GEF_Industry_Day_Slides_151015.pptx
PPTX presentation 14 MB Posted
- Attached to
- Global Enterprise Fabric Federal contract opportunity
- Solicitation number
- W91RUS16GEF1
About this file
Global Enterprise Fabric Industry Day Briefing Slides
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| AMD_08.pdf | ||
| AMD_07.pdf | ||
| AMD_06.pdf | ||
| AMD_05.pdf | ||
| AMD_04.pdf | ||
| A01-Solicitation_AMD_03.pdf | ||
| AMD_02.pdf | ||
| AMD_01_(Final).pdf | ||
| AMD_01.pdf | ||
| A01-Solicitation_151221.pdf | ||
| Q A_from_Industry_Day_(151109).docx | DOCX document | |
| SOO_FRD_Answers_151008.docx | DOCX document | |
| FRD.docx | DOCX document | |
| SOO.docx | DOCX document |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enterprise Strategy
Evolution of the Army's IT Infrastructure Multiple, complex environments Stand-alone hardware De-centralized, non-standard “silo” effect No standardization of the global network environment Theater level consolidation Stand-alone hardware De-centralized, non-standard ICAN, TLA, RTLA OPORD #0428-301 Standardization of the global network environment Software Defined Infrastructure Theater Centric Centralized Management, Standard Decentralized Execution JIE / JRSS / JMN MPLS network and security stack architecture
UNCLASSIFIED
Together We Are…The Voice of Our Army
This slides depicts the evolution of the Army and DoD IT infrastructure from isolated, decentralized management, non-standard operational environment, to a consolidated, centralized, standard environment. That provides the ability to:
Build Operate, Maintain, Defend and See the COE Global unfettered access to information Globalized standards for Army networks, workstations, servers, applications, and data Secure/reliable service, anywhere, anytime Synchronize with JRSS solution Centralized management, monitoring and reporting Protected Army DOIM with limited entry points Automated IA policy verification and enforcement Isolation of compromised servers and PCs
Enterprise Strategy
Zone 1 Zone 3
To meet the Army objectives of the Building One, Inherently Joint Network – to the, NETCOM has developed enterprise objectives and an execution plan that enables us to overcome current impediments to achieve the desired end-state. We call this plan the Enterprise Strategy. This plan is not just a NETCOM project – it is all of ours. We need everyone teamed together to achieve mass of fires and accomplish a targeted goal while still having resource/funding constraints ahead of us.
The execution plan is fully integrated with Joint efforts such as JRSS/MPLS, with a focus on high impact areas within the Army/NETCOM family.
To more clearly layout the lines of effort and associated effects, we use Zones. These 6 Zones were not invented by NETCOM but are defined in the NSA and JIE Cyber Security Model. It provides us a way to focus our efforts and synchronize “lanes in the road” for execution.
Our initial areas of focus are in Zones 2, 4, 5 and 6. This isn’t to say we aren’t working other Zones, but our primary efforts will be in Zones 2, 4, 5 and 6 for the next 12-18 months.
I won’t spend a lot of time discussing Zone 2, which encompasses JRSS/MPLS. This is a critical effort that that is being heavily supported by a number of organizations to include NETCOM, the Theater Signal Commands, the PEO Community, FORSCOM, and our Senior Mission Commanders already and I have a few follow-on slides that will address the work within this zone.
Zone 4 is a key inflection point and represents the Regional Cyber Centers (RCCs) and its management of the enterprise. The RCC is a core element in driving standardization of the enterprise.
As we pursue enterprise effects, the RCCs around the globe must operate using a standard set of processes and capabilities in order to provision services in a consistent manner both within and between Theaters.
Right now, there is a great deal of variety in the technologies, tools, and processes utilized by each RCC. This inhibits Joint interoperability and more importantly impacts services to the warfighter that affect connectivity and exercises, to include coalition partners. This also inhibits our ability to standardize our sensor grid to support DCO and DoDIN.
It is critical that we template the RCCs to the greatest extent possible while ensuring we meet the priorities of the Combatant Commander within each Theater. Furthermore, RCC standardization enables better DoDIN operations to keep our adversaries from compromising our lines of communication or interfering with the critical information that flows across our network.
Standardized RCC’s will also improve our ability to reposition resources to better support the mission. Dynamic allocation of services is not only a technology enabled outcome, but is based upon the level of standardization achieved in the processes we use and the training we provide our staff.
Zone 5 is directly addressing our installations. As you may be aware, we have taken on the task of restructuring our NECs to meet the challenges going forward. The current structure of the NECs results in a duplication of services, staff, and capabilities at installations.
Going forward, this approach is inefficient and does not provide our supported commands with the best service possible. Although, our NECs are constrained in terms of resources, both funds and manning, there is still a great deal of opportunity to optimize what we have to better align with mission command requirements.
To that end, NEC regionalization is a primary goal of this command. In particular, rebalancing the NECs to match resources to mission. Specifically, when one looks across the spectrum of installations, not all services and their underlying tasks need to be provisioned at all installations. A better approach is to align services, and the required resources in a manner that affords the greatest return on investment for our supported Commands.
