Exhibit J DHA B2B Gateway Questionnaire -- 26 Feb 2020.docx

DOCX document 1 MB Posted

Attached to
Clinical Reference Laboratory Testing Services Federal contract opportunity
Solicitation number
W81K04-20-R-0017-0001
Issued by
Department of the Army Medical Command

About this file

This document is a questionnaire template for commercial partners to connect their systems to the Defense Health Agency's Military Health System network via a virtual private network. It includes appendices requesting details on software and hardware requirements, system performance needs, and network diagrams. Appendix F requires a table listing proposed applications with descriptions, protocols, port numbers, IP addresses and site locations. It seeks approval signatures from various information system security managers and project managers.

The related federal contract opportunity posting is for clinical reference laboratory testing services for the Department of the Army Medical Command. It provides no further specification of required products or services.

View the file

Other files for this federal contract opportunity

Other files attached to Clinical Reference Laboratory Testing Services, newest first.
File Type Posted
Attachment 11 Workload by MTF FY2018 -- 26 Feb 2020.xlsx XLSX spreadsheet
Questions and Answers - 27FEB2020 Final.pdf PDF
Exhibit B_Summary by Facility Name -- 26 Feb 2020.xlsx XLSX spreadsheet
W81K04-20-R-0017-0001 Reference Lab Amendment.pdf PDF
Exhibit C_Schedule of Required Tests -- 26 Feb 2020.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Defense Health Agency

DEFENSE HEALTH AGENCY

BUSINESS 2 BUSINESS (B2B) GATEWAY QUESTIONNAIRE

PHASE II – [INSERT VENDOR NAME AND MTFS IF LISTED]

January 31, 2018 Version 10.3

CHANGE / REVISION RECORD

This record is maintained throughout the life of the document; each published update is recorded. A Change Package (re-issue of changed pages only) carries change bars in the page margins to identify differences from the preceding issue. Due to the scope of change that necessitates a Revision (re-issue of entire document); a Revision does not carry change bars.

DOCUMENT VERSION NUMBER
REVISION SUMMARY
DATE
Version 5.0
Updated to reflect transition from DISA to DHA
12/14/15
Version 6.0
Updated to reflect AnyConnect option
4/4/16
Version 7.0
Updated to reflect Citrix option
11/9/16
Version 8.0
Updated contact list to reflect current personnel
12/2/16
Version 9.0
Updated the TOC. Updated General Information Page. Updated the DHA staff information. Updated the Implementation Checklist. Removed the DD Form 2875 attachment and screenshot and added a Web link to access the form. Added an appendix to gather data for software and hardware requirements. Revised the B2B Requirements appendix. Added a signature line for program office’s ISSM.
8/8/17
Version 10.0
Update DoD POC information. Replace “Netscreen” with “Cisco ISR” under Network Boundary Information. Update Network Address table and Notes below table. Update Appendix I. Add Appendix K and update following Appendices’ letters.
10/26/17
Version 10.2
“eMASS #” section added in General Information table. Update B2B Mailbox email address in DoD POC table. Last Mile Information table of Appendix E updated. Appendix J &K edited.
1/23/18
Version 10.3
Updated Appendix F: Phase I/Existing Connection chart. Clarified Example row on Phase II Chart
1/31/18

Table of Contents

Introduction5
DHA Policy for Communications6
Commercial Partner POC Information9
Implementation Checklist10
Appendix A: Software and Settings/Hardware Requirements11

Appendix B: Submission of the System Authorization Access Request (SAAR)

Form 287512
Appendix C: User Performance Requirements13
User System Requirements13
Appendix D: System Performance Requirements14
System (Third Party Partner) to System (MHS) Requirements14
Appendix E: VPN Implementation Form15
Last Mile Information – WAN Access15
Network Boundary Information (not required for Citrix)15
Firewall Specifics/Proxy Servers (not required for Citrix)17
Appendix F: DHA B2B Connectivity Requirements Submission18
Appendix G: “As Is” Diagram (not required for Citrix)20
Appendix H: Last Mile Diagram (not required for Citrix)21
Appendix I: Device Package Slip (not required for Citrix)22
Appendix J: ISSM Approval (For all new connections)23
Appendix K: Site ISSM Approval24
Appendix L: Program Manager Approval25
Appendix M: Security Approval26
Appendix N: Project Manager Approval (For new connections only)27

Introduction Defense Health Agency (DHA) oversees the Military Health System (MHS) Infrastructure and Operations (I&O). DHA is chartered to design, provision, and deploy a standards based, common telecommunications infrastructure throughout the MHS.

