Statement_of_Work.docx
DOCX document 163 KB Posted
- Attached to
- IT EQUIPMENT: ENTERPRISE CONVERGED PLATFORM Federal contract opportunity
- Solicitation number
- SAQMMA14R0308
About this file
Section C Attachment - Statement of Work
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFP SAQMMA14R0308
SECTION C: STATEMENT OF WORK
1. PURPOSE
The Enterprise Converged Platform (ECP) contract will provide the Department of State with innovative technical solutions capable of achieving the Bureau of Information Resource Management’s (IRM) equipment life-cycle refresh goals for Information Technology (IT) core infrastructure worldwide.
2. BACKGROUND
The Department of State’s enterprise IT infrastructure, services, applications and information enable and empower front-line diplomats to carry out U.S. foreign policy and development priorities. The Department’s IT Strategic Plan (Fiscal Years 2014-2016) outlines the Department’s vision of positioning secure IT as a critical enabler of U.S. diplomacy and the protection of national and economic security.
To support this vision, IRM provides IT infrastructure in the form of storage, computing, and networking for domestic and overseas locations. The design, build, support and management of these infrastructure resources are managed through a consolidated effort between IRM’s Enterprise Server Operations Centers (ESOC) Division, responsible for Domestic Data Centers, and the Global Information Technology Modernization Division (GITM), responsible for Remote Offices to include overseas posts and domestic offices. These two entities collaborate on all aspects of the worldwide centralized IT core infrastructure implementation.
Current advances in technology, including converged systems, have resulted in a requirement for the ECP contractor(s) to provide a robust technical solution focused on core equipment life-cycle refresh for two separate but related segments of the worldwide infrastructure:
· Domestic Data Centers defined as Tier 3 data centers (See Glossary) located in the continental U.S.
· Remote Offices defined as 1) overseas posts, and 2) Department offices located in the continental U.S.
The converged infrastructure packages multiple IT components into a single, optimized computing solution defined as the ECP. ECP components include servers, data storage devices, networking equipment and software for IT infrastructure management. The physical components will be preloaded with software as defined in the delivery order, packaged and prepared for shipment by the ECP contractor(s). Implementation of the ECP solution is focused on ease of assembly, network/domain integration and smooth data migration.
3. SCOPE
The ECP contractor(s) shall develop technical solutions (hardware and software) for Department Domestic Data Centers and Remote Offices. The ECP technical solution will be preconfigured to include: racks, servers, switches, storage, local back-up and data offshoring solutions for Disaster Recovery (DR), Uninterrupted Power Supply (UPS), computing and networking components, management utilities for configuration and any necessary wiring. All solutions will be designed to be as energy-efficient as possible without affecting system performance. The ECP contractor(s) shall provide a standardized ECP solution with customized components, based on location specific requirements. The installation of, and training on, the ECP solution are also to be provided by the ECP contractor(s) under this contract.
Note: This document uses “system” and “solution” interchangeably to refer to the ECP products and services delivered under this solicitation.
4. TECHNICAL REQUIREMENTS OF THE ECP SOLUTION
This section of the SOW describes the Government’s Technical requirements in three areas:
· Common Technical requirements, which apply to both the Domestic Data Center and the Remote Offices solutions;
· Domestic Data Center Technical requirements, which apply to Tier 3 (three) data centers in the continental U.S.; and
· Remote Offices Technical requirements, which apply to 1) overseas posts, and 2) Department offices located in the continental U.S.
Additional background information on Enterprise Server Operations Center (ESOC) and the Domestic Data Centers are contained in Attachment J-2 (ESOC and GITM Overview).
4.1 Common Technical Requirements
This section contains common technical requirements that apply to both the Domestic Data Centers and the Remote Offices. The following requirements shall be met by the ECP contractor(s).
4.1.1 Innovation
The Department requires innovative ECP solution(s) that address our IT core infrastructure requirements, reduce IT infrastructure life-cycle costs, achieve efficiencies through standardization, increase existing system reliability and capability; yet provide scalable solutions that incorporate emerging technology, while still providing growth potential for future enhancements. In addition, the Government seeks to reduce the core operating physical footprint. The ECP solution shall:
· Consolidate present-day separate technical support structures for storage, compute, and networking into a single support portfolio (i.e. a single Tier 4 toll-free vendor provided support center);
· Manage multi-tiered vendor provided support through a “single pane of glass” with role based views;
· Standardize core IT infrastructure that incorporates innovative technologies capable of scaling to meet evolving and emerging business requirements;
· Provide a scalable solution capable of adding storage, compute, networking nodes as demand grows;
· Be simple and straightforward to install, migrate, administer, and maintain, e.g.; plug-and-play.
· Reduce the hardware footprint at sites where space is at a premium.
4.1.2 General Systems Requirements
· The contractor(s) shall provide an ECP solution capable of interfacing with the existing Department of State network infrastructure, running a virtualized environment with the intended load, handling international power and fitting within Department of State rack requirements.
· The contractor(s) ECP solution shall be easy to assemble and plug into the network, point the solution to the existing data and seamlessly replace the existing system with the new one.
· The ECP solution shall include all software necessary to initially boot, connect, and migrate data. Any issues encountered during this process should be easily diagnosed and fixed using contractor(s)-provided documentation.
· All system added features (i.e. options) will be Original Equipment Manufacturer (OEM)-certified.
· The contractor(s)’s solution shall not include a platform with embedded Bluetooth ®, infrared technology, wireless technology, webcam, GPS modules, “anti-theft technology,” and “Active Management Technology (AMT)”. Further, the contractor(s)’s platform provided under this contract shall exclude all explicit tracking and automatic update capabilities (e.g., no Absolute Basic Input/Output System (BIOS)) unless specified.
