentication.

File details come from the government source that posted it. Updated .