This information paper identifies the required parameters for Commercial Business Partners to connect to an MHS Military Treatment Facility (MTF) or other Department of Defense (DoD) .mil network using a Virtual Private Network (VPN). This information sheet is intended do the following:

· Adhere to the DoD Guidelines for third party vendors

· Adhere to the policies of connectivity and device management of the third party vendor

· Meet the functional and technical requirements as designed for a given project

In prioritizing security and confidentiality of DoD system resources and networks, the gateway approach is the standard for all non-DoD resources to connect, communicate, and manage systems within the DoD. In the gateway solution, the third party affiliate will terminate at a DMZ and then be re-directed to its destination. This is the recommended long-term solution to ensure data and system resource security and confidentiality.

The following criterion depicts a Gateway solution:

· There is a single reference point for the third party affiliate to the DoD thus eliminating any back doors to the DoD

· Third party affiliate VPN device procurement resource must be identified

· Third party affiliate VPN device model must be in the product line of the DHA – MHS Standard

· The DHA VPN team maintains Configuration Management and support of the VPN device located at the Third Party Affiliate’s DMZ

· MHS traffic can be more effectively managed

· Adheres to the DoD initiative to move away from third party affiliates connecting directly to a MTF This document is to serve as a template to identify the requirements of the sponsoring organization and the third party partner to DHA. Below will be detailed information that when completed will be used for:

· Establishing necessary requirements

· Configuring the MHS B2B Gateway

· Configuring the VPN device

DHA Policy for Communications The TRICARE Systems Manual (TSM 7950.1-M) discusses the requirements necessary for Managed Care Contractors to interface with the Department of Defense (DoD):

Defense Health Agency

B2B Implementation Plan v10.3 January 2018 The information contained in this document is of a sensitive nature to the Department of Defense. The reader shall not disclose such information to any person or entity except employees and affiliates who have a need-to-know and who have been informed of the reader’s obligations under this paragraph.

General Information

Project Information

Request Type
New Connection(s)
Changes/Updates to Existing Connection(s)
Decommission Connection(s)
Connection Type: For legacy Juniper connections select “Changes/Updates..” and/or “Decommission..”
Server to Server

Allows continuous connectivity between the partner-and DHA-hosted servers. The commercial partner (vendor) will be required to procure and install a DHA-configured and tested Cisco VPN router (Cisco ISR) on its premise at all appropriate locations. The device (which will be remotely managed by DHA) will provide a controlled entry/exit point and an encrypted pathway for all communications between the commercial partner and its DHA-hosted system(s). System-to-system communications are defined as automated processes between two systems that require always-on connectivity.

Client to Server Allows the commercial partner system administrators to manage and monitor those systems for which they are responsible. Client-to-server communications are defined as any administrative function that requires administrative input (Remote Desktop, Dameware, SSH, etc).This will be an on-demand solution and will require the administrator to establish a connection for each use through a DHA provided Virtual Desktop Infrastructure (VDI) using CAC authentication.

eMASS # (DHA ID for the system with which the vendor is communicating.)

Project Name (Vendor Name to MHS Name)

Program Office

Description: What is this for?

