CLIN-SCLIN Descriptions.doc

DOC document 118 KB Posted

Attached to
Capacity Services Communications Federal contract opportunity
Solicitation number
HC102810R2039
Issued by
Defense Information Systems Agency

About this file

CLIN-SLIN Description Document

View the file

Other files for this federal contract opportunity

Other files attached to Capacity Services Communications, newest first.
File Type Posted
Evaluation Scenario with Quantities.xls XLS spreadsheet
HC102810R2039 Amd 2 CSC Questions.doc DOC document
J-1 Section B-Maintenance Pricing Table.xls XLS spreadsheet
Released RFP Amd 3.doc DOC document
IT Equipment Rack Specifications.pdf PDF
HC102810R2039 CSC Questions.doc DOC document
Evaluation Scenario with Quantities.xls XLS spreadsheet
Released RFP Amd 2.doc DOC document
J-5 Section B Pricing Table.xls XLS spreadsheet
Released RFP Amd 1.doc DOC document
J-4 NDA for Contractor Employees.doc DOC document
Released RFP.doc DOC document
J-3 DD254.doc DOC document
J-4 NDA for Contractor Employees.doc DOC document
J-5 Pricing Table.xls XLS spreadsheet
J-2 QASP.doc DOC document
J-1 Equipment List dtd 7 Sep 10.xls XLS spreadsheet
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

This document is an attachment to the J-5 Section B Pricing Table document in RFP HC1028-10-R-2039. The information contained in this document provides a complete detailed description of the CLINs and SubCLINs listed in the Pricing Table.

CLIN 0001 Category 1 Switches CONUS

Category 1 of this contract focuses on network switch technology and the features required in a datacenter.

SCLIN 0001AA Category 1 Switches Tier 1a (Small)

This tier is the lowest category of switch used on this contract. This type of switch would be classified as an access layer switch used for layer 2 connectivity in the data center. This switch needs to support the data center class requirements but remain cost effective enough to be deployed on a larger scale. Features typically found in this class of switch would be: port channeling, modular expansion for uplinks, port security, layer 2 access control, dual redundant power supplies, multicast, and port mirroring.

Size: 1 Gbps Port Example hardware models in this tier are: Cisco 4948, Juniper EX4200 SCLIN 0001AB Category 1 Switches Tier 1b (Small)

This tier is the lowest category of switch used on this contract. This type of switch would be classified as an access layer switch used for layer 2 connectivity in the data center. This switch needs to support the data center class requirements but remain cost effective enough to be deployed on a larger scale. Features typically found in this class of switch would be: port channeling, modular expansion for uplinks, port security, layer 2 access control, dual redundant power supplies, multicast, and port mirroring.

Size: 10 Gbps Port Example hardware models in this tier are: Cisco 4948, Juniper EX4200

SCLIN 0001AC Category 1 Switches Tier 2a (Medium)

This tier encompasses the switch models that meet the typical data center class layer 2 switching requirements found in the aggregation layer. This category contains the features found in the tier 1 class switches as well as some of the features found in the tier 3. This type of switch has the ability to switch network traffic at a high rate of speed, provide redundant configurations, and remain scalable. Features typically found in this class of switch would be: Port channeling, hot swappable modules, multicast, port mirroring, dual redundant power supplies, port security, and IPv6.

Size: 1 Gbps Port Example hardware models in this tier are: Cisco 4506, Juniper EX4500

SCLIN 0001AD Category 1 Switches Tier 2b (Medium)

This tier encompasses the switch models that meet the typical data center class layer 2 switching requirements found in the aggregation layer. This category contains the features found in the tier 1 class switches as well as some of the features found in the tier 3. This type of switch has the ability to switch network traffic at a high rate of speed, provide redundant configurations, and remain scalable. Features typically found in this class of switch would be: Port channeling, hot swappable modules, multicast, port mirroring, dual redundant power supplies, port security, and IPv6.

Size: 10 Gbps Port Example hardware models in this tier are: Cisco 4506, Juniper EX4500

SCLIN 0001AE Category 1 Switches Tier 3a (Large)

This tier encompasses the higher end switches that would typically be found in a Data Center, Enterprise, or Core device classes. These devices are not only capable of supporting greater throughput and meeting higher density port requirements but also have the features and options of supporting the latest technologies found in an enterprise class network. This type of switch will need to support high availability, operational simplicity, and have the scalability to meet the requirements of a cutting edge IT switch. Features typically found in this class of switch would be: Port channeling, VLAN management, high throughput, hot swappable modules, hardware acceleration, dual redundant power supplies, IPv6 Quality of Service (QOS), and virtualization.