In the same way that we are moving out on regionalization of network assets (JRSS/MPLS), NECs will follow suit and align to a regional construct. Hand-in-Hand with regionalization is modernization of the installation backbone; reducing the number of routers and firewalls that inhibit communication and visibility of the network, and implementing network access control (802.1x) to improve security.
Zone 6 is focused on tactical. Although per this model we have a Zone dedicated to the Warfighter, the entire Enterprise Strategy is dedicated to supporting the Warfighter mission. A key area here is to continue with the on-going enterprise implementation of IaaDS and Home Station Mission Command efforts.
Not only are we concerned with eliminating any impediments to tactical units establishing connectivity in garrison, but we are also focused on supporting consistent and simplified connectivity for deploying units, as well as Live/Virtual training exercises that include my Coalition partners.
Execution of this plan will result in fully network-enabled Mission Command at the end-state, including:
- Delivery of services to the edge
- The ability to conduct Live Virtual Constructive Training
- Achievement desired cyber effects,
- Realization of mission assurance
Critical to achieving our efforts is sustaining these capabilities throughout the POM. This will be the glue that holds allows us to achieve and maintain the desired outcomes.
Enterprise Strategy Objectives
Global Enterprise Fabric (GEF) Overview
Fabric Objectives 10/15/2015 Purpose: “…build out our 'virtualized fabric' to enable DCO/DODIN operations pursuing innovative technologies and capabilities to support the Army.” . It is the intent of the Global Enterprise Fabric to allow the Army to take a “Virtualization First” design strategy in regards to Enterprise capabilities and then expand that strategy to local requirements.
Build Operate, Maintain, Defend and See the COE Global unfettered access to information Globalized standards for Army networks, workstations, servers, applications, and data Secure/reliable service, anywhere, anytime Synchronize with JRSS solution Centralized management, monitoring and reporting Protected Army LandWarNet with limited entry points -- mass IA resources to address threat Defence-in-depth from data canter to end user Automated IA policy verification and enforcement Isolation of compromised servers and PCs
AS-IS Environment
Today, Army enterprise is organized in silos.
Typical infrastructure groups are only responsible for facilities and hardware.
Modernizing a data-center service requires the consolidation of several layers of IT to a centralized infrastructure service organization.
Transforming a traditional data center to provide or consume global fabric is a restructuring of those layers as a single, highly efficient service.
Reducing the cost of infrastructure and support enables the IT budget to be redistributed to help provide greater value to the business.
GEF High-Level Overview
Self-Monitoring Self-Healing Self-Reporting Decentralized Execution
Centralized Management
Visibility / Discoverability Health Compliance Standardization
The Global Fabric solution utilizes a converged architecture that is a software defined infrastructure consisting of computing, network and storage management elements. When configured and deployed it will enable the Army to have global visibility and CND, regional management environment with ability to enforce compliance. The it will be located at 160, locations that can operate independent on a platform based on a converged architecture which allows the Army to project critical enterprise services at each post, camp, and station providing a global user role based portal. From a single pane of glass it provides Visibility/discoverability/health of the network/compliance and standardization.
Cyber Security Layer Network Services Layer Management Layer Physical Infrastructure Compute Network Storage Virtualization Layer Lab Testing Integrated Enterprise workloads
SYSMAN
PKI
Other Workloads
Shared Resource Fabric & Fabric Management
Self-Monitoring Self-Healing Self-Reporting
GEF Dashboard Visibility / Discoverability Health Compliance Standardization
Dedicated Fabric Management Node (DFMN) Node
The Global Fabric solution utilizes a converged architecture that is a software defined infrastructure consisting of computing, network and storage management elements.
When configured and deployed it will enable the Army to have global visibility and CND, regional management environment with ability to enforce compliance.
The equipment must be predefined out-of-the-box solution based on common global fabric design that will have the ability to utilize Army’s existing NETOPS capability.
This will include a vendor produced reference architecture, deployment guide, build guide, and operation guides, best practices, and prescriptive guidance.
This hardware will provide the platform and capacity to field capabilities enabling the Army to leverage existing and joint technology investments.
Fabric Hosting Environment Government Estimated Hardware Requirement Logical Diagram
GEF Phased Strategy
DFMN
(Dedicated Fabric Management Node)
Phase 1
RFMN
(Regional Fabric Management Node)
Phase 2
IPN
(ISN and IPN Fabric Node)
Phase 3
DFMN: Sites around the world to provide top level visibility and capacity to the NETOPs and Infrastructure support provided by NETCOM.
RFMN: Primarily required in CONUS for distribution due to the large user base and the current architecture of the NETOPs and Infrastructure.
IPN: Each Post/Camp/Station supported by NETCOM will require a smaller footprint of the Fabric to support local instances of enterprise capabilities. (i.e. Active Directory and authentication services) – Align with Technical Refresh to minimize impact and costs.
GEF Management Architecture
Phase 1 Dedicated Fabric Management Node (DFMN)
| Layer | Description | Workloads |
| Management | FOUNDATION SERVICES - allows centralizing and automating complex management functions that can be carried out in a highly standardized, repeatable fashion to increase availability and lower operational costs. | EDS&A |
DNS/DHCP/PKI
System Center Out of Band Management (OOBM) vCloud/vCenter Enterprise ENTERPRISE SERVICES – supports the tiered architecture of many of the NETOPs capabilities that provide services to the Theater. HBSS Remedy / ITSM
ACAS
Spectrum ArcSight
| Local | ||
| Management | NEC SERVICES – support the local (on-site) requirements for supporting local capabilities and customers both from infrastructure and common user services. | Print Services |
RCVS/CRLs Security Svcs UC Emergency Svcs Local Services DATA AND FILE SERVICES – supports the local (on-site) customer file and data storage requirements. Unstructured data Structured data Local Applications
Phase 2 Regional Fabric Management Node (RFMN)
| Layer | Description | Workloads |
| Management | FOUNDATION SERVICES - allows centralizing and automating complex management functions that can be carried out in a highly standardized, repeatable fashion to increase availability and lower operational costs. | EDS&A |
DNS/DHCP/PKI
System Center (subset)/vCenter Enterprise ENTERPRISE SERVICES – supports the tiered architecture of many of the NETOPs capabilities that provide services to the Theater. HBSS
ACAS
Spectrum ArcSight
| Local | |
| Management | NEC SERVICES – support the local (on-site) requirements for supporting local capabilities and customers both from infrastructure and common user services. |
| Provides COOP/DR for file and data services from the supported regional spokes and failover RFMN. | Print Services |
RCVS/CRLs Security Svcs UC Emergency Svcs COOP/DR for Regional spokes Local Services DATA AND FILE SERVICES – supports the local (on-site) customer file and data storage requirements. Unstructured data Structured data
Phase 3 Installation Fabric Node (IFN)
| Layer | Description | Workloads |
| Management | FOUNDATION SERVICES - allows centralizing and automating complex management functions that can be carried out in a highly standardized, repeatable fashion to increase availability and lower operational costs. | EDS&A |
DNS/DHCP/PKI
System Center (subset)/vCenter Enterprise ENTERPRISE SERVICES – supports the tiered architecture of many of the NETOPs capabilities that provide services to the Theater. HBSS
ACAS
Spectrum ArcSight
| Local | ||
| Management | NEC SERVICES – support the local (on-site) requirements for supporting local capabilities and customers both from infrastructure and common user services. | Print Services |
RCVS/CRLs Security Svcs UC Emergency Svcs
| Local Services | DATA AND FILE SERVICES – supports the local (on-site) customer file and data storage requirements. | |
| Provides data and file caching capability from its supporting RFMN. | Unstructured data |
Structured data
Storage caching capability
Site Fabric Breakout
| Enterprise Workloads Example's |
| Web Server |
Database Server
| Layer Owner | ||
| RCC | ARCYBER/NETCOM | Enterprise |
| Management | Standards/Compliance | Trusted |
| RCC Workloads Example's |
| IdAM – AD, IdSS, Cross Domain |
Out of Band Management (OOBM) Public Key Infrastructure (PKI) RCVS/CRLs Admin Tools
NETOPS
Security Svcs, UC Emergency Svcs Infrastructure Management System Center 2012 Windows Server 2012 and Hyper-V
| RCC / NETCOM Workloads Example's |
| Cyber Components |
SIEM
Big Data
| Theater Workloads Example's |
| SharePoint |
Web Server Database Server
Build Operate Maintain Defend “See the Network”
12.5k per 1U Server POD is spec’d to run 24, 12.5k equivalent workloads Limited only by capacity and we can add capacity!
Agility! Agility! Agility!
GEF Installation Connectivity
JRSS Acronyms:
VRF – Virtual Routing Firewall PE – Provider Edge CE – Customer Edge
Fabric Objectives 10/15/2015 Purpose: “…build out our 'virtualized fabric' to enable DCO/DODIN operations pursuing innovative technologies and capabilities to support the Army.” . It is the intent of the Global Enterprise Fabric to allow the Army to take a “Virtualization First” design strategy in regards to Enterprise capabilities and then expand that strategy to local requirements.
Build Operate, Maintain, Defend and See the COE Global unfettered access to information Globalized standards for Army networks, workstations, servers, applications, and data Secure/reliable service, anywhere, anytime Synchronize with JRSS solution Centralized management, monitoring and reporting Protected Army LandWarNet with limited entry points -- mass IA resources to address threat Defence-in-depth from data canter to end user Automated IA policy verification and enforcement Isolation of compromised servers and PCs
QUESTIONS?
image14.png image15.png image16.png image17.png image18.png image19.png image20.png image21.png image22.emf image30.png image31.png image32.png image23.png image24.png image25.png image26.png image27.png image28.png image29.png image35.png image36.png image37.png image38.png image39.png image40.png image33.png image34.png image41.png image42.png image43.emf image44.jpeg image45.png image46.emf image47.emf image13.jpg image6.png image2.png image3.png image1.jpeg image4.png image5.png image7.jpeg image8.png image9.png image10.png image11.jpeg
File details come from the government source that posted it. Updated .