· All hardware and software of “silent” reach-back capabilities to OEM or third party vendors shall be hard-disabled by the contractor(s). There will not be any automatic unauthorized remote data transfer or automatic update without a customer acknowledgement or confirmation process.
· Whenever the OEM and/or ECP contractor implements modifications to the ECP solution(s), the Government reserves the right to thoroughly evaluate, test and/or inspect all solutions (models, Central Processing Units (CPU), chipsets, etc.) before issuing any delivery order for the modified equipment.
· Workmanship will be in accordance with best commercial practice and accepted industry standards.
· All equipment provided by the contractor(s) under this contract shall be new and warranted as such. Used, refurbished or gray market (i.e., goods acquired through distribution channels other than those authorized or intended by the contractor) products will not be allowed.
· Solutions must be interoperable with the Department of State’s current core infrastructure.
· The base configuration will contain the contractor(s) prescribed migration software tools, VMware vSphere Hypervisor, and a Department of State approved version of firmware(s). The base configuration will be manageable and deployable from a central location. The solution will support the virtual machine servers configured with Server 2008 or later.
· Rack: Department of State server rooms are space-constrained, and the ECP solution must accommodate limited space availability as it replaces existing racks. The contractor(s)’s provided ECP solutions shall comply with the maximum dimensions for a server rack listed below.
| Dimension |
| Maximum |
| Height |
| 80” |
| Depth |
| 54” |
| Width |
| 30” |
| Weight |
| 400 lbs |
The contractor shall provide all cabling interconnecting the ECP solution and it shall be clearly labeled at each end of every cable, identifying component endpoints. The contractor is not required to provide any data cabling external to the ECP solution.
4.1.3 Networking
Networking must be consistent and compatible from the Domestic Data Center to the Remote Office. Below is a list of the common networking requirements which the contractor(s)’s solution shall satisfy; additional specifications for the Domestic Data Center and the Remote Offices are found in sections 4.2.2 and 4.3.2 respectively.
Department of State currently has an IPv.4 based network with a variety of network technologies. All contractor-provided ECP equipment requiring network access shall support both IP v.4 and IP v.6. The contractor(s)’s ECP solution shall connect to the existing Department of State networks.
| Specification |
| Requirement |
| Connectivity |
| The solution will have Broad connectivity support including Gigabit Ethernet (GE), 10 GE, 10GBase-T, 40 GE, Fibre Channel (FC) and FC over Ethernet (FCoE). |
The solution will have the ability for an Ethernet module that provides 1/10 GE and FCoE ports using the Small Form Factor Pluggable Plus (SFP+) interface.
The solution will have the ability for a FC plus Ethernet module that provides1/10 GE and FCoE ports.
| Supported Layers |
| The solution will support comprehensive Layer 2 and 3 features for Local Area network (LAN) and Storage Area Network (SAN) traffic. |
| Configuration |
| Institute of Electrical & Electronics Engineers (IEEE) 802.1Q Virtual LAN (VLAN) encapsulation. |
Support for up to 4096 VLANs.
Link Aggregation Control Protocol (LACP): IEEE 802.3ad.
Advanced PortChannel hashing based on Layer 2, 3, and 4 information.
Jumbo frames on all ports (up to 9216 bytes).
Private VLANs.
Private VLAN over trunks (isolated and promiscuous).
Private VLANs over vPC and EtherChannels.
VLAN Remapping.
Layer 2 IEEE 802.1p Class of Service (CoS).
Per-port Quality of Service (QoS) configuration.
Modular QoS Command Line Interface (CLI) Modular QoS CLI (MQC) compliance – Internet Protocol (IP)v4 and IPv6.
Access Control List (ACL)-based QoS classification (Layer 2).
Standard and extended Layer 2 ACLs: MAC addresses, protocol type, etc.
VLAN-based ACLs (VACLs).
Port-based ACLs (PACLs).
IPv6 capability.
In-Service Software Upgrade (ISSU) for Layer 2.
Hot-swappable field-replaceable power supplies, fan modules, and expansion modules.
1:1 power redundancy.
N:1 fan module redundancy.
Configuration rollback.
Secure Shell Version 2 (SSHv2).
Telnet.
Authentication, Authorization and Accounting (AAA) Network Security.
| Management |
| AAA with Role-Based Access Control (RBAC). |
Configuration rollback.
SSHv2.
Telnet.
AAA.
Remote Authentication Dial In User System (computer networks) (RADIUS).
Terminal Access Controller Access Control System Plus (TACACS+).
Syslog (8 servers).
Embedded packet analyser.
Simple Network Management Protocol (SNMP)v1, v2, and v3 (IPv4 & IPv6).
Enhanced SNMP Management Information Base (MIB) support.
Unified username and passwords across CLI and SNMP.
Microsoft Challenge Handshake Authentication Protocol (MS-CHAP).
Digital certificates for management between switch and RADIUS server.
RBAC
4.1.4 Storage
The contractor(s)’s technical solution shall meet all requirements listed below.
| Specification |
| Requirement |
| Management |
| The solution will provide an easy to use administration and management Graphical User Interface (GUI). |
| Protocols |
| The solution will support and be licensed for thin provisioning Common Internet File Systems (CIFS), Network File Systems (NFS), Internet Small Computer Systems Interface (iSCSI), FC, and FCOE on the same system. |
| Features |
| The solution will provide an automated process for expanding volumes or file systems. |
The solution will support automated file archiving in the same or to another like storage solution, while being transparent to the end-user and administration functions.
The solution will provide file system quota management capable of enforcement at the individual file share level.
Near-linear performance scalability and linear capacity scalability; includes heterogeneous storage configurations with point-in-time recovery and data updates occurring during operations over time.
The solution will provide a separation of storage client access and administrative access so that all control functions are isolated from client access, providing secure, out-of-band management.
The solution will provide the ability to easily re-assign data access (volumes) between nodes of the cluster without physically copying the data.