Size: 1 Gbps Port Example hardware models in this tier are: Cisco 6513, Cisco 6509, and Juniper EX8200

SCLIN 0001AF Category 1 Switches Tier 3b (Large)

This tier encompasses the higher end switches that would typically be found in a Data Center, Enterprise, or Core device classes. These devices are not only capable of supporting greater throughput and meeting higher density port requirements but also have the features and options of supporting the latest technologies found in an enterprise class network. This type of switch will need to support high availability, operational simplicity, and have the scalability to meet the requirements of a cutting edge IT switch. Features typically found in this class of switch would be: Port channeling, VLAN management, high throughput, hot swappable modules, hardware acceleration, dual redundant power supplies, IPv6 Quality of Service (QOS), and virtualization.

Size: 10 Gbps Port Example hardware models in this tier are: Cisco 6513, Cisco 6509, and Juniper EX8200

CLIN 0002 Category 2 Routers CONUS Routers are specialized hardware-based network communications devices that interconnect two or more computer networks and selectively interchange packets of data between them.

SCLIN 0002AA Category 2 Routers

Tier 1a (Small): 4 Gbps or less of aggregate data passed through the device

A small router is typically optimized for lower performance needs, such as use within a branch or small office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4 and IPv6, using open-standards based routing protocols such as OSPF and BGP, and provide packet filtering capabilities using access-control lists. Minimal scalability through additional line cards to allow for interface expansion. Redundancy of power input is common in this tier of router. Routers in this tier typically pass 4 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 1 Gbps Port Examples of routers in the medium tier include Cisco 3900 series Integrated Services Routers and Juniper J6350 3D Universal Edge Router.

SCLIN 0002AB Category 2 Routers

Tier 1b (Small): 4 Gbps or less of aggregate data passed through the device

A small router is typically optimized for lower performance needs, such as use within a branch or small office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4 and IPv6, using open-standards based routing protocols such as OSPF and BGP, and provide packet filtering capabilities using access-control lists. Minimal scalability through additional line cards to allow for interface expansion. Redundancy of power input is common in this tier of router. Routers in this tier typically pass 4 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 10 Gbps Port Examples of routers in the medium tier include Cisco 3900 series Integrated Services Routers and Juniper J6350 3D Universal Edge Router.

SCLIN 0002AC Category 2 Routers

Tier 2a (Medium): 100 Gbps or less of aggregate data passed through the device A router in the medium tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and 10 Gbps interface availability. Medium tier devices typically exhibit significant scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 100 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 1 Gbps Port Examples of routers in this medium tier include Cisco 7200 Series and Juniper MX80 3D Universal Edge routers.

SCLIN 0002AD Category 2 Routers

Tier 2b (Medium): 100 Gbps or less of aggregate data passed through the device A router in the medium tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and 10 Gbps interface availability. Medium tier devices typically exhibit significant scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 100 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 10 Gbps Port Examples of routers in this medium tier include Cisco 7200 Series and Juniper MX80 3D Universal Edge routers.

SCLIN 0002AE Category 2 Routers

Tier 3a (Large): 2 Tbps or less of aggregate data passed through the device

A router in the large tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and multiple 10 Gbps interface availability. Large tier devices typically exhibit robust scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 2 Tbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 1 Gbps Port Examples of routers in the large tier include Cisco 7600 Series and Juniper MX480 3D Universal Edge routers.

SCLIN 0002AF Category 2 Routers

Tier 3b (Large): 2 Tbps or less of aggregate data passed through the device

A router in the large tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and multiple 10 Gbps interface availability. Large tier devices typically exhibit robust scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 2 Tbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 10 Gbps Port Examples of routers in the large tier include Cisco 7600 Series and Juniper MX480 3D Universal Edge routers.

CLIN 0003 Category 3 Appliances CONUS

Application-level gateways are devices or specialized operating environments in a virtualized environment that provide protection to certain application-layer “control/data” protocols such as HTTP, HTTPS, DNS, XML and/or FTP, while commonly providing load balancing capabilities as well.

SCLIN 0003AA Category 3 Appliances

Tier 1 - Application-level gateway

Tier 1a (Small)

Small application-level gateways provide basic application protection, caching and/or load balancing functionalities at the enclave level. These are typically deployed directly in front of the servers they are supporting. Features include basic caching, protocol acceleration, load balancing, and application-layer communications protection. SSL termination is typically not required at this tier. Automatic configuration synchronization between redundant pairs of devices is common at this level. Remote management, redundant power and traffic monitoring are common as well.

Examples include the F5 Networks BigIP LTM VE, the Blue Coat ProxySG 210 series.

