CMPP_Telecommunications__Requirements_Appendix_DV3.docx

DOCX document 33 KB Posted

Attached to
Award Notice - Central Meat Processing Plant Federal contract opportunity
Solicitation number
HQC007-17-Q-0023
Issued by
Defense Commissary Agency

About this file

Appendix D - Telecommunication Requirements

View the file

Other files for this federal contract opportunity

Other files attached to Award Notice - Central Meat Processing Plant, newest first.
File Type Posted
CMPP_PWS_V5.FBO_rev1.pdf PDF
HQC007-17-Q-0023-0006.FBO.pdf PDF
CMPP_Technical_Requirements_-_Appendix_BV4_FBO-Rev2.pdf PDF
HQC007-17-Q-0023-0005.FBO.pdf PDF
CMPP_Technical_Requirements_-_Appendix_BV4.FBO-Rev1.pdf PDF
HQC007-17-Q-0023-0004.FBO.pdf PDF
HQC007-17-Q-0023-0003.FBO.pdf PDF
HQC007-17-Q-0023-0002.FBO.pdf PDF
HQC007-17-Q-0023-0001.FBO.pdf PDF
HQC007-17-Q-0023.FBO.pdf PDF
HQC007-17-Q-0023_draft_8.3.17.pdf PDF
CMPP_Technical_Requirements_-_Appendix_BV3.docx DOCX document
CMPP_Functional_Requirements_Appendix_AV3.docx DOCX document
CMPP_Cyber_Security_Requirements_Appendix_CV3.docx DOCX document
CMPP_PWS_V3.docx DOCX document
Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Appendix DTelecommunications RequirementsD-2
D.1Network IntegrationD-2
D.1.1InterfacesD-2
D.2Local Area Network (LAN) ConnectivityD-2
D.3Wireless LAN (WLAN) ConnectivityD-2
D.3.1Wireless IntegrationD-2
D.3.1.1Wireless StandardsD-2
D.3.1.2RF Data EncryptionD-2
D.3.1.3Hand-Held IntegrationD-3
D.4Centralized Fault and Performance ManagementD-3
D.4.1System & Application Service MonitorsD-3
D.4.2DeCA CIC hierarchyD-3
D.5Remote Support RequirementsD-3
D.5.1PCs/Workstation configurationsD-4
D.6Existing and Planned Network ConfigurationsD-4
D.7Equipment Cabinets (19” RACK MOUNT)D-5
D.8Cabling RequirementsD-5
D.9Commercial Internet and Military Network (MILNET) AccessD-5
D.10Government Furnished Equipment and InformationD-5

Telecommunications Requirements Network Integration The DeCA CMPP facility will be in Ramstein, Germany. The software will operate at DeCA HQ in Kapaun, Germany with backup/failover capabilities. The system shall also support secured web-based data submissions from commissaries throughout the DeCA European Area commissaries. All telecommunications shall be through DeCA’s wide-area network (DeCANet). See Department of Defense Directive 8100.2, Use of Commercial Wireless Devices, Services and Technologies in the DoD Global Information Grid (GIG), April 14, 2004. The contractor shall provide all the hardware and software required to integrate the CMPP system into DeCA's network, unless otherwise specified in this document.

Interfaces All equipment that interfaces with the CMPP system software shall have a TCP/IP interface. TCP/IP must be IPv4 and compatible with IPv6 in order to meet DoD and Office of Personnel Management (OPM) requirements.

Local Area Network (LAN) Connectivity Typical LAN connectivity is through a Fast Ethernet backbone and the site WLAN. Equipment connected to the LAN must be capable of operating at a minimum 100MBPS (100baseT) with flexibility to operate at 1000MBPS (1000baseT, gigabit copper), if desired. NICs must have configuration settings available to disable auto-sensing of speed, full/half duplex selection, and flow-control negotiation.

Wireless LAN (WLAN) Connectivity WLAN connectivity conforms to the following specifications: DeCA’s current wireless infrastructure supports both wireless bands, 802.11a and 802.11g. CMPP wireless devices shall support both IEEE 802.11a and IEEE 802.11g bands, be Wi-Fi CERTIFIED and support both Wi-Fi Protected Access II (WPA2) and IEEE 802.11i standards. CMPP wireless devices shall support both Dynamic Host Configuration Protocol (DHCP) and statically (manually) assigned IP addresses.

Wireless Integration All wireless devices associated with the CMPP system shall be Wi-Fi CERTIFIED, support both 802.11g 2.4GHz band and 802.11a 5GHz band, support Wi-Fi Protected Access II (WPA2) and IEEE 802.11i standard. The offeror shall be responsible for all integration and support all wireless devices proposed under this contract.

Wireless Standards All wireless systems in the CMPP system shall conform to the Wi-Fi CERTIFIED standard, Wi-Fi Protected Access II (WPA2) standard, IEEE 802.11i standard, 802.11g 2.4GHz band and 802.11a 5GHz band standards. The CMPP system shall satisfy all Deutsche Industry Norm (DIN) regulations, meet Restriction of Hazardous Substances Directive (RoHS 1), and all German Accident Prevention Regulations (UVV) and German Electrical Standards and Regulations (VDE).

RF Data Encryption All RF data used by the CMPP system shall be encrypted. All devices connected wirelessly shall support IEEE 802.11i/WPA2 standard and use Advanced Encryption Standard (AES) to encrypt traffic and must be compatible with or not interfere with DeCA’s WLAN infrastructure. Refer to PGP IT-2 for further guidance.

Hand-Held Integration Comment by Croom, Jim CIV (US) DeCA HQ LEIP: Ask Scott..

Hand-held units shall be connected by WLAN to the network and be capable of online picking and integration with hand-held devices (used for scanning bar codes and label printing).

Centralized Fault and Performance Management The CMPP system shall integrate into DeCA’s Cisco Information Center (CIC) Manager of Managers (MOM) architecture. The system servers must run the System Service Monitor (SSM) agent. The contractor shall perform the integration of this requirement into its solution. It also shall assist with integrating its solution into the Government’s CIC architecture with the guidance of Government personnel. Comment by Croom, Jim CIV (US) DeCA HQ LEIP: Ask SCott System & Application Service Monitors Regional CIC System Service Monitors and Application Service Monitor (SSM/ASM) CMPP support servers shall be installed at DeCA Europe Kapaun Server Center. Servers and applications shall be configured to provide operational redundancy and failover capability.

DeCA CIC hierarchy Servers shall report to DeCA’s CIC hierarchy. Servers shall also report to the new system’s support center, as required.

Remote Support Requirements

The contractor shall provide for remote access support for DeCA’s CMPP system based on the following. This access will also provide the basis for forwarding server alerts to the vendor’s support center if needed. The vendor shall:

1. Meet DeCA Cybersecurity requirements for user access

1. Assist with the establishment of an Enclave Security Memorandum of Agreement (MOA)

1. Select one of two architectures for remote support access:

2. Option 1: VPN tunnels between vendor and DeCA

0. Terminates in commercial Internet VPN concentrator Dual homed to DeCA HQ and DeCA West

0. Requires authentication in DeCA proxy gateway server

0. Provides terminal services access

0. Access to NIPRNET via DeCA is blocked

2. Option 2: DeCA network node in contractor facility Vendor purchases circuits and bills DeCA

1. Circuits connect “outside” DeCA’s enclave firewall Dual homed to DeCA HQ and DeCA West

1. Node and LAN managed by DeCA

1. Only DeCA equipment installed on the LAN

1. Vendor staff must authenticate on DeCA’s network via Active Directory

1. Access to NIPRNET via DeCA is blocked PCs/Workstation configurations Contractor installed PCs at the CMPP that will access the CMPP application on Kapaun, Germany Server Center shall: Comment by Croom, Jim CIV (US) DeCA HQ LEIP: Ask Scott

0. Operate on a LAN segment

0. Connect to the application using a terminal emulation package Comment by Croom, Jim CIV (US) DeCA HQ LEIP: Why ??

Existing and Planned Network Configurations The CMPP system shall comply with the standards listed in Table D1, and those outlined under DoD’s Information Assurance requirements, including Ports, Protocols, and Services (PPS).

Table D1 Mandated IT Standards Applicable to CMPP

Network Service/Support Area
Standard
Bootstrap protocol
Bootstrap Protocol (BOOTP)
Configuration information transfer
Dynamic Host Configuration Protocol (DHCP)
Cryptographic modules
Federal Information Processing Standards Publication 140-2, Security Requirements for Cryptographic Modules (May 2001)
Data transfers
Extensible Markup Language (XML)
Directory services
Lightweight Directory Access Protocol (LDAP) Domain Name System (DNS)
Electronic mail
Simple Mail Transfer Protocol (SMTP)
Evaluation criteria
Common Criteria the International Organization for Standardization (ISO)/ the International Electro technical Commission (IEC) 15408:1999
File transfer
File Transfer Protocol (FTP) not authorized, must use secure copy (Secure Shell (SSH) or Secure Sockets Layer (SSL) versions, Secure FTP(SFTP), and Secure Copy (SCP))
Local Area Network (LAN) access
IEEE 802.3 (Ethernet, Fast Ethernet, Gigabit Ethernet)
Network and systems management
Simple Network Management Protocol (SNMP) minimum Version 3

Telecommunications Management Network (TMN) Framework

Network services
Internet Protocol (IP) Version 4, compatible with Version 6
Network time synchronization
Network Time Protocol (NTP)
Secure Web browsing
Secure Sockets Layer (SSL) Protocol
+TCP/IP
Must operate with Version 4 and be capable of using Version 6 when required
Telnet
Use of standard clear-text telnet is not authorized; must use secure shell version 2(SSHv2)
Terminal services or equivalent
Must be encrypted and require strong user authentication
Transport services
Transmission Control Protocol (TCP) User Datagram Protocol (UDP)
Web services
See Secure Web Browsing Uniform Resource Locator (URL) Uniform Resource Identifier (URI)
Wireless Local Area Network (WLAN)
IEEE 802.11g, IEEE 802.11a, IEEE 802.11i, Wi-Fi CERTIFIED, WPA2, and AES.

Equipment Cabinets (19” RACK MOUNT) The Government will not provide equipment racks and cabinets to support the CMPP solution-specific equipment. Vendors shall advise the Government of their rack space requirements with their solution and provide their plan for installing their rack mount equipment throughout the facility as dictated by their solution. The vendor shall be responsible for providing the cabling needed to link their solution into the Government’s network infrastructure based on consultation with an appropriate Government representative. They shall also provide suitable cabling to tie their solution together.

Cabling Requirements Though it is tailored for a commissary (store) environment, wiring and cabling standards will be followed by DeCA’s NetCom standards for its locations.

Commercial Internet and Military Network (MILNET) Access CMPP will operate in a protected networking environment and will not have direct access to the commercial Internet or MILNET.

Government Furnished Equipment and Information

The Government will provide cleared contractor personnel with terminals and logins to access DeCA systems through the DeCANET. While accessing the DeCANET, contractor personnel shall meet DeCA IA requirements for user access and assist with the establishment of an enclave security MOA. Contractor personnel working on-site will be provided work space and computer equipment necessary to perform the tasks under the contract. Upon completion or termination of this contract, all Government property and equipment provided to the contractor shall be returned.

DeCA provides telecommunications hardware for all DeCA locations. Equipment installed as part of the DeCA site telecommunications infrastructure includes, but is not limited to, the following:

1. Cisco routers: stores/CDCs: models 2621, 4300, 3900, server support centers: 6509 and all models used at stores.

1. Cisco switches: stores/CDCs: models 2960x, 2960s (stores), server & support centers: 6509 and all models used at stores.

1. Cisco Access Points: models 1142n, 1242g, 2602i/e, 2702i/e.

1. CSU/DSUs: as provided by transport service providers. Equipment cabinet-primary: 19” rack-mount, with doors.

1. Equipment cabinet-secondary (at some locations): 19” rack-mount, with doors.

1. Cisco Information Center (CIC): Object Server, Precision, WebTop, Reporter, Remedy Gateway, Internet Service Monitors, System Service Monitors, Applications Service Monitors, and others as they are installed.

D-6

File details come from the government source that posted it. Updated .