The solution will provide scalable and fully redundant connections to the back-end storage to assure high availability and performance with no loss in maximum available capacities.
Will keep write cache persistent during fault conditions to prevent data losses.
The solution will provide a scalable n-way (N+1) cluster architecture for flexible clusters failover configuration with one or more standby processors to each of which one or more designated production processors can fail over, so that:
There is no performance degradation after failover completes.
Fail-back is as simple and quick as failover with no performance impact.
Multi-path Input/Output (I/O) to disk drives exists in cluster configuration.
The solution will provide the ability to support flexible disk configurations, including Solid State Disk (SSD)/Flash, Serial Attached SCSI (SAS) and Serial Advanced Technology Attachment (SATA) simultaneously.
The solution will provide point-in-time backup and restore capability with the ability for end-user clients to restore their own files from their Windows client desktop.
The solution will provide the capability to separate storage for production data and point-in-time data with the ability for the production file systems to be placed on differing (Redundant Array of Independent Disks (RAID)) arrays, disk types, and RAID types from the snapshot data.
The solution will ensure there is no fragmentation of the production file system data or degradation of performance with the creation and deletion of point-in-time recovery points.
The solution will ensure there is not a loss of more recent snapshots with an out of order point-in-time restore.
The solution will have the ability to forgo taking snapshots if space is not available and send an alert.
The solution will provide the ability to expand the snapshot space or production file system independently of the other.
The solution will provide replication in both synchronous and asynchronous modes. The solution will be able to provide data replication between storage arrays. Additionally, it will provide compression and/or de-duplication in order to reduce bandwidth utilization and increase transfer rates. It will also support replication in both virtual and physical environments, and will be able to recover from a full range of recovery points.
The solution's data de-duplication with compression functionally will not impact or change any system sizing, capacity planning or performance limits when enabled.
| Compatibility |
| The solution will be compatible with VMware File System (VMFS) ESX and ESXi version 4.0 and above. |
| Misc. |
| The solution will have a non-returnable disk maintenance contract. |
4.1.5 Computing
Computing requirements are unique to each environment (i.e. Domestic Data Centers and Remote Offices) and are described in sections 4.2.2 and 4.3.2.
4.1.6 UPS
There are no UPS requirements for the Domestic Data Centers. The Remote Offices’ UPS requirements are described in section 4.3.6.
4.1.7 Backup/Disaster Recovery/Data Offshoring
Backup/Disaster Recovery/Data Offshoring requirements are unique to each environment (i.e. Domestic Data Centers and Remote Offices) and are described in sections 4.2.6 and 4.3.6.
4.1.8 Enterprise Software Environment
The contractor shall provide VMware vSphere preinstalled with all necessary hardware-specific drivers included. The software shall be compatible with the Government-provided current VMware operating system licenses. Additional background information on Enterprise Server Operations Center (ESOC) and the Domestic Data Centers are contained in Attachment J-2 (ESOC and GITM Overview).
4.1.9 Systems Management Suite
This section describes the requirements the contractor(s) shall provide in its Systems Management Suite. This suite will manage storage, computing and network capabilities using a single pane of glass. The suite will allow the administrator to monitor the entire system (end-to-end) as well as manage individual components (i.e. the single pane management systems, which will allow all components to be managed from a single user interface, for local and remote management; however, the systems must also be manageable using our existing network and server management systems) using a consistent display and command structure. This may be through a single tabbed pane, an expandable product tree or by opening distinct sub-windows or windows on a per-activity basis. In certain cases, external management activities may need to be invoked. Within the Suite, access to components as well as management and monitoring programs will be controlled through an AD-based RBAC process. The contractor(s)’s systems management suite shall provide the requirements listed below.
· The solution will contain an out-of-band management solution.
· The solution will allow for configuration of all server functions, network functions, storage functions and multi-pathing functions.
· The solution will support remotely accessible smart Power Distribution Units (PDU).
· The solution will support Wake-on-LAN.
· The solution will support iSCSI, NFS, FC, FCoE and CIFS.
· The solution will support a minimum of N+1 hardware redundancy (no single points of failure).
· The solution will allow hot swappable primary components.
· The solution will provide the most power efficient solution available.
· The solution will provide physical notification of system status.
· The solution’s components will be easily accessible for component repair/administration.
· The solution’s applicable system components and software will be common criteria certified.
· The solution’s technical support will provide collaborative support processes across all components of solution.
· The solution will provide monitoring and alert processing for:
· SNMP traps to third party systems;
· Physical devices;
· Network connectivity;
· Environmental factors;
· Performance CPU, memory, storage device utilization; and
· Log file and log device limits.
· The solution will provide separation to allow flexibility with upgrades and faster recovery times, and eliminates issues that a virtualized solution may encounter.
· The solution will provide resiliency in the event of an outage. The solution will continue to handle workloads without interruption.
· The solution will provide the ability to manage a multi-tenant environment.
· The solution’s management interface will be able to deliver firmware to blades as part of a service profile.
· The solution will be able to manage all devices remotely.
· The solution will handle all licensing for the solution with minimal interaction.
· The solution will support VLANS to manage QoS granularly to protect critical traffic.
· The solution will not impact the performance of the system it monitors with the exception of the system that hosts the management solution.
· The solution will allow RESTful Application Program Interface (API) for site-level customization.
· The solution will allow AD integration, secure configurations, secure administrative access and secure use-case.
· The solution will contain plug-ins and adapters for all virtualization and cloud management.
· The solution will contain ability to scan production system for Department of State operational and security compliance.
· The solution will contain the ability to troubleshoot production infrastructure, whether virtual or physical.
· The solution will contain all monitoring and performance tools required for solution.
· The solution will provide a centralized location for patch and firmware management.
· The solution will include all required licensing required for all components of the ECP solution.