SCLIN 0003AB Category 3 Appliances

Tier 1 - Application-level gateway

Tier 1b (Large)

The large tier of application-level gateways provides application protection and load balancing at datacenter, DMZ or global levels. Are typically deployed at the perimeter of the network and provide caching, protocol acceleration, load balancing and application-layer communications protection services to multiple workloads at one or more sites. SSL offload is often required at this level using FIPS 140-2 compliant equipment. Large tier application-level gateways often offer DNS components to allow for load balancing across multiple sites.

Examples of large tier devices include F5 Networks BigIP LTM / GTM 6900, the Blue Coat ProxySG 8100 series, Cisco ACE XML Gateway, and Cisco ACE GSS 4400 series.

SCLIN 0003AC Category 3 Appliances

Tier 2 - Firewall

A firewall is a software based application suite or hardware based network appliance designed to permit and/or deny access to a network, enclave or data center based upon configured rules. Basic features common to each proceeding tier are high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.), cost effective bandwidth capability, and cost effective simultaneous connection support.

Tier 2a (Small)

Firewall servers or devices at this tier are expected to protect a small enclave or network using a limited sized ruleset in support of a limited number of applications, servers and/or devices. Devices in this tier typically reside in the access layer in the hierarchical internetworking model. Features included in this tier include high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.). Redundant power paths are also common.

Example Hardware: Cisco ASA 5505 or 5510, Juniper Netscreen 5200

SCLIN 0003AD Category 3 Appliances

Tier 2 - Firewall

A firewall is a software based application suite or hardware based network appliance designed to permit and/or deny access to a network, enclave or data center based upon configured rules. Basic features common to each proceeding tier are high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.), cost effective bandwidth capability, and cost effective simultaneous connection support.

Tier 2b (Medium)

Firewalls in this tier typically support multiple enclaves and networks and therefore the servers support multiple customers and applications. Features included in this tier commonly include all the features outlines in tier 2a above, plus virtualization capabilities, high availability, IDS capabilities, multiple site-to-site VPN connection termination, high-speed network interface connections (up to 1 Gbps per interface), and are commonly scalable to include increased capabilities and new technologies through the installation of line cards or modules. Devices in this tier typically reside in the aggregation or distribution layers of the network.

Example firewalls in this tier include Cisco ASA 5520 and 5540 models and Juniper Netscreen 5200 or ISG1000 devices.

SCLIN 0003AE Category 3 Appliances

Tier 2 - Firewall

A firewall is a software based application suite or hardware based network appliance designed to permit and/or deny access to a network, enclave or data center based upon configured rules. Basic features common to each proceeding tier are high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.), cost effective bandwidth capability, and cost effective simultaneous connection support.

Tier 2c (Large)

Tier 2c is described as the high performance security device or server that protects entire data centers or large enterprise networks. This level device should support features included in the tiers above, plus upgradable hardware, support for multiple high speed network interface cards (1 Gbps or faster) , and are commonly scalable to include increased capabilities and new technologies through the installation of line cards or modules. Devices in this tier typically reside at the core layer of the network.

Example Hardware: Cisco ASA 5550 or 5580, Juniper Netscreen 5400 or ISG2000

SCLIN 0003AF Category 3 Appliances

Tier 3 - Intrusion Detection System

Category 3; Tier 3 of this contract focuses on Intrusion Detection System and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 3a (Small)

Tier 3a Intrusion Detection Systems would be the smallest sensor used on the network. They would provide real-time and historical analytics based on vulnerability and anomaly based inspection methods. This data would be aggregated and sent to a central management location for processing. Tier 3a Intrusion Detection Systems should be capable of identifying vulnerabilities as well as reporting real-time security threats. Automatic trend identification and analysis should be a common function of Tier 3a Intrusion Detection Systems. Tier 3a Intrusion Detection Systems would generally support a throughput of approximately 100 Mbps.

Example: SourceFire 3D2000 Sensor

SCLIN 0003AG Category 3 Appliances

Category 3; Tier 3 of this contract focuses on Intrusion Detection System and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 3b (Medium)

Tier 3b Intrusion Detection Systems would incorporate all the features of a Tier 3a Sensor, however the size of the supported site or enclave would be significantly larger. Tier 3b Intrusion Detection Systems would be used to the perimeter of a large LAN or medium Campus network. Expected throughput for a Tier 3b system would be approximately 1 Gbps.

Example: SourceFire 3D3500 Sensor

SCLIN 0003AH Category 3 Appliances

Category 3; Tier 3 of this contract focuses on Intrusion Detection System and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 3c (Large)

Tier 3c Intrusion Detection Systems would incorporate all the features of Tier 3a and Tier 3b Sensors, however the size of the supported site or enclave would be significantly larger. Tier 3c Intrusion Detection Systems would be used at the top of the network topology, likely in a DMZ environment. Expected throughput for a Tier 3c system would be approximately 10 Gbps.

