M0026322Q1004 U0001.docx
DOCX document 32 KB Posted
- Attached to
- Web Security Proxy Federal contract opportunity
- Solicitation number
- M0026322Q1004
- Issued by
- United States Marine Corps
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| M0026322Q1004 Web Security Proxy.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
M0026322Q1004
SECTION SF 30 BLOCK 14 CONTINUATION PAGE
SUMMARY OF CHANGES
SECTION L - INSTRUCTIONS, CONDITIONS AND NOTICES TO BIDDERS
The following have been added by full text:
ATTACHMENT I - Q&A
1. The RFQ says high availability (HA) which means a pair of devices but the qty on the RFQ says 1. Can you please confirm the qty?
Yes 1 qty, HA capability will ensure that if and when future capacity need increases we will have the capability in place to deploy HA if needed.
2. Are you open to a cloud-native, SaaS web proxy and secure access solution? If so, what FedRAMP and/or DISA Impact Level certifications are required?
All requirements have been laid out in the RFQ.
3. How many users traffic would be protected by this solution? Need to know for licensing estimates of an inline proxy solution that sits between users and the internet/SaaS/private apps.
3500 concurrent sessions
4. Are you open to a combined solution from two different software vendors?
Yes, if that helps meet the objectives listed in the RFQ.
5. Does the solution need to support ad hoc file hash submissions for reputation scoring, or will inline detection, sandboxing/detonation, and blocking of malicious files meet this requirement?
All requirements have been laid out in the RFQ. Please review.
6. Besides WCCP, will other methods of transparent mode deployments be considered?
All requirements have been laid out in the RFQ. Please review. The RFQ mentions explicit mode, web proxy auto discovery in addition to wccp.
7. Can you elaborate on the term "file security schemes?"
Proxy re-encryption schemas is an example of file security schemes.
RFQ Reference: Statement of Work, Section 3.1 Objective 1 – Device
8. NIAP no longer evaluates against Evaluation Assurance Levels (EAL) and has transitioned to NIAP-approved Protection Profile instead. Is this acceptable since no proxy solutions currently exist under the EAL rating of 2+?
Only considering products that are capable of being configured for minimum CC EAL requirement.
9. Does the Marine Corps require the solution to be a High Availability (HA) configuration?
Yes, have the capability of High Availability
10. How many users should the solution be designed to support?
3500 concurrent sessions
11. Does the Marine Corps require a management component to be included with the solution?
If a management component is needed in order to meet the objectives listed, then yes.
12. RFQ Reference: Statement of Work, Section 8.0 Period of Performance The referenced section indicates “Upon date of contract award, the contractor shall contact the Government POC for the scheduling of all work.” Previous sections do not mention a requirement for installation, integration, and training support, yet the referenced section indicates that the Marine Corps may require those services. Please clarify.
The referenced section does not state that installation, integration and or training support is required. The ‘scheduling of all work’ is referring to all that’s required to get a solution delivered to MCRC that meets the objects listed in RFQ.
13. Regarding LB'ing requirements, are there preferred or required topologies L2/L3/Hybrid/DSR? Is there a list of protocols that require layer specific persistence?
The objective is that the solution has capability to LB, no requirement on how it goes about doing it as long as LB capability can be achieved if needed.
14. Regarding explicit and transparent proxy (WCCP). Does this requirement only pertain to DC or private cloud? Public cloud transparent mode requires a degree of control over the vswitch which few cloud providers allow.
The objective is that the solution has capability to offer WCCP.
15. Certain requirements, like "fail open" pertain to hardware-based solutions. Will the selected solution be expected to deliver all requirements on both hardware and virtual? - or has the delivery platform not been fully determined?
The listed objective can be achieved by hardware and or virtual for packet or system failures. As long as the proposed solution has a way of addressing this objective.
(End of Summary of Changes) image1.wmf
File details come from the government source that posted it. Updated .