· Keyboard Video Mouse (KVM) for each server will be accessible from the management single pane of glass.
· KVM will allow for AD RBAC.
· The solution will have the following security features:
· Active directory integration;
· Secure configurations;
· Secure administrative access; and
· Secure use-case.
· The solution will contain plugins and adapters for all virtualization and cloud management.
· The solution will contain ability to scan production system for Department of State operational and security compliance.
· The solution will contain the ability to troubleshoot production infrastructure whether virtual or physical.
· The solution will contain all monitoring and performance tools required for solution.
· The solution Scripting Tools will:
· Support scripting via PowerShell or an equivalent scripting solution;
· Include Department of State-provided scripts in the release product, such scripts will be provided to the contractor(s) prior to the system assembly/installation phase;
· Support central IRM management and domestic and overseas locations authoring custom scripts;
· Support scripts invoked either automatically (on an event/alert basis for any trigger able event/alert) or manually from within the management product; and
· Support scripts external to the management product will invoke/execute management activities.
4.1.10 Security
The contractor(s) shall meet and/or comply with the following Common Security requirements:
· Comply with Federal Information Processing Standard (FIPS) 200/National Institute Standards (NIST) SP 800-53 requirements.
· Be FIPS 140-2 and Level 2 compliant per NIST FIPS 140-2 Security Requirements for Cryptographic Modules.
· Be FIPS 180-2 compliant.
· Support RBAC through AD integration.
· Support common criteria certified software.
· Support Trade Act Agreement (TAA) compliant hardware.
· No item may contain embedded Bluetooth ®, infrared Technology, wireless Technology, or any device internal to a computer system case that transmits or receives any information in the Radio Frequency (RF) spectrum, including but not limited to, 802.11, 802.16, Global Positioning System (GPS), wireless USB, Radio Frequency Identification (RFID), or any other technology that accesses or has the capability to access the RF spectrum.
· Any firmware or device driver software required for the operation of each item is free of malicious code.
· No item contains firmware based tracking/anti-theft software or any other tracking functionality (including, but not limited to, firmware, software, or other unidentified tracking capabilities).
· All x64 architecture based systems offered include a Trusted Platform Module (TPM), version 1.2 or greater. For each item, the TPM chip manufacturer and models included in the system must be identified and provided to the Government, and they must ensure that such information is up-to-date, complete, and accurate (i.e., this is a continuing requirement such that if the information changes after it has been provided, the contractor(s) will promptly, within 10 calendar days of the change, provide the updated information).
· For each item, all instances of hidden or recovery disk partitions must be identified and instructions for their removal have been provided to the Government.
· For each x64 architecture based system, a description of the OEM supplied device drivers required to operate each item must be provided to the Government, and such information must be up-to-date, complete, and accurate (i.e., this is a continuing requirement such that if the information changes after it has been provided, the contractor(s) will promptly, within 10 calendar days of the change, provide the updated information).
· No item will contain a built-in camera or any other imaging devices.
4.2 Domestic Data Center Requirements
4.2.1 Introduction to the Domestic Data Center Operating Environment Background information on Enterprise Server Operations Center (ESOC) and the Domestic Data Centers are contained in Attachment J-2 (ESOC and GITM Overview). This section contains the unique requirements for the Department of State, Domestic Data Centers.
4.2.2 Networking
The technical solution for Networking to be provided by the contractor(s) shall satisfy all requirements listed below.
| Requirement Description |
| Type |
| Networking |
| Throughput and port count |
| Requirement |
| The solution will have 960 Gbps or greater of throughput and up to 48 ports (32 unified ports) |
| Unified Ports |
| Requirement |
| The solution will have unified port modules that provide GE and FCoE ports using the SFP+ interface. |
| Validation Testing |
| Requirement |
| The solution will have a suite of diagnostic facilities to verify that hardware and internal data paths are operating as designed. |
| Layer 2 Hardware Forwarding |
| Requirement |
| The solution will have the ability to do Layer 2 hardware forwarding at 960 Gbps (gigabit per second) or 714.24 Mpps (Million packets per second) or greater. |
4.2.3 Storage
The technical solution for Storage to be provided by the contractor(s) shall satisfy all requirements listed below.
· The solution’s array will support a minimum of 500GB of extended Read/Write cache for systems with a mix of high speed/high density disks.
· For additional requirements, refer to the table below.
| Requirement Description |
| Type |
| Storage |
| Processing |
| Requirement |
| Array based storage - dual storage processor/multi-core operating system |
| Tiered Storage |
| Requirement |
| T1 EFD storage |
T2 15k SAS storage T3 7.2K NL-SAS storage
| Availability |
| Requirement |
| The solution will ensure that the uptime of production file systems is not impacted in the event an out of disk space for a snapshot results in a write failure. |
The solution will ensure there is not a loss of more recent snapshots with an out of order snapshot restore.
Provide snapshot backup and restore capability with the ability for end-user clients to restore their own files from their windows client desktop.
Will keep write cache persistent during fault conditions to prevent data loss Support data-in-place upgrades of the hardware for future technology refresh.
Dedicated Hot Spares.
| Capability |
| Requirement |
| The solution’s array will support a minimum of 500GB of extended Read/Write cache for systems with a mix of high speed/high density disks. |
Provide an automated process for expanding volumes or file systems.
Configuration will consist of a mixture of Solid State Drives, 15k rpm, 10k rpm SAS drives and 7200rpm NL SAS.
Supported Raid levels - 5/6/10.
Support and licensed for thin provisioning.
Provide an easy to use administration and management web based graphical user interface (GUI).
Support and licensed for CIFS, NFS, FC.
Multi-Pathing software/simultaneous path failover/load balancing.
Dynamic adaption to I/O changes.
Automated Failover/Failback.
Automated Storage Tiering.
Support for Controller based and Array Cache.