Example: SourceFire 3D9900 Sensor

SCLIN 0003AJ Category 3 Appliances

Tier 4 - SMTP Email Security Appliance

Email security appliances are used to protect the enterprise from external attacks and prevent internal email viruses from spreading. Features typically found in this class of email security appliance are spam defense, virus defense, phishing defense, and other email related threats.

Tier 4a (Small)

This tier meets the requirements generally needed for specific application or smaller workload requirements. Features that are typically found in this class are: virus defense, phishing, mail relay.

Example hardware models in this tier are: Cisco C160 and McAfee S120

SCLIN 0003AK Category 3 Appliances

Tier 4 - SMTP Email Security Appliance

Email security appliances are used to protect the enterprise from external attacks and prevent internal email viruses from spreading. Features typically found in this class of email security appliance are spam defense, virus defense, phishing defense, and other email related threats.

Tier 4b (Medium)

This tier focuses on meeting the requirements at a datacenter level and should be able to support the bandwidth, storage, and concurrent sessions to support the workloads at each center. Features that are typically found in this class are: centralized management, spam protection, virus defense, phishing defense, mail relay, attachment blocking, and data loss prevention.

Example hardware models in this tier are: Cisco 360, Cisco 370, and McAfee EG-5000 SCLIN 0003AL Category 3 Appliances

Tier 4 - SMTP Email Security Appliance

Email security appliances are used to protect the enterprise from external attacks and prevent internal email viruses from spreading. Features typically found in this class of email security appliance are spam defense, virus defense, phishing defense, and other email related threats.

Tier 4c (Large) This tier encompasses the higher end enterprise class appliances. Features that are typically found in this class are: centralized management, Policy enforcement, spam protection, virus defense, SMTP relay, attachment blocking, and data loss prevention.

Example hardware models in this tier are: Cisco X1060, Cisco C660, and McAfee EG-5500.

SCLIN 0003AM Category 3 Appliances Tier 5 - Wan Optimizers

This focuses on network WAN optimization and the features required in the datacenter. WAN optimization products seek to accelerate a broad range of applications accessed by distributed enterprise users via eliminating redundant transmissions, staging data in local caches, compressing and prioritizing data, and streamlining chatty protocol. WAN optimization also helps avoid packet delivery issues common in shared WAN environments.

Tier 5a (Small)

This Tier is more suitable to support individual workloads and applications. Devices in this range have the ability of supporting anywhere from2 Mbps up to 45 Mbps throughput. It should also has the ability of supporting anywhere from 300 to 6,000 concurrent connections. This tier should have the ability to store anywhere between 80 and 400 GB of data and in most cases will be set up in standalone disk drives.

Example hardware would include the Riverbed Steelhead 550, 1050, and 2050 series.

SCLIN 0003AN Category 3 Appliances Tier 5 - Wan Optimizers

This focuses on network WAN optimization and the features required in the datacenter. WAN optimization products seek to accelerate a broad range of applications accessed by distributed enterprise users via eliminating redundant transmissions, staging data in local caches, compressing and prioritizing data, and streamlining chatty protocol. WAN optimization also helps avoid packet delivery issues common in shared WAN environments.

Tier 5b (Medium)

This tier is the largest tier of optimizers and runs a much more robust platform. This tier would be utilized to provide wan optimization services for an enterprise datacenter supporting multiple customer workloads and applications. It is capable of supporting from 90 Mbps up to 1 Gbps in total throughput and support from 7,500 connections to 100,000 connections. This tier should have the ability to store anywhere between 600 GB and 4.4 TB or data and would have the ability to do some sort of Raid configuration to support Storage fault tolerance.

Example hardware would include the Riverbed Steelhead 5050, 6050, and 7050 series.

SCLIN 0003AP Category 3 Appliances Tier 6 - Authentication, Authorization and Accounting (AAA) Security Server or Appliance

The AAA Security Server or Appliance provides centralized authentication, authorization and accounting services for user access to network-based resources. Common features services that manage user access using the RADIUS, LDAP and/or TACACS+ protocols. Systems commonly provide for centralized management and the ability for multiple servers or appliances to be configured to work together using a single user database. Granular management is allowed by applying permission controls to logical grouping of equipment and users. The service can be a software package installed on a physical or virtual server, or a dedication hardware appliance.

Examples of products that perform this function are Juniper Networks Steel-Belted Radius Server Global Enterprise Edition and Cisco Systems Secure Access Control Server (ACS) Solution Engine.