Requested Date:

Critical Date:

DoD POC Information Please complete the following:

DoD Organization
Name
Phone
E-Mail

Government POC Sponsoring the B2B Gateway Connection

Contracting Officer/COR

ISSM

DHA B2B ISSM
Mr. Eric Wildermuth
(703) 681-1145
Eric.R.Wildermuth.civ@mail.mil
DHA B2B Project Manager
Mr. Orlando Januario Jr.
(210) 295-3599
orlandojr.januario.civ@mail.mil
DHA B2B Project Manager
Mr. Gary Waltman
(703) 681-6754
Gary.P.Waltman.civ@mail.mil
DHA B2B PM Support
Ms. Asha Jones
(571) 765-6136
asha.z.jones2.ctr@mail.mil
DHA B2B Phase 2 Support
Mr. Ronald Yoon
(516) 509-0022
ronald.i.yoon.ctr@mail.mil

DHA Engineer

DHA Other (SPAWAR)
Remote Systems Management

rsm@nsoc.health.mil

DHA Global Service Center
DHA Global Service Center Personnel
(800)-600-9332
dhagsc@mail.mil
DHA B2B Mailbox
DHA B2B Team

dha.ncr.ops-sustain.list.b2b-phase2@mail.mil

.MIL Gov.

.MIL PM Support

.MIL Firewall Engineer

.MIL System Administrator

Commercial Partner POC Information Please complete the following:

Organization
Name
Phone
E-Mail

PM

Application /System Engineer

Network Administrator

Security Manager

Network Manager

Organization
Name
Phone
E-Mail
Procedures

Help Desk Contact Information

After-Hours Support Contact Information

Organization Address:

Physical Device Location (not required for Citrix): {NOTE: Be sure to include the full address, building, room, and rack where the MHS VPN node will be deployed}

Implementation Checklist Please check the following:

Question
Yes
No
Date Complete

1. Has the software requirements for C2S connection been provided by vendor? (Appendix A)

2. Is Form 2875 completed? (See PDF file “DHAGSC_B2B_C2S (v.1.1 20171212)” sent with questionnaire)

3. Internet addresses are publicly routable for all B2B applications? (Clients need a unique address for authentication tracking.)

4. Is user performance requirement information completed?

(Appendix C)

5. Is system performance requirement information completed? (Appendix D)

6. Has the VPN Implementation Form been completed? (Appendix E)

7. Has Connectivity Requirements Sheet been submitted? (Appendix F)

8. Has “As Is” Network Diagram been provided? (Appendix G - Attachment)

9. Has VPN Last Mile Diagram (Appendix H) been discussed and concurred by both sides?

10. Is VPN device procured? (Appendix A, S2S connections only)

11. Has the VPN device been configured and STIGed by DHA?

(Please send VPN device to the contact and address below for configuration:

Shaun Pillé KSH Solutions, Inc.

5965 Core Road, Suite 624 North Charleston, SC 29406)

12. Has VPN Installation been scheduled?

Appendix A: Software and Settings/Hardware Requirements

For Client to Server Connections:

We need to better understand the administrative tasks to be performed by the commercial partner to determine software and setting requirements. Please answer the following questions:

Question
Response

1. What is the highest number of simultaneous users you expect to have active connections at peak usage?

2. List the full name of all applications that you expect to use in management of your servers and/or remote assets. Please include any Proprietary software.

3. For each application, please list all dependencies required for full functionality, including:

a) Active X settings;

b) Specific browsers required (Chrome, Firefox, etc.);

c) Browser settings required;

d) SSL/CA Certificate installations

For Server to Server Connections:

The commercial partner will be required to purchase one of the following Cisco device(s) for their location(s):

· ISR C891fLess than 5Mb
· ISR 4331Between 5Mb-30Mb
· ISR 4451Between 30Mb-300Mb

Also, please make certain to provide (on Appendix F) 2 public IP addresses for each device to be installed.

Note: The Cisco pubs indicate higher bandwidth capabilities for models noted above; however, the Cisco figures are under ideal conditions (UDP, low overhead, etc.). These considerations were evaluated by the DHA engineers and factored in the configurations and other overhead/loading factors (noted above). If you opt to select the next lower/smaller model, then there is a potential risk of overloading the device, which will require the procurement of a replacement with the next higher model.

Appendix B: Submission of the System Authorization Access Request (SAAR) Form 2875

The DD 2875 form and instructions are attached in a separate PDF document named “DHAGSC_B2B_C2S_(v1.1 20171212)”

Appendix C: User Performance Requirements

Project Name

Program Office

Project POC

User System Requirements

Subject Matter
Metric

Commercial User to MHS System

Number of Users *

Number of Existing User Accounts*

Number of New User Accounts Needed*

Peak Operational Time

Operational Time Frame (Per Day)

Operational Time Frame (Per Week)

Operational Time Frame (Per Year)

Number of concurrent sessions per user

Number of concurrent users *

Average file/data size per user

Average number of transactions per day/ per user

Expected % growth per year

Other

Other

Other

Other

Other

MHS User to Third Party System

Number of Users

Peak Operational Time

Operational Time Frame (Per Day)

Operational Time Frame (Per Week)

Operational Time Frame (Per Year)

Number of concurrent sessions per user

Number of concurrent users

Average file/data size per user

Average number of transactions per day/ per user

Expected % growth per year

* Note: Each user should be coming from a unique IP address

Appendix D: System Performance Requirements Project Name

Program Office

Project POC

System (Third Party Partner) to System (MHS) Requirements

Subject Matter
Metric

Expected screen refresh time

Expected response time

Expected % availability uptime

Meantime between failure

Meantime to repair

Sustained throughput requirement

Max packet loss acceptable

Max latency

Expected bandwidth between systems

Peak bandwidth requirements

Other

Other

Other

Other

Other

Appendix E: VPN Implementation Form Project Name

Program Office

Project POC

Last Mile Information – WAN Access Please check the following for the .MIL side of the connection:

Question
Answer

1. Who is your Internet Service Provider? (Please Specify)

2. Assessment and Authorization

a. What type of certification does the Gov. Sponsor require? DIACAP/RMF, Certificate of Networthiness (CON), Platform IT (PIT), DODI8582.01

b. What is the current status of required certification and date of your expected date of certification?

c. Has documentation been provided to the B2B team as evidence of the A&A process? (ATO memo, 8582 evidence, CON memo, or PIT memo)

Please check the following for the .COM side of the connection:

Question
Answer

1. Who is your Internet Service Provider? (Please Specify)

2. Assessment and Authorization

a. What type of certification does the Gov. Sponsor require? DIACAP/RMF, Certificate of Networthiness (CON), Platform IT (PIT), DODI8582.01

b. What is the current status of required certification and date of your expected date of certification?

c. Has documentation been provided to the B2B team as evidence of the A&A process? (ATO memo, 8582 evidence, CON memo, or PIT memo)

Network Boundary Information (not required for Citrix)

1. What are the Interfaces of the Border Router?

Interface
IP Address
Subnet Mask
Default Gateway

2. What are the External and DMZ Interfaces of the Firewall?

Interface
IP Address
Subnet Mask
Default Gateway

3. What is the Network Space between the Firewall and Border Router where the Cisco ISR will be installed?

NOTES:

a. Ensure the Network between the Firewall and the Border Router has sufficient address space to support splitting the network.

b. Ensure the Bit Boundaries are valid and are NOT CROSSED when splitting into smaller subnets.

IP Network/ Mask
Subnet Mask

4.

What are the new Network Addresses for the Cisco ISR device?

External Interface
Subnet Mask
Default Gateway

Primary ISR

Secondary ISR

RLOC IP
Subnet Mask
Default Gateway

Primary ISR

255.255.255.255
NA

Secondary ISR

255.255.255.255
NA
Internal Interface
Subnet Mask
Default Gateway

Primary ISR

Secondary ISR

Floating

Note 1: For HA setup, each device would require a unique External, Internal and RLOC IP address. One additional floating Internal IP is required for VRRP failover.

Note 2: All IP addresses for the ISR need to be publically routable. Private address space using a NAT is not permitted.

Note 3: RLOC IP addresses should be /32 addresses and not a part of the subnet used by the External or Internal interfaces.

Firewall Specifics/Proxy Servers (not required for Citrix) Please check the following:

Question
Yes
No

1. Is this site using Network Address Translation (NAT) Static (1 to 1)?

Appendix F: DHA B2B Connectivity Requirements Submission

Vendor Name

Program Office

Project POC

Please read failure to do so will delay the processing of this request. If you are submitting a Phase II connection please complete the chart below titled Phase II Environment Type. For Phase I /Existing Connections skip down and complete the next chart titled Phase I or Existing Environment Type.

Phase II Environment Type (Please submit B2BQ for each environment. One environment per B2BQ)

Test
Production

APPLICATION

NAME

DESCRIPTION
IP

PROTOCOL

SERVICE
LOW

PORT

HIGH

PORT

VENDOR

SERVER

NAME

VENDOR

SERVER

IP

VENDOR

SERVER

NAT

DHA

SERVER

NAME

DHA

SERVER

IP

DHA

SERVER

NAT

DHA

SITE

LOCATION

CONNECTION

SOURCE

*Example*
Eg. BDMS
Eg. Blood Donor Management Server
Eg. TCP
Eg. SFTP
Eg. 22
22
Comm Vault Server
X.X.X.X
Provided

By NSOC

RSM

Insight Server
X.X.X.X
Provided

By NSOC

RSM

NMC San Diego
.COM
*Example*

Phase I or Existing Environment Type (Please submit B2BQ for each environment. One environment per B2BQ)

Test
Production
Application
Commercial IP Address
Commercial side B2B Gateway Address
.com Port
DoD side B2B Gateway Address
DoD IP Address
DoD Site Name
Data Service
Protocol
.mil Port
Source of traffic (.mil, .com, Bi-directional)

Defense Health Agency

B2B Implementation Plan v10.3 January 2018 The information contained in this document is of a sensitive nature to the Department of Defense. The reader shall not disclose such information to any person or entity except employees and affiliates who have a need-to-know and who have been informed of the reader’s obligations under this paragraph.

Appendix G: “As Is” Diagram (not required for Citrix)

Appendix H: Last Mile Diagram (not required for Citrix)

Appendix I: Device Package Slip (not required for Citrix)

INCLUDE THIS DOCUMENT INSIDE THE CISCO ISR SHIPPING PACKAGE

Name of Project

Point of Contact (POC)
Name of Company

ATTN: POC Name

ADDRESS

Contact Number Email

Device Serial Number

Device Model

Shipping Tracking Number

NOTE:

After shipment, please send a copy of this appendix to DHA PM Support.

Appendix J: ISSM Approval (For all new connections)

Information System Security Manager B2B Implementation Approval

[ ] As the ISSM for the DHA B2B C2S, I have reviewed the appropriate documentation and provide the approval to proceed as planned.

[ ] As the ISSM for the DHA B2B S2S, I have reviewed the appropriate documentation and provide the approval to proceed as planned.

TYPED NAME

SIGNATURE DATE

Appendix K: Site ISSM Approval (For all connections; i.e. add/remove/modify)

Information Assurance Manager

As the Site ISSM for [appropriate program office or installation], I have reviewed the appropriate documentation and provide the approval to proceed as planned.

TYPED NAME

PROGRAM OFFICE

SIGNATURE DATE

Appendix L: Program Manager Approval (For all connections; i.e. add/remove/modify) May sign in lieu of multiple site ISSM connections sic Appendix K

Program Manager

As the Government Sponsor for [appropriate program office or installation], I have reviewed the appropriate documentation and vendor certification. I provide the approval to proceed as planned.

TYPED NAME

_____________________________________________________________________ SIGNATURE DATE

Appendix M: Security Approval (For all connections; i.e. add/remove/modify)

Commercial Partner Security Manager

As the Security Manager of the [MHS .com partner], I have reviewed the appropriate documentation and provide the approval to proceed as planned.

TYPED NAME

SIGNATURE DATE

Appendix N: Project Manager Approval (For all connections; i.e. add/remove/modify)

Defense Health Agency B2B Gateway Project Manager

As the Business-to-Business Gateway Project Manager for DHA, I have reviewed the appropriate documentation and provide the approval to proceed as planned.

TYPED NAME

SIGNATURE DATE

image2.emf

Microsoft_Visio_Drawing1111111111111.vsdx image1.png

File details come from the government source that posted it. Updated .