4.2.4 Computing
The technical solution for computing to be provided by the contractor(s) shall satisfy all requirements listed below.
· The solution will support dual Intel E5-2690 processors equivalent or better and 512GB or better of DDR3 RAM on a half width blade.
· The solution will scale to 7000+ physical CPU cores and 100TB+ of RAM.
· The solution’s server platform will be stateless, where the characteristics are defined via an identity profile. All profiles will be maintained and managed on an appliance device.
· The solution will support re-purpose of a server, replace a failed blade and move the OS/Application to a blade with more resources. It will perform these functions by transferring the server identity/parameters to the new blade through the server management software without additional server configuration.
· The solution’s firmware will be applied on the server based on the "profile" settings. This profile will be capable of loading and configuring the firmware for the BIOS, Adapter and out-of-band management module.
· The solution’s access controls must support the security concepts that users are given only those privileges and entitlements necessary to perform their function and that those privileges are auditable.
· The solution will be able to aggregate network, storage and management connectivity to a single network cable to a chassis.
· The solution will manage a multi-tenant environment.
· The solution will manage NIC Media Access Control (MAC) in pools and the ability to create multiple pools based on security or functionality.
· The solution will manage HBA World Wide Names (WWN) in pools and the ability to create multiple pools based on security or functionality.
· The solution will manage Server UUID in pools and the ability to create multiple pools based on security or functionality.
· The solution will manage multiple blade chassis with one management system using the native equipment without additional software requirements. The interface will be able to deliver firmware to blades as part of a service profile. The interface will also be able to apply firmware updates.
· The solution will manage all aspects of system configuration and operation through a single management console, eliminating the need to use separate element managers for each system component.
· The solution will have a single integrated management application for all aspects of configuration, management, monitoring, alerting and security for the following:
· The blade chassis and all associated power and cooling.
· Any internal or required external uplink or interconnect modules facilitating the first layer of Ethernet and/or FC connectivity from the blade infrastructure to any external Ethernet or FC environment.
· All blade servers and installed options such as network or storage mezzanine adapters.
· The solution will transparently pass all blade servers’ I/O requirements from each chassis upstream to a network interconnect layer which acts as a consolidation and interconnect layer for all Ethernet, blade and chassis management, and storage networking functions.
· The solution will include a system of redundant uplinks that provide connections from each blade in the chassis to an upstream network interconnect device.
· The solution will allow third party orchestration products to configure, manage and monitor the solution, servers and uplink modules through a standard published and publically accessible API such as XML.
· The solution will support the ability to move a server’s configuration state from any blade in the environment to any other blade in the environment through the provided GUI management system.
· The solution will be Highly Available (HA) and fully redundant hardware architecture with automated failover included.
· The solution will support full AAA security functions and integration with RADIUS, TACACS+ and Lightweight Directory Access Protocol (LDAP) environments.
· The solution will support multiple users and roles that are configurable with granular levels of access control to all major elements within the solution.
· The solution’s server will support the option for FCoE and FC external interfaces. All FCoE for chassis-to-chassis communication are connected to the same management module.
· The solution’s chassis will support a beaconing facility with clear visual indications that can be activated electronically through a management system and manually through a chassis button to aid in locating the platform in a Data Center.
· The solution will include sufficient power and cooling capabilities to operate fully redundantly in all possible configurations, up to and including a fully populated configuration, with all blades and options populated and operating at full capacity.
· The solution’s blade chassis will support hot insertion and removal of server blades without disrupting other running blades in the chassis.
· The solution’s blades will support a local KVM facility allowing the connection of keyboard, mouse, video, and DVD drive or USB key to the blade directly.
· The solution will include redundant hot pluggable power supplies that are connected through at least two discrete and separate power sources.
· The solution’s profiles will allow for configuration of the following:
| Requirement Description |
| Data Center Management |
| Out of band management |
| Out of band management |
| Configuration |
| The proposed management solution will allow for configuration of the following: |
All server functions for the solution All network types functions for the solution All array functions for the solution All multi-pathing functions for the solution
| Features |
| The management interface will be able to deliver firmware to blades as part of a service profile. |
The proposed management solution will utilize current virtualization technologies for the Data Center to include all resources.
The proposed management solution will contain the ability to troubleshoot production infrastructure whether virtual or physical.
Continuous certified code releases for entire converged infrastructure to ensure interoperability of all components Agentless SNMP Monitoring (equivalent or better).