SCLIN 0003AQ Category 3 Appliances Tier 7 - Client VPN Appliance

Client VPN appliances are an essential resource when managing our datacenter resources remotely. This function needs to support the latest features focusing on secure remote connectivity.

Tier 7a (Small)

This tier focuses on the lower capacity models of the client VPN appliances that may be used to access isolated customer enclaves or individual network resources. Although this is a lower end tier the features required will be the same. Features typically found in this tier are: SSL and IPSEC protocol support, AAA support, CAC authentication, and granular access control.

Example hardware models in this tier are: Juniper SA2500 SSL

SCLIN 0003AR Category 3 Appliances Tier 7 - Client VPN Appliance

Client VPN appliances are an essential resource when managing our datacenter resources remotely. This function needs to support the latest features focusing on secure remote connectivity.

Tier 7b (Medium)

This tier addresses the medium sized yet feature rich appliances that could be used on a site to site basis or for large workloads. Features typically found in this tier are: AAA support, CAC authentication, policy based client firewall, clustering, dual redundant power supplies, SSL and IPSEC protocol support, and granular access control.

Example hardware models in this tier are: Juniper SA4500 SSL VPN Appliance, Cisco ASA 5500

SCLIN 0003AS Category 3 Appliances Tier 7 - Client VPN Appliance

Client VPN appliances are an essential resource when managing our datacenter resources remotely. This function needs to support the latest features focusing on secure remote connectivity.

Tier 7c (Large)

This tier encompasses the higher end enterprise class appliances with greater scalability and support for greater number of users, bandwidth, and functionality. Features typically found in this tier are: AAA support, CAC authentication, policy based client firewall, and granular access control.

Example hardware models in this tier are: Juniper SA6500 SSL VPN Appliance

SCLIN 0003AT Category 3 Appliances Tier 8 - Intrusion Detection System

This function of the contract focuses on Intrusion Detection Systems and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 8a (Small)

Tier 8a Intrusion Detection Systems would be the smallest sensor used on the network. They would provide real-time and historical analytics based on vulnerability and anomaly based inspection methods. This data would be aggregated and sent to a central management location for processing. Tier 8a Intrusion Detection Systems should be capable of identifying vulnerabilities as well as reporting real-time security threats. Automatic trend identification and analysis should be a common function of Tier 8a Intrusion Detection Systems. Tier 8a Intrusion Detection Systems would generally support a throughput of approximately 100 Mbps.

Example: SourceFire 3D2000 Sensor

SCLIN 0003AU Category 3 Appliances

This function of the contract focuses on Intrusion Detection Systems and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 8b (Medium)

Tier 8b Intrusion Detection Systems would incorporate all the features of a Tier 8a Sensor however the size of the supported site or enclave would be significantly larger. Tier 8b Intrusion Detection Systems would be used to the perimeter of a large LAN or medium Campus network. Features expected in this tier are: dual redundant power supplies, multiple interfaces, and enterprise management abilities. Expected throughput for a Tier 8b system would be approximately 1 Gbps.

Example: SourceFire 3D3500 Sensor

Average monthly usage 500 Mbps SCLIN 0003AV Category 3 Appliances

This function of the contract focuses on Intrusion Detection Systems and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 8c (Large)

Tier 8c Intrusion Detection Systems would incorporate all the features of Tier 8a and Tier 8b Sensors however the size of the supported site or enclave would be significantly larger. Tier 8c Intrusion Detection Systems would be used at the top of the network topology, likely in a DMZ environment. Features expected in this tier are: dual redundant power supplies, multiple interfaces, and enterprise management abilities. Expected throughput for a Tier 3 system would be approximately 10 Gbps.

Example: SourceFire 3D9900 Sensor

SCLIN 0003AW Category 3 Appliances Tier 9 - Protocol Analyzer

This function describes the requirements needed in a network packet capture and protocol analysis appliance.

Tier 9a (Small)

Tier 9a protocol analyzers allow for verification and analysis of traffic flowing between a multiple number of devices and networks. Features include gathering and analyzing network statistics on bandwidth and response times, protocol analysis to determine application functionality, and protocol analysis to identify anomalous or erroneous traffic types or patterns. It is common for tier 9a devices to capture and identify network intrusion attempts or network misuse by users. Network forensics capabilities are common at this tier as well. The ability to remotely administer the devices allows for ease in troubleshooting issues at remote locations. Devices at this tier also commonly provide detailed protocol analysis enterprise wide to isolate application response time problems across numerous networks. Long term trending analysis is also done at this level to determine the adequacy of network connections and to anticipate future network bandwidth requirements. Tier 9b devices would also have the responsibility of monitoring SLA enforcement for network and application availability as well as application response times. The functions at this level occur across multiple networks and physical locations. Interface speeds for these devices are usually less than 8 Gbps.

