Exhibit J DHA B2B Gateway Questionnaire -- 26 Feb 2020.docx
DOCX document 1 MB Posted
- Attached to
- Clinical Reference Laboratory Testing Services Federal contract opportunity
- Solicitation number
- W81K04-20-R-0017-0001
- Issued by
- Department of the Army Medical Command
About this file
This document is a questionnaire template for commercial partners to connect their systems to the Defense Health Agency's Military Health System network via a virtual private network. It includes appendices requesting details on software and hardware requirements, system performance needs, and network diagrams. Appendix F requires a table listing proposed applications with descriptions, protocols, port numbers, IP addresses and site locations. It seeks approval signatures from various information system security managers and project managers.
The related federal contract opportunity posting is for clinical reference laboratory testing services for the Department of the Army Medical Command. It provides no further specification of required products or services.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 11 Workload by MTF FY2018 -- 26 Feb 2020.xlsx | XLSX spreadsheet | |
| Questions and Answers - 27FEB2020 Final.pdf | ||
| Exhibit B_Summary by Facility Name -- 26 Feb 2020.xlsx | XLSX spreadsheet | |
| W81K04-20-R-0017-0001 Reference Lab Amendment.pdf | ||
| Exhibit C_Schedule of Required Tests -- 26 Feb 2020.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Defense Health Agency
DEFENSE HEALTH AGENCY
BUSINESS 2 BUSINESS (B2B) GATEWAY QUESTIONNAIRE
PHASE II – [INSERT VENDOR NAME AND MTFS IF LISTED]
January 31, 2018 Version 10.3
CHANGE / REVISION RECORD
This record is maintained throughout the life of the document; each published update is recorded. A Change Package (re-issue of changed pages only) carries change bars in the page margins to identify differences from the preceding issue. Due to the scope of change that necessitates a Revision (re-issue of entire document); a Revision does not carry change bars.
| DOCUMENT VERSION NUMBER |
| REVISION SUMMARY |
| DATE |
| Version 5.0 |
| Updated to reflect transition from DISA to DHA |
| 12/14/15 |
| Version 6.0 |
| Updated to reflect AnyConnect option |
| 4/4/16 |
| Version 7.0 |
| Updated to reflect Citrix option |
| 11/9/16 |
| Version 8.0 |
| Updated contact list to reflect current personnel |
| 12/2/16 |
| Version 9.0 |
| Updated the TOC. Updated General Information Page. Updated the DHA staff information. Updated the Implementation Checklist. Removed the DD Form 2875 attachment and screenshot and added a Web link to access the form. Added an appendix to gather data for software and hardware requirements. Revised the B2B Requirements appendix. Added a signature line for program office’s ISSM. |
| 8/8/17 |
| Version 10.0 |
| Update DoD POC information. Replace “Netscreen” with “Cisco ISR” under Network Boundary Information. Update Network Address table and Notes below table. Update Appendix I. Add Appendix K and update following Appendices’ letters. |
| 10/26/17 |
| Version 10.2 |
| “eMASS #” section added in General Information table. Update B2B Mailbox email address in DoD POC table. Last Mile Information table of Appendix E updated. Appendix J &K edited. |
| 1/23/18 |
| Version 10.3 |
| Updated Appendix F: Phase I/Existing Connection chart. Clarified Example row on Phase II Chart |
| 1/31/18 |
Table of Contents
| Introduction | 5 |
| DHA Policy for Communications | 6 |
| Commercial Partner POC Information | 9 |
| Implementation Checklist | 10 |
| Appendix A: Software and Settings/Hardware Requirements | 11 |
Appendix B: Submission of the System Authorization Access Request (SAAR)
| Form 2875 | 12 |
| Appendix C: User Performance Requirements | 13 |
| User System Requirements | 13 |
| Appendix D: System Performance Requirements | 14 |
| System (Third Party Partner) to System (MHS) Requirements | 14 |
| Appendix E: VPN Implementation Form | 15 |
| Last Mile Information – WAN Access | 15 |
| Network Boundary Information (not required for Citrix) | 15 |
| Firewall Specifics/Proxy Servers (not required for Citrix) | 17 |
| Appendix F: DHA B2B Connectivity Requirements Submission | 18 |
| Appendix G: “As Is” Diagram (not required for Citrix) | 20 |
| Appendix H: Last Mile Diagram (not required for Citrix) | 21 |
| Appendix I: Device Package Slip (not required for Citrix) | 22 |
| Appendix J: ISSM Approval (For all new connections) | 23 |
| Appendix K: Site ISSM Approval | 24 |
| Appendix L: Program Manager Approval | 25 |
| Appendix M: Security Approval | 26 |
| Appendix N: Project Manager Approval (For new connections only) | 27 |
Introduction Defense Health Agency (DHA) oversees the Military Health System (MHS) Infrastructure and Operations (I&O). DHA is chartered to design, provision, and deploy a standards based, common telecommunications infrastructure throughout the MHS.