| Requirement Description |
| Blade Compute |
| Per Physical Blade |
| 1/2 Height/Width |
| Processor |
| TWO (2) INTEL OCTA CORE PROCESSORS E5-2690 (20M CACHE, 2.90 GHZ, 8.00 GT/S INTEL® QPI) (equivalent or better); must be a eight core Processor or better; must obtain a PassMark® CPU score of 10,000 or better; must be 95 Watts or lower; The vendor must provide testing data to validate power consumption and performance for any alternative processors |
| Memory |
| 512 GB 1066 MHz DDR3 Registered DIMMs; Memory must be installed for optimal performance according to the Manufacture DDR3 Memory configuration tool; All DIMMs must be same size, rank, and speed; must provide Advanced ECC and 4-way interleaving (equivalent or better). |
| Configuration |
| BIOS: Quiet Boot |
BIOS: Resume A/C on Power Loss BIOS: Front Panel Lockout BIOS: Turbo Boost BIOS: Enhanced Intel Speedstep BIOS: Hyper Threading
BIOS: VT
BIOS: Processor C3 Report BIOS: Processor C6 Report BIOS: VT for Directed IO BIOS: Interrupt Remap BIOS: Coherency Support BIOS: Advanced Technical Support (ATS) BIOS: Pass-through Direct Memory Access (DMA) Support BIOS: Memory Remote Access Server (RAS) Configuration BIOS: Non-Uniform Memory Access (NUMA) BIOS: Low Voltage Dial-on-Demand Routing (DDR) Mode BIOS: Console Redirection Method BIOS: Console Baud Rate Server Boot Order: Hard Disk Drive (HDD), CD-ROM, SAN, USB, Floppy, Partial XML (Extensible Markup Language) Envelope (PXE) Server BIOS Firmware Ethernet Adapter Firmware FC Adapter Firmware Host - Based Authentication (HBA) Option Read-Only Memory (ROM) Firmware Storage Controller Firmware Remote Management Controller Firmware Server Unique User Identifier (UUID) Virtual Server Serial Number Defined Number of Virtual Network Interface Cards (vNIC) on Server Defined Number of Dynamic vNICs Internet Protocol Multicast Initiative (IPMI) Usernames & Passwords IPMI User Roles Serial Over LAN Configuration Peripheral Component Interconnect Express (PCIe) Bus Device Scan Order for Network Interface Cards (NIC)/HBAs PCIe Virtual Device Slot Placement for NIC/HBA BIOS Scrub Actions Disk Scrub Actions Thresholds for Monitored Statistics Number of Virtual HBAs (vHBA) on Server Local HDD RAID Configuration Distribution FC Switch Uplink Assignment per HBA (Pin Group) HBA World Wide Port Name (WWPN) Assignment HBA FC SAN Membership FC Boot Parameters HBA-to-Distribution FC Switch Uplink Persistent Binding HBA Maximum Data Field Size (MTU) HBA Transmit Queue Ring Size HBA Receive Queue Ring Size HBA SCSI I/O Queues HBA SCSI I/O Queue Ring Size HBA FC Protocol (FCP) Error Recovery HBA Fabric Login (FLOGI) Retries HBA FLOGI Timeout HBA Port Login (PLOGI) Retries HBA PLOGI Timeout HBA Port Down Timeout HBA Port Down I/O Retry HBA Link Down Timeout HBA I/O Throttle Count HBA Max Logical Unit Numbers (LUN) per Target HBA Interrupt Mode HBA QoS Priority HBA QoS Burst size HBA QoS Rate limit HBA QoS Host Control Option HBA World Wide Node Name (WWNN) Assignment
| Network |
| Blade will have dual 10GB uplinks with the capability of being virtualized or better |
| RAID Controller |
| Raid 1 internal Drives (equivalent or better) |
| Blade Chassis Density |
| Blade Chassis should hold 8 blades(equivalent or better) |
| Blade Chassis Power |
| N+1/N+2 Hot swappable Power supplies sufficient to power fully populated blade Chassis |
| Blade Chassis network uplinks |
| Unified I/O or equivalent |
1 Gb/10Gb/FC if applicable Dual Network Switches - 48 Unified ports or equivalent 4x 10-40Gb uplinks per Chassis to network switches Pre-Configured with Customer network details Virtual Access Switch: Includes VSG(Virtual Secure Gateway) /DHCP/IP source Guard/Dynamic ARP Inspection/Secured network segmentation
| Blade Chassis per Management interface |
| 20 Plus Blade Chassis Per Management Interface |
| Blade Chassis Power |
| N+1 Hot-swappable Single-Phase |
4.2.5 UPS
The Domestic Data Centers’ solution has no requirements for UPS.
4.2.6 Backup/Disaster Recovery/Data Offshoring
The Data Center solution will provide centralized management and Backup/Disaster Recovery (DR) so there is an effective, coordinated and tested response to application outages. The contractor(s)’s Backup/DR solution shall enhance the Department’s diplomatic mission by introducing the capability to continue IT operations for critical IRM applications in the event of a disaster or sub-system failure.
| SPECIFICATION |
| REQUIREMENTS |
| VM Level Backups |
| Solution will provide point in time snapshot for Virtual machine backup and recovery. |
| File Level Backups |
| Solution will provide an option for File level backup and recovery. |
| Application Level Backups |
| Solution will provide an option for Application Level Backup and recovery (Exchange 2010, SharePoint, etc.). |
| Compatibility |
| The solution will be compatible with VMware File System (VMFS) ESX and ESXi version 4.0 and above. |
| Disaster Recovery |
| Solution will provide site to site replication with VMware Site Recovery Manager Integration. |
| CIFS Home Directory / Backup Archiving. |
| Provide snapshot backup and restore capability with the ability for end-user clients to restore their own files from their windows client desktop. |
4.2.7 Systems Management Suite
The technical solution to be provided by the contractor(s) shall satisfy all the management and software requirements described in section 4.1.9.
4.2.8 Security
The technical solution to be provided by the contractor(s) shall satisfy all the security requirements described in section 4.1.10.
4.2.9 Implementation and Migration
· Implementation: Department of State may require the contractor(s) to install the ECP infrastructure at the Domestic Data Center sites. If required to do so, the contractor(s) shall perform all installations using only cleared resources (i.e. resources with valid government security clearances). The solution to be provided by the contractor(s) shall:
· Be compatible and integrate with VMware vCenter and vCenter Operations Manager.
· Have vSphere preinstalled according to ESOC’s current baseline.
· Allow for continuous capacity monitoring with unified dashboards, reports and analytics across all components.
· Provide redundancy for each component with no single point of failure.
· Be able to grow both modularly and incrementally.
· Migration: The contractor(s) shall provide a detailed migration plan to transition from the current Domestic Data Centers infrastructure to the contractor(s)’s solution with minimal interruption to services. The contractor(s) shall provide all applicable licenses to perform these tasks in the solution.
4.3 Remote Office Requirements
4.3.1 Introduction to the Remote Office Operating Environment Background information on the Global IT Modernization Program and Remote Offices are contained in Attachment J-2 (ESOC and GITM Overview). This section contains the unique requirements for the Department of State, Remote Offices.
The ECP configuration will include, but is not limited to the following:
· Core switch configuration
· Virtual host (ESXi) OS installation and configuration
· UPS configuration
· Storage configuration and provisioning
· Virtual machine staging
· Backup/DR software configuration
In addition, the contractor(s)’s technical solution shall meet all of the requirements described in this section.
4.3.2 Networking
Core Switching: Core switches provide redundant layer 3 connectivity between the WAN and LAN distribution switches. Core switches will provide sufficient performance to support the entire ECP solution as well as LAN communications and WAN traffic. The core switches will be redundant so that in the event of a single switch failure, the ECP, WAN connectivity, and LAN connectivity will be maintained.
Core Switch Technical Requirements (User Base A through D) The following table provides an example of the requirements expected to be met by the core switches for a moderately sized post. The contractor(s)’s configuration shall provide a core switch solution that is equivalent or better than the systems listed below. User Base is defined in Section 4.3.5, under “VM Minimum Configuration”.
USER BASE A THROUGH D CORE SWITCH MINIMUM REQUIREMENTS
Performance Switching Capacity - 160Gbps Forwarding Performance - 101.2Mpps
Switching - Layer 3 processing
WAN - Must provide support for dual paths in a failover configuration (primary vs alternate path). Must have a separately configurable/manageable operating environment for each path (2 disparate switches).
Environmental Parameters
* Humidity Operating range 5-95% (non-condensing)
* Max Operating Temperature 113 °F
* Min Operating Temperature 32 °F
Backbone - Must be able to support a 1Gbps Fiber or Copper
Duty Cycle - MTBF 70080 hours
Authentication Method - Kerberos, RADIUS, Secure Shell v.2 (SSH2), TACACS+
Compliant Standards AS/NZ 3548 Class A , AS/NZS 60950-1 , CB , CCC , CISPR 22 Class A , CSA C22.2 No. 60950-1 , cUL , EN 60950-1 , EN55022 Class A , FCC Part 15 A , GOST , IEC 60950-1 , KCC , NOM , RoHS , TUV GS , UL 60950-1 , VCCI Class A ITE
Network Standards IEEE 802.1ab (LLDP), IEEE 802.1D, IEEE 802.1p, IEEE 802.1Q, IEEE 802.1s, IEEE 802.1w, IEEE 802.1x, IEEE 802.3, IEEE 802.3ab, IEEE 802.3ad (LACP), IEEE 802.3ah, IEEE 802.3u, IEEE 802.3x, IEEE 802.3z
Data Transfer Rate - 1000 Mbps/ 1Gbps
Networking Features Access Control List (ACL) support , ARP support , Auto-negotiation , Auto-uplink (auto MDI/MDI-X) , Broadcast Storm Control , Cisco StackWise Technology , DHCP snooping , DHCP support , Dynamic ARP Inspection (DAI) , Dynamic IP address assignment , Dynamic Trunking Protocol (DTP) support , EIGRP Stub Routing , High Availability , Hot swap module replacement , IGMP snooping , Jumbo Frames support , Layer 2 switching , Link Aggregation Control Protocol (LACP) , MLD snooping , Multicast Storm Control , Per-VLAN Spanning Tree Plus (PVST+) , Port Aggregation Protocol (PAgP) support , Quality of Service (QoS) , Rapid Spanning Tree Protocol (RSTP) support , Remote Switch Port Analyzer (RSPAN) , Shaped Round Robin (SRR) , Syslog support , Traffic shaping , Trivial File Transfer Protocol (TFTP) support , Trunking , Uni-Directional Link Detection (UDLD) , Unicast Storm Control , Virtual Route Forwarding-Lite (VRF-Lite) , VLAN support
Remote Management Protocol HTTP, HTTPS, RMON 1, RMON 2, RMON 3, RMON 9, SNMP 1, SNMP 2c, SNMP 3, SSH, SSH-2,Telnet
Routing Protocol BGP-4, EIGRP, EIGRP for IPv6, HSRP, IGRP, IS-IS, OSPF for IPv6, OSPFv3, PIM-DM, PIM-SM, Policy-based routing (PBR), RIP-1, RIP-2, RIPng, Static IP routing
Status Indicator Link OK, Port duplex mode, Port status, Port transmission speed, Power, System
Redundancy No single points of failure on any critical system components
Core Switch Technical Requirements (User Base E through H) The following table provides an example of the requirements to be met by the core switches for a large post. The contractor’s proposed configuration shall provide a core switch solution that is equivalent or better to the systems listed below. User Base is defined in Section 4.3.5, under “VM Minimum Configuration”.
USER BASE E THROUGH H CORE SWITCH MINIMUM REQUIREMENTS
Performance Switching Capacity - 160Gbps Forwarding Performance - 101.2Mpps
Switching Layer 3 processing
WAN
Must provide support for dual paths in a failover configuration (primary vs alternate path). Must have a separately configurable/manageable operating environment for each path (2 disparate switches).