Example systems in this tier are: Netscout Infinistream 2900 series appliances, Wildpackets Omnipliance Edge, or Niksun NetVCR appliances.

SCLIN 0003AX Category 3 Appliances Tier 9 - Protocol Analyzer

This function describes the requirements needed in a network packet capture and protocol analysis appliance.

Tier 9b (Medium)

This level includes all of the functions listed under Tier 9a while supporting interface speeds and capture rates at or above 8 Gbps.

Example systems in the tier are: Netscout Infinistream 6900 series, Wildpackets Omnipliance Core w/ OmniAdapter 10G.

CLIN 0004 Category 1 Switches OCONUS

Category 1 of this contract focuses on network switch technology and the features required in a datacenter.

SCLIN 0004AA Category 1 Switches Tier 1a (Small)

This tier is the lowest category of switch used on this contract. This type of switch would be classified as an access layer switch used for layer 2 connectivity in the data center. This switch needs to support the data center class requirements but remain cost effective enough to be deployed on a larger scale. Features typically found in this class of switch would be: port channeling, modular expansion for uplinks, port security, layer 2 access control, dual redundant power supplies, multicast, and port mirroring.

Size: 1 Gbps Port Example hardware models in this tier are: Cisco 4948, Juniper EX4200 SCLIN 0004AB Category 1 Switches Tier 1b (Small)

This tier is the lowest category of switch used on this contract. This type of switch would be classified as an access layer switch used for layer 2 connectivity in the data center. This switch needs to support the data center class requirements but remain cost effective enough to be deployed on a larger scale. Features typically found in this class of switch would be: port channeling, modular expansion for uplinks, port security, layer 2 access control, dual redundant power supplies, multicast, and port mirroring.

Size: 10 Gbps Port Example hardware models in this tier are: Cisco 4948, Juniper EX4200

SCLIN 0004AC Category 1 Switches Tier 2a (Medium)

This tier encompasses the switch models that meet the typical data center class layer 2 switching requirements found in the aggregation layer. This category contains the features found in the tier 1 class switches as well as some of the features found in the tier 3. This type of switch has the ability to switch network traffic at a high rate of speed, provide redundant configurations, and remain scalable. Features typically found in this class of switch would be: Port channeling, hot swappable modules, multicast, port mirroring, dual redundant power supplies, port security, and IPv6.

Size: 1 Gbps Port Example hardware models in this tier are: Cisco 4506, Juniper EX4500

SCLIN 0004AD Category 1 Switches Tier 2b (Medium)

This tier encompasses the switch models that meet the typical data center class layer 2 switching requirements found in the aggregation layer. This category contains the features found in the tier 1 class switches as well as some of the features found in the tier 3. This type of switch has the ability to switch network traffic at a high rate of speed, provide redundant configurations, and remain scalable. Features typically found in this class of switch would be: Port channeling, hot swappable modules, multicast, port mirroring, dual redundant power supplies, port security, and IPv6.

Size: 10 Gbps Port Example hardware models in this tier are: Cisco 4506, Juniper EX4500

SCLIN 0004AE Category 1 Switches Tier 3a (Large)

This tier encompasses the higher end switches that would typically be found in a Data Center, Enterprise, or Core device classes. These devices are not only capable of supporting greater throughput and meeting higher density port requirements but also have the features and options of supporting the latest technologies found in an enterprise class network. This type of switch will need to support high availability, operational simplicity, and have the scalability to meet the requirements of a cutting edge IT switch. Features typically found in this class of switch would be: Port channeling, VLAN management, high throughput, hot swappable modules, hardware acceleration, dual redundant power supplies, IPv6 Quality of Service (QOS), and virtualization.

Size: 1 Gbps Port Example hardware models in this tier are: Cisco 6513, Cisco 6509, and Juniper EX8200

SCLIN 0004AF Category 1 Switches Tier 3b (Large)

This tier encompasses the higher end switches that would typically be found in a Data Center, Enterprise, or Core device classes. These devices are not only capable of supporting greater throughput and meeting higher density port requirements but also have the features and options of supporting the latest technologies found in an enterprise class network. This type of switch will need to support high availability, operational simplicity, and have the scalability to meet the requirements of a cutting edge IT switch. Features typically found in this class of switch would be: Port channeling, VLAN management, high throughput, hot swappable modules, hardware acceleration, dual redundant power supplies, IPv6 Quality of Service (QOS), and virtualization.