This information paper identifies the required parameters for Commercial Business Partners to connect to an MHS Military Treatment Facility (MTF) or other Department of Defense (DoD) .mil network using a Virtual Private Network (VPN). This information sheet is intended do the following:
· Adhere to the DoD Guidelines for third party vendors
· Adhere to the policies of connectivity and device management of the third party vendor
· Meet the functional and technical requirements as designed for a given project
In prioritizing security and confidentiality of DoD system resources and networks, the gateway approach is the standard for all non-DoD resources to connect, communicate, and manage systems within the DoD. In the gateway solution, the third party affiliate will terminate at a DMZ and then be re-directed to its destination. This is the recommended long-term solution to ensure data and system resource security and confidentiality.
The following criterion depicts a Gateway solution:
· There is a single reference point for the third party affiliate to the DoD thus eliminating any back doors to the DoD
· Third party affiliate VPN device procurement resource must be identified
· Third party affiliate VPN device model must be in the product line of the DHA – MHS Standard
· The DHA VPN team maintains Configuration Management and support of the VPN device located at the Third Party Affiliate’s DMZ
· MHS traffic can be more effectively managed
· Adheres to the DoD initiative to move away from third party affiliates connecting directly to a MTF This document is to serve as a template to identify the requirements of the sponsoring organization and the third party partner to DHA. Below will be detailed information that when completed will be used for:
· Establishing necessary requirements
· Configuring the MHS B2B Gateway
· Configuring the VPN device
DHA Policy for Communications The TRICARE Systems Manual (TSM 7950.1-M) discusses the requirements necessary for Managed Care Contractors to interface with the Department of Defense (DoD):
Defense Health Agency
B2B Implementation Plan v10.3 January 2018 The information contained in this document is of a sensitive nature to the Department of Defense. The reader shall not disclose such information to any person or entity except employees and affiliates who have a need-to-know and who have been informed of the reader’s obligations under this paragraph.
General Information
Project Information
| Request Type |
| New Connection(s) |
| Changes/Updates to Existing Connection(s) |
| Decommission Connection(s) |
| Connection Type: For legacy Juniper connections select “Changes/Updates..” and/or “Decommission..” |
| Server to Server |
Allows continuous connectivity between the partner-and DHA-hosted servers. The commercial partner (vendor) will be required to procure and install a DHA-configured and tested Cisco VPN router (Cisco ISR) on its premise at all appropriate locations. The device (which will be remotely managed by DHA) will provide a controlled entry/exit point and an encrypted pathway for all communications between the commercial partner and its DHA-hosted system(s). System-to-system communications are defined as automated processes between two systems that require always-on connectivity.
Client to Server Allows the commercial partner system administrators to manage and monitor those systems for which they are responsible. Client-to-server communications are defined as any administrative function that requires administrative input (Remote Desktop, Dameware, SSH, etc).This will be an on-demand solution and will require the administrator to establish a connection for each use through a DHA provided Virtual Desktop Infrastructure (VDI) using CAC authentication.
eMASS # (DHA ID for the system with which the vendor is communicating.)
Project Name (Vendor Name to MHS Name)
Program Office
Description: What is this for?