Backbone Must be able to support a 1Gbps Fiber or Copper
Duty Cycle MTBF 70080 hours
Authentication Method Kerberos, RADIUS, Secure Shell v.2 (SSH2), TACACS+
Environmental Parameters
* Operating temperature: 32 to 104ºF (0 to 40ºC)
* Storage temperature: -40 to 167ºF (-40 to 75ºC)
* Relative humidity: 10 to 90 percent, noncondensing
* Operating altitude: -60 to 3000 meters (m)
* Fan Operations: system must be able to detect and notify the user (through LED, CLI, and Simple Network Management Protocol [SNMP]) of failures and that replacements are required
Network Standards IEEE 802.1ab (LLDP), IEEE 802.1D, IEEE 802.1p, IEEE 802.1Q, IEEE 802.1s, IEEE 802.1w, IEEE 802.1x, IEEE 802.3, IEEE 802.3ab, IEEE 802.3ad (LACP), IEEE 802.3ah, IEEE 802.3u, IEEE 802.3x, IEEE 802.3z
Compliant Standards Regulatory compliance - CE Marking Safety - UL 60950, CAN/CSA-C22.2 No. 60950, EN 60950, IEC 60950, TS 001, AS/NZS 3260 EMC - FCC Part 15 (CFR 47) Class A, ICES-003 Class A, EN55022 Class A, CISPR22 Class A, AS/NZS 3548 Class A, VCCI Class A, EN 50121-4, EN 55022, EN 55024, EN 61000-6-1, EN 50082-1, EN 61000-3-2, EN 61000-3-3, ETS 300 386 Industry EMC, safety, and environmental standards - NEBS Level 3, ETS 300 019 Storage Class 1.1, ETS 300 019 Transportation Class 2.3, ETS 300 019 Stationary Use Class 3.1, ETS 300 386 Telecom (E1) - CTR 12/13, CTR 4, ACA TS016 Telecom (T1) - FCC Part 68, Canada CS-03, JATE Green Book ROHS compliance - ROHS5
Networking Features Access Control List (ACL) support , ARP support , Auto-negotiation , Auto-uplink (auto MDI/MDI-X) , Broadcast Storm Control , Cisco StackWise Technology , DHCP snooping , DHCP support , Dynamic ARP Inspection (DAI) , Dynamic IP address assignment , Dynamic Trunking Protocol (DTP) support , EIGRP Stub Routing , High Availability , Hot swap module replacement , IGMP snooping , Jumbo Frames support , Layer 2 switching , Link Aggregation Control Protocol (LACP) , MLD snooping , Multicast Storm Control , Per-VLAN Spanning Tree Plus (PVST+) , Port Aggregation Protocol (PAgP) support , Quality of Service (QoS) , Rapid Spanning Tree Protocol (RSTP) support , Remote Switch Port Analyzer (RSPAN) , Shaped Round Robin (SRR) , Syslog support , Traffic shaping , Trivial File Transfer Protocol (TFTP) support , Trunking , Uni-Directional Link Detection (UDLD) , Unicast Storm Control , Virtual Route Forwarding-Lite (VRF-Lite) , VLAN support
Remote Management Protocol HTTP, HTTPS, RMON 1, RMON 2, RMON 3, RMON 9, SNMP 1, SNMP 2c, SNMP 3, SSH, SSH-2,Telnet
Routing Protocol BGP-4, EIGRP, EIGRP for IPv6, HSRP, IGRP, IS-IS, OSPF for IPv6, OSPFv3, PIM-DM, PIM-SM, Policy-based routing (PBR), RIP-1, RIP-2, RIPng, Static IP routing
Power N+1 Redundant
Distribution Switching:
Distribution switches connect the core switches to the client switches. The contractor-provided distribution switch solution shall meet the requirements listed below.
DISTRIBUTION SWITCH MINIMUM REQUIREMENTS
Switching Layer 2 processing
Environmental Parameters
* Humidity Operating range 10 - 85% (non-condensing)
* Max Operating Temperature 113 °F
* Min Operating Temperature 32 °F
Backbone Must be able to support a 1Gbps Fiber or Copper
Duty Cycle MTBF 70080 hours
Authentication Method RADIUS, Secure Shell (SSH), TACACS+
Compliant Standards CE, CISPR 24, CSA, CUL, EN 60950, EN55022, EN55024, FCC Class A certified, IEC 60950, NOM, TUV GS, UL, VCCI Class A ITE
Network Standards IEEE 802.1ab (LLDP), IEEE 802.1D, IEEE 802.1p, IEEE 802.1Q, IEEE 802.1s, IEEE 802.1w, IEEE 802.1x, IEEE 802.3, IEEE 802.3ab, IEEE 802.3ad (LACP), IEEE 802.3ah, IEEE 802.3u, IEEE 802.3x, IEEE 802.3z
Data Transfer Rate - 1000 Mbps/ 1Gbps
Networking Features Access Control List (ACL) support , ARP support , Auto-negotiation , Auto-uplink (auto MDI/MDI-X) , Broadcast Storm Control , Cisco StackWise Technology , DHCP snooping , DHCP support , Dynamic ARP Inspection (DAI) , Dynamic IP address assignment , Dynamic Trunking Protocol (DTP) support , High Availability , Hot swap module replacement , IGMP snooping , Jumbo Frames support , Layer 2 switching , Link Aggregation Control Protocol (LACP) , MLD snooping , Multicast Storm Control , Per-VLAN Spanning Tree Plus (PVST+) , Port Aggregation Protocol (PAgP) support , Quality of Service (QoS) , Rapid Spanning Tree Protocol (RSTP) support , Remote Switch Port Analyzer (RSPAN) , Shaped Round Robin (SRR) , Syslog support , Traffic shaping , Trivial File Transfer Protocol (TFTP) support , Trunking , Uni-Directional Link Detection (UDLD) , Unicast Storm Control , Virtual Route Forwarding-Lite (VRF-Lite) , VLAN support
Remote Management Protocol HTTP, HTTPS, RMON 1, RMON 2, RMON 3, RMON 9, SNMP 1, SNMP 2c, SNMP 3, SSH, SSH-2,Telnet
Routing Protocol EIGRP, RIP-1, RIP-2, RIPng, Static IP routing
Status Indicator Link OK, Port duplex mode, Port status, Port transmission speed, Power, System Bandwidth utilization percentage, Link activity, Port duplex mode, Port status, Port transmission speed
Power - Must provide N+1 redundant power
Troubleshooting - Must provide N+1 redundant power
4.3.3 Storage
The contractor(s)’s backup solution shall comply with the Backup and Data Off-shoring section. The contractor(s)’s storage solution shall provide for, at a minimum, power supply, controller,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .