Mandatory Equipment Specification

Download as pdf or txt
Download as pdf or txt
You are on page 1of 8

NG AI Firewall Technical Specification

Sr. No 1 (Mandatory)
Requirement (QTY - 01)
The appliance-based security platform should be a stateful NGFW, Next
Generation IPS, malware protection, URL protection, providing firewall,
Basic Firewall
application visibility, and IPS functionality in a single
appliance.

2 x 40GE (QSFP+) + 8 x 10GE (SFP+) +


12 x GE

Hardware architecture Redundant AC Power Supply

Provide SSD 240GB Local Hard disk for


logs and reports

Layer 3 throughput ≥40Gbps;

concurrent connections per second ≥


12,000,000; new connections per second
≥395,000;

Performance requirements IPSec VPN throughput (AES-256,1420


byte)≥30 Gbps

Application controlling and IPS


throughput ≥ 15 Gbps;

SSL Inspection throughput ≥5.9 Gbps

Supports static routes, policy-based routing, and routing protocols such as


RIP, OSPF, BGP, and IS-IS;
Routing Policy-based routing supports the following matching conditions: source IP
address, destination IP address, service type, application type, user/user
group/security group, inbound interface, and DSCP priority.

Supports service-specific PBR and intelligent uplink selection based on multiple


Intelligent uplink selection load balancing algorithms (for example, based on bandwidth ratio and link
health status) in multi-egress scenarios.

Supports full NAT functions and NAT ALG for multiple application-layer
protocols, including ILS, DNS, PPTP, SIP, FTP, ICQ, RTSP, MSN, and MMS.

Supports Source NAT automatic detection and exclusion of invalid


NAT addresses in NAT address pools.
Firewall should support NAT444, NAT66
(IPv6‐to‐IPv6) , Nat46 (IPv4‐to‐IPv6)
and DS-Lite NAT
Supports IPSec VPN intelligent uplink selection to select the best link based on
link quality detection.

Support L2TP/GRE VPN, SSL VPN, MPLS VPN, Providing 100 SSL VPN
VPN
User License & Client software;

Supports DMVPN or similar VPN for full-mesh VPN, support dynamic public
IP address.

Supports application-layer protocol-base traffic control policies, including setting


the maximum bandwidth, guaranteed bandwidth, and protocol traffic priority.
Traffic control
Supports bandwidth guarantee based on users and IP addresses. Supports maximum
number of connections per IP address or user.

Supports attack detection and prevention based on over 7000 local signatures.

Supports the customization of intrusion prevention policy templates based on


scenarios.
Intrusion prevention and
antivirus Supports brute-force cracking prevention for common application services (HTTP,
FTP, SSH, SMTP, and IMAP) and database software (MySQL, Oracle, and MSSQL).
Supports malicious domain name-based filtering to block C&C.

Supports antivirus for protocols such as HTTP, FTP, SMTP, POP3, IMAP, and NFS.

over 120 million URLs and accelerates


access to specific categories of websites,
improving access experience of high
priority websites.

Supports DNS filtering, in which


URL filtering accessed web pages are filtered based on
domain names.

Supports the Safe Search function to filter


resources of search engines, such as
Google, to guarantee access to only
healthy network resources.
Supports data leak prevention to identify
and filter files and content (different types
of information, such as ID cards, credit
cards, debit cards, and social security
cards) during transit.
Data security
Supports DNS filtering to improve web
page filtering performance.

Supports Safe Search to filter out


unhealthy content returned by search
engines such as Google.

Supports application-layer flood attacks


such as HTTP, HTTPS, DNS, and SIP,
supports traffic auto-learning, the setting
DDoS defense of the auto-learning time, and automatic
generation of anti-DDoS policies.
Supports IP reputation

Supports interworking with the local


sandbox for APT defense.

Supports interworking with the Big Data


Intelligent threat prevention intelligent security analysis system to
implement posture awareness, display
network-wide threats, and generate
policies to block threats.

Allows users to configure security


policies based on time, user/user
group/security group, application-layer
protocol, geographical location, IP
address, port, domain name group, URL
Policy & Management category, access type, vlanID and content
security.

Provides northbound interfaces such as


RESTCONF and NETCONF APIs to
connect to third-party management
platforms.
Supports the analysis of policy risks and
redundancy, and provides security policy
tuning suggestions.

Supports multiple user authentication


methods, including local, RADIUS,
HWTACACS, AD, and LDAP.
Network access user
The firewall supports built-in Portal and
authentication
Portal redirection functions.

Supports AD SSO, RADIUS SSO,


NTLM authentication

Provides the related Full threats protection


License
License of 3 Years

Supports BFD link detection and


association of BFD and VRRP/OSPF to
implement rapid active/standby
switchover.
Reliability
Supports the smooth upgrade of
HA(Active/Active or Active/Standby)
Mode, the software of different versions
can be used for hot standby.

Has been listed as Leader or Challenger


Product certification
in Gartner Magic Quadrant;

Warranty Service 3 years 24x7 NBD warranty


Sr. No 2 Web Application Firewall Qty=01 (Mandatory)

Requirement
Solution Can Be Hardware Appliance OR Software Module
in Quoted NGFW Above
In case of HW appliance, must have
Must Have Minimum 2 x 1G Ethernet Interface
Must Have Minimum 4 x 10G SFP+ Interface Loaded with
4 x SR Multi-Mode Transceivers (Per Device)
Must Be Listed in NSS Labs for Web Application Firewall
Must Have Minimum 20Gbps Web Application Firewall
Throughput
Must Include AI-Based Machine Learning Threat Detection,
IP Geolocation, Data Leak Prevention, Brute Force
Protection, HTTP Header Security, Custom Error Message,
Error Code Handling and Local Report Center
Must Include Application Attack Protection, OWASP Top
10 Protection, Cross Site Scripting, SQL Injection, Cross
Site Request Forgery, Session Hijacking, Built-in
Vulnerability Scanner, File Upload Scanning with AntiVirus and Cloud-Based Sandbox
3 Years Complete Security Features License
3 Years Software Upgrade & 24x7 Technical Support
3 Years Hardware Warranty Service If Propose Hardware
Appliance
Must Quote Onsite Configuration & Installation
Must Quote Onsite Training & Product Certification For 5
Participants
Specifications for Server ((Mandatory)

Sr. No 3 Item Server Specifications


Form Factor 2U Rack mounted Server

Processor 2 x Intel Xeon Gold 6000 Series (2.3 GHz or higher), (16 cores, 24.75MB cache or
higher)

Memory 4 x 32GB DDR4 RDIMM, 2666 MHz or higher (24 DIMM slots required for further up
gradation upto 256GB)

Hard Drives 3 x 800GB SSD SAS Mix Use 12Gbps 512e 2.5in Hot-plug
4 x 2.4 TB 10K RPM SAS 12Gbps 512e 2.5in Hot-plug Hard or higher Drive
Scalable upto 8 HDDs (Chassis)
RAID Independent RAID controller card with Min. 2GB NV Cache or higher.
Controller Support RAID 0, 1, 5,6 or more
Network Dual Port 1GbE BASE-T
Adapter Dual Port 10 GbE BaseT
Power Supply Redundant hot-swappable and power cords

Stability Support long-term operating temperature under specific conditions

System Provide full features of server management, inclusive of integrated system


Management management, independent remote management

Management software capabilities include Capacity Management, Remote


management, Web Management, Configuration Management, Event
Scheduling, Alert Management, Failure Analysis software for processors, disks,
memory, voltage, power supplies, fans, temperature etc.
Chassis Chassis with up to 8 x 2.5" SAS/SATA Hard Drives for 2CPU Configuration
Rack Mountable tool