Requested Date:
Critical Date:
DoD POC Information Please complete the following:
| DoD Organization |
| Name |
| Phone |
Government POC Sponsoring the B2B Gateway Connection
Contracting Officer/COR
ISSM
| DHA B2B ISSM |
| Mr. Eric Wildermuth |
| (703) 681-1145 |
| Eric.R.Wildermuth.civ@mail.mil |
| DHA B2B Project Manager |
| Mr. Orlando Januario Jr. |
| (210) 295-3599 |
| orlandojr.januario.civ@mail.mil |
| DHA B2B Project Manager |
| Mr. Gary Waltman |
| (703) 681-6754 |
| Gary.P.Waltman.civ@mail.mil |
| DHA B2B PM Support |
| Ms. Asha Jones |
| (571) 765-6136 |
| asha.z.jones2.ctr@mail.mil |
| DHA B2B Phase 2 Support |
| Mr. Ronald Yoon |
| (516) 509-0022 |
| ronald.i.yoon.ctr@mail.mil |
DHA Engineer
| DHA Other (SPAWAR) |
| Remote Systems Management |
rsm@nsoc.health.mil
| DHA Global Service Center |
| DHA Global Service Center Personnel |
| (800)-600-9332 |
| dhagsc@mail.mil |
| DHA B2B Mailbox |
| DHA B2B Team |
dha.ncr.ops-sustain.list.b2b-phase2@mail.mil
.MIL Gov.
.MIL PM Support
.MIL Firewall Engineer
.MIL System Administrator
Commercial Partner POC Information Please complete the following:
| Organization |
| Name |
| Phone |
PM
Application /System Engineer
Network Administrator
Security Manager
Network Manager
| Organization |
| Name |
| Phone |
| Procedures |
Help Desk Contact Information
After-Hours Support Contact Information
Organization Address:
Physical Device Location (not required for Citrix): {NOTE: Be sure to include the full address, building, room, and rack where the MHS VPN node will be deployed}
Implementation Checklist Please check the following:
| Question |
| Yes |
| No |
| Date Complete |
1. Has the software requirements for C2S connection been provided by vendor? (Appendix A)
2. Is Form 2875 completed? (See PDF file “DHAGSC_B2B_C2S (v.1.1 20171212)” sent with questionnaire)
3. Internet addresses are publicly routable for all B2B applications? (Clients need a unique address for authentication tracking.)
4. Is user performance requirement information completed?
(Appendix C)
5. Is system performance requirement information completed? (Appendix D)
6. Has the VPN Implementation Form been completed? (Appendix E)
7. Has Connectivity Requirements Sheet been submitted? (Appendix F)
8. Has “As Is” Network Diagram been provided? (Appendix G - Attachment)
9. Has VPN Last Mile Diagram (Appendix H) been discussed and concurred by both sides?
10. Is VPN device procured? (Appendix A, S2S connections only)
11. Has the VPN device been configured and STIGed by DHA?
(Please send VPN device to the contact and address below for configuration:
Shaun Pillé KSH Solutions, Inc.
5965 Core Road, Suite 624 North Charleston, SC 29406)
12. Has VPN Installation been scheduled?
Appendix A: Software and Settings/Hardware Requirements
For Client to Server Connections:
We need to better understand the administrative tasks to be performed by the commercial partner to determine software and setting requirements. Please answer the following questions:
| Question |
| Response |
1. What is the highest number of simultaneous users you expect to have active connections at peak usage?
2. List the full name of all applications that you expect to use in management of your servers and/or remote assets. Please include any Proprietary software.
3. For each application, please list all dependencies required for full functionality, including:
a) Active X settings;
b) Specific browsers required (Chrome, Firefox, etc.);
c) Browser settings required;
d) SSL/CA Certificate installations
For Server to Server Connections:
The commercial partner will be required to purchase one of the following Cisco device(s) for their location(s):
| · ISR C891f | Less than 5Mb |
| · ISR 4331 | Between 5Mb-30Mb |
| · ISR 4451 | Between 30Mb-300Mb |
Also, please make certain to provide (on Appendix F) 2 public IP addresses for each device to be installed.
Note: The Cisco pubs indicate higher bandwidth capabilities for models noted above; however, the Cisco figures are under ideal conditions (UDP, low overhead, etc.). These considerations were evaluated by the DHA engineers and factored in the configurations and other overhead/loading factors (noted above). If you opt to select the next lower/smaller model, then there is a potential risk of overloading the device, which will require the procurement of a replacement with the next higher model.
Appendix B: Submission of the System Authorization Access Request (SAAR) Form 2875
The DD 2875 form and instructions are attached in a separate PDF document named “DHAGSC_B2B_C2S_(v1.1 20171212)”
Appendix C: User Performance Requirements
Project Name
Program Office
Project POC
User System Requirements
| Subject Matter |
| Metric |
Commercial User to MHS System
Number of Users *
Number of Existing User Accounts*
Number of New User Accounts Needed*
Peak Operational Time
Operational Time Frame (Per Day)
Operational Time Frame (Per Week)
Operational Time Frame (Per Year)
Number of concurrent sessions per user
Number of concurrent users *
Average file/data size per user
Average number of transactions per day/ per user
Expected % growth per year
Other
Other
Other
Other
Other
MHS User to Third Party System
Number of Users
Peak Operational Time
Operational Time Frame (Per Day)
Operational Time Frame (Per Week)
Operational Time Frame (Per Year)
Number of concurrent sessions per user
Number of concurrent users
Average file/data size per user
Average number of transactions per day/ per user
Expected % growth per year
* Note: Each user should be coming from a unique IP address
Appendix D: System Performance Requirements Project Name
Program Office
Project POC
System (Third Party Partner) to System (MHS) Requirements
| Subject Matter |
| Metric |
Expected screen refresh time
Expected response time
Expected % availability uptime
Meantime between failure
Meantime to repair
Sustained throughput requirement
Max packet loss acceptable
Max latency
Expected bandwidth between systems
Peak bandwidth requirements
Other
Other
Other
Other
Other
Appendix E: VPN Implementation Form Project Name
Program Office
Project POC
Last Mile Information – WAN Access Please check the following for the .MIL side of the connection:
| Question |
| Answer |
1. Who is your Internet Service Provider? (Please Specify)
2. Assessment and Authorization
a. What type of certification does the Gov. Sponsor require? DIACAP/RMF, Certificate of Networthiness (CON), Platform IT (PIT), DODI8582.01
b. What is the current status of required certification and date of your expected date of certification?
c. Has documentation been provided to the B2B team as evidence of the A&A process? (ATO memo, 8582 evidence, CON memo, or PIT memo)
Please check the following for the .COM side of the connection:
| Question |
| Answer |
1. Who is your Internet Service Provider? (Please Specify)
2. Assessment and Authorization
a. What type of certification does the Gov. Sponsor require? DIACAP/RMF, Certificate of Networthiness (CON), Platform IT (PIT), DODI8582.01
b. What is the current status of required certification and date of your expected date of certification?
c. Has documentation been provided to the B2B team as evidence of the A&A process? (ATO memo, 8582 evidence, CON memo, or PIT memo)
Network Boundary Information (not required for Citrix)
1. What are the Interfaces of the Border Router?
| Interface |
| IP Address |
| Subnet Mask |
| Default Gateway |
2. What are the External and DMZ Interfaces of the Firewall?
| Interface |
| IP Address |
| Subnet Mask |
| Default Gateway |
3. What is the Network Space between the Firewall and Border Router where the Cisco ISR will be installed?
NOTES:
a. Ensure the Network between the Firewall and the Border Router has sufficient address space to support splitting the network.
b. Ensure the Bit Boundaries are valid and are NOT CROSSED when splitting into smaller subnets.
| IP Network/ Mask |
| Subnet Mask |
4.
What are the new Network Addresses for the Cisco ISR device?
| External Interface |
| Subnet Mask |
| Default Gateway |
Primary ISR
Secondary ISR
| RLOC IP |
| Subnet Mask |
| Default Gateway |
Primary ISR
| 255.255.255.255 |
| NA |
Secondary ISR
| 255.255.255.255 |
| NA |
| Internal Interface |
| Subnet Mask |
| Default Gateway |
Primary ISR
Secondary ISR
Floating
Note 1: For HA setup, each device would require a unique External, Internal and RLOC IP address. One additional floating Internal IP is required for VRRP failover.
Note 2: All IP addresses for the ISR need to be publically routable. Private address space using a NAT is not permitted.
Note 3: RLOC IP addresses should be /32 addresses and not a part of the subnet used by the External or Internal interfaces.
Firewall Specifics/Proxy Servers (not required for Citrix) Please check the following:
| Question |
| Yes |
| No |
1. Is this site using Network Address Translation (NAT) Static (1 to 1)?
Appendix F: DHA B2B Connectivity Requirements Submission
Vendor Name
Program Office
Project POC
Please read failure to do so will delay the processing of this request. If you are submitting a Phase II connection please complete the chart below titled Phase II Environment Type. For Phase I /Existing Connections skip down and complete the next chart titled Phase I or Existing Environment Type.
Phase II Environment Type (Please submit B2BQ for each environment. One environment per B2BQ)
| Test |
| Production |
APPLICATION
NAME
| DESCRIPTION |
| IP |
PROTOCOL
| SERVICE |
| LOW |
PORT
HIGH
PORT
VENDOR
SERVER
NAME
VENDOR
SERVER
IP
VENDOR
SERVER
NAT
DHA
SERVER
NAME
DHA
SERVER
IP
DHA
SERVER
NAT
DHA
SITE
LOCATION
CONNECTION
SOURCE
| *Example* |
| Eg. BDMS |
| Eg. Blood Donor Management Server |
| Eg. TCP |
| Eg. SFTP |
| Eg. 22 |
| 22 |
| Comm Vault Server |
| X.X.X.X |
| Provided |
By NSOC
RSM
| Insight Server |
| X.X.X.X |
| Provided |
By NSOC
RSM
| NMC San Diego |
| .COM |
| *Example* |
Phase I or Existing Environment Type (Please submit B2BQ for each environment. One environment per B2BQ)
| Test |
| Production |
| Application |
| Commercial IP Address |
| Commercial side B2B Gateway Address |
| .com Port |
| DoD side B2B Gateway Address |
| DoD IP Address |
| DoD Site Name |
| Data Service |
| Protocol |
| .mil Port |
| Source of traffic (.mil, .com, Bi-directional) |
Defense Health Agency
B2B Implementation Plan v10.3 January 2018 The information contained in this document is of a sensitive nature to the Department of Defense. The reader shall not disclose such information to any person or entity except employees and affiliates who have a need-to-know and who have been informed of the reader’s obligations under this paragraph.
Appendix G: “As Is” Diagram (not required for Citrix)
Appendix H: Last Mile Diagram (not required for Citrix)
Appendix I: Device Package Slip (not required for Citrix)
INCLUDE THIS DOCUMENT INSIDE THE CISCO ISR SHIPPING PACKAGE
Name of Project
| Point of Contact (POC) |
| Name of Company |
ATTN: POC Name
ADDRESS
Contact Number Email
Device Serial Number
Device Model
Shipping Tracking Number
NOTE:
After shipment, please send a copy of this appendix to DHA PM Support.
Appendix J: ISSM Approval (For all new connections)
Information System Security Manager B2B Implementation Approval
[ ] As the ISSM for the DHA B2B C2S, I have reviewed the appropriate documentation and provide the approval to proceed as planned.
[ ] As the ISSM for the DHA B2B S2S, I have reviewed the appropriate documentation and provide the approval to proceed as planned.
TYPED NAME
SIGNATURE DATE
Appendix K: Site ISSM Approval (For all connections; i.e. add/remove/modify)
Information Assurance Manager
As the Site ISSM for [appropriate program office or installation], I have reviewed the appropriate documentation and provide the approval to proceed as planned.
TYPED NAME
PROGRAM OFFICE
SIGNATURE DATE
Appendix L: Program Manager Approval (For all connections; i.e. add/remove/modify) May sign in lieu of multiple site ISSM connections sic Appendix K
Program Manager
As the Government Sponsor for [appropriate program office or installation], I have reviewed the appropriate documentation and vendor certification. I provide the approval to proceed as planned.
TYPED NAME
_____________________________________________________________________ SIGNATURE DATE
Appendix M: Security Approval (For all connections; i.e. add/remove/modify)
Commercial Partner Security Manager
As the Security Manager of the [MHS .com partner], I have reviewed the appropriate documentation and provide the approval to proceed as planned.
TYPED NAME
SIGNATURE DATE
Appendix N: Project Manager Approval (For all connections; i.e. add/remove/modify)
Defense Health Agency B2B Gateway Project Manager
As the Business-to-Business Gateway Project Manager for DHA, I have reviewed the appropriate documentation and provide the approval to proceed as planned.
TYPED NAME
SIGNATURE DATE
image2.emf
Microsoft_Visio_Drawing1111111111111.vsdx image1.png
File details come from the government source that posted it. Updated .