Size: 10 Gbps Port Example hardware models in this tier are: Cisco 6513, Cisco 6509, and Juniper EX8200

CLIN 0005 Category 2 Routers OCONUS Routers are specialized hardware-based network communications devices that interconnect two or more computer networks and selectively interchange packets of data between them.

SCLIN 0005AA Category 2 Routers

Tier 1a (Small): 4 Gbps or less of aggregate data passed through the device

A small router is typically optimized for lower performance needs, such as use within a branch or small office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4 and IPv6, using open-standards based routing protocols such as OSPF and BGP, and provide packet filtering capabilities using access-control lists. Minimal scalability through additional line cards to allow for interface expansion. Redundancy of power input is common in this tier of router. Routers in this tier typically pass 4 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 1 Gbps Port Examples of routers in the medium tier include Cisco 3900 series Integrated Services Routers and Juniper J6350 3D Universal Edge Router.

SCLIN 0005AB Category 2 Routers

Tier 1b (Small): 4 Gbps or less of aggregate data passed through the device

A small router is typically optimized for lower performance needs, such as use within a branch or small office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4 and IPv6, using open-standards based routing protocols such as OSPF and BGP, and provide packet filtering capabilities using access-control lists. Minimal scalability through additional line cards to allow for interface expansion. Redundancy of power input is common in this tier of router. Routers in this tier typically pass 4 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 10 Gbps Port Examples of routers in the medium tier include Cisco 3900 series Integrated Services Routers and Juniper J6350 3D Universal Edge Router.

SCLIN 0005AC Category 2 Routers

Tier 2a (Medium): 100 Gbps or less of aggregate data passed through the device –

A router in the medium tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and 10 Gbps interface availability. Medium tier devices typically exhibit significant scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 100 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 1 Gbps Port Examples of routers in this medium tier include Cisco 7200 Series and Juniper MX80 3D Universal Edge routers.

SCLIN 0005AD Category 2 Routers

Tier 2b (Medium): 100 Gbps or less of aggregate data passed through the device –

A router in the medium tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and 10 Gbps interface availability. Medium tier devices typically exhibit significant scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 100 Gbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 10 Gbps Port Examples of routers in this medium tier include Cisco 7200 Series and Juniper MX80 3D Universal Edge routers.

SCLIN 0005AE Category 2 Routers

Tier 3a (Large): 2 Tbps or less of aggregate data passed through the device

A router in the large tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and multiple 10 Gbps interface availability. Large tier devices typically exhibit robust scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 2 Tbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 1 Gbps Port Examples of routers in the large tier include Cisco 7600 Series and Juniper MX480 3D Universal Edge routers.

SCLIN 0005AF Category 2 Routers

Tier 3b (Large): 2 Tbps or less of aggregate data passed through the device

A router in the large tier is typically optimized for performance needs, such as use within a medium to large office setting. Features of routers in this tier include the routing of multiple communications protocols, including IPv4, IPv6 and MPLS, using open-standards based routing protocols such as OSPF and BGP, packet filtering capabilities using access-control lists, quality of service tagging, hardware encryption and multiple 10 Gbps interface availability. Large tier devices typically exhibit robust scalability to allow for new capabilities and interface expansion through the installation of additional line cards and modules. Redundancy of hardware through the installation of secondary line cards and redundant power supplies are common in this tier of routers. Routers in this tier typically pass 2 Tbps or less of aggregate data through the device when averaged across a 30 day period.

Size: 10 Gbps Port Examples of routers in the large tier include Cisco 7600 Series and Juniper MX480 3D Universal Edge routers.

CLIN 0006 Category 3 Appliances OCONUS

Application-level gateways are devices or specialized operating environments in a virtualized environment that provide protection to certain application-layer “control/data” protocols such as HTTP, HTTPS, DNS, XML and/or FTP, while commonly providing load balancing capabilities as well.

SCLIN 0006AA Category 3 Appliances

Tier 1 - Application-level gateway

Tier 1a (Small)

Small application-level gateways provide basic application protection, caching and/or load balancing functionalities at the enclave level. These are typically deployed directly in front of the servers they are supporting. Features include basic caching, protocol acceleration, load balancing, and application-layer communications protection. SSL termination is typically not required at this tier. Automatic configuration synchronization between redundant pairs of devices is common at this level. Remote management, redundant power and traffic monitoring are common as well.

Examples include the F5 Networks BigIP LTM VE, the Blue Coat ProxySG 210 series.

SCLIN 0006AB Category 3 Appliances

Tier 1 - Application-level gateway

Tier 1b (Large)

The large tier of application-level gateways provides application protection and load balancing at datacenter, DMZ or global levels. Are typically deployed at the perimeter of the network and provide caching, protocol acceleration, load balancing and application-layer communications protection services to multiple workloads at one or more sites. SSL offload is often required at this level using FIPS 140-2 compliant equipment. Large tier application-level gateways often offer DNS components to allow for load balancing across multiple sites.

Examples of large tier devices include F5 Networks BigIP LTM / GTM 6900, the Blue Coat ProxySG 8100 series, Cisco ACE XML Gateway, and Cisco ACE GSS 4400 series.

SCLIN 0006AC Category 3 Appliances

Tier 2 - Firewall

A firewall is a software based application suite or hardware based network appliance designed to permit and/or deny access to a network, enclave or data center based upon configured rules. Basic features common to each proceeding tier are high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.), cost effective bandwidth capability, and cost effective simultaneous connection support.

Tier 2a (Small)

Firewall servers or devices at this tier are expected to protect a small enclave or network using a limited sized ruleset in support of a limited number of applications, servers and/or devices. Devices in this tier typically reside in the access layer in the hierarchical internetworking model. Features included in this tier include high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.). Redundant power paths are also common.

Example Hardware: Cisco ASA 5505 or 5510, Juniper Netscreen 5200

SCLIN 0006AD Category 3 Appliances

Tier 2 - Firewall

A firewall is a software based application suite or hardware based network appliance designed to permit and/or deny access to a network, enclave or data center based upon configured rules. Basic features common to each proceeding tier are high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.), cost effective bandwidth capability, and cost effective simultaneous connection support.

Tier 2b (Medium)

Firewalls in this tier typically support multiple enclaves and networks and therefore the servers support multiple customers and applications. Features included in this tier commonly include all the features outlines in tier 2a above, plus virtualization capabilities, high availability, IDS capabilities, multiple site-to-site VPN connection termination, high-speed network interface connections (up to 1 Gbps per interface), and are commonly scalable to include increased capabilities and new technologies through the installation of line cards or modules. Devices in this tier typically reside in the aggregation or distribution layers of the network.

Example firewalls in this tier include Cisco ASA 5520 and 5540 models and Juniper Netscreen 5200 or ISG1000 devices.

SCLIN 0006AE Category 3 Appliances

Tier 2 - Firewall

A firewall is a software based application suite or hardware based network appliance designed to permit and/or deny access to a network, enclave or data center based upon configured rules. Basic features common to each proceeding tier are high availability, NAT/PAT, application layer filtering, stateful TCP and UDP connections and packet inspection, smart application protocol support (port redirection for FTP, SQLnet, RTSP, DNS, etc.), cost effective bandwidth capability, and cost effective simultaneous connection support.

Tier 2c (Large)

Tier 2c is described as the high performance security device or server that protects entire data centers or large enterprise networks. This level device should support features included in the tiers above, plus upgradable hardware, support for multiple high speed network interface cards (1 Gbps or faster) , and are commonly scalable to include increased capabilities and new technologies through the installation of line cards or modules. Devices in this tier typically reside at the core layer of the network.

Example Hardware: Cisco ASA 5550 or 5580, Juniper Netscreen 5400 or ISG2000

SCLIN 0006AF Category 3 Appliances

Category 3; Tier 3 of this contract focuses on Intrusion Detection System and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 3a (Small)

Tier 3a Intrusion Detection Systems would be the smallest sensor used on the network. They would provide real-time and historical analytics based on vulnerability and anomaly based inspection methods. This data would be aggregated and sent to a central management location for processing. Tier 3a Intrusion Detection Systems should be capable of identifying vulnerabilities as well as reporting real-time security threats. Automatic trend identification and analysis should be a common function of Tier 3a Intrusion Detection Systems. Tier 3a Intrusion Detection Systems would generally support a throughput of approximately 100 Mbps.

Example: SourceFire 3D2000 Sensor

SCLIN 0006AG Category 3 Appliances

Category 3; Tier 3 of this contract focuses on Intrusion Detection System and the features required in a datacenter. Intrusion Detection Systems are essential to a secure and confidential computing environment.

Tier 3b (Medium)

Tier 3b Intrusion Detection Systems would incorporate all the features of a Tier 3a Sensor, however the size of the supported site or enclave would be significantly larger. Tier 3b Intrusion Detection Systems would be used to the perimeter of a large LAN or medium Campus network. Expected throughput for a Tier 3b system would be approximately 1 Gbps.

Example: SourceFire 3D3500 Sensor

SCLIN 0006AH Category 3 Appliances

Category 3; Tier 3 of this contract focuses on Intrusion Detection System and the features required in a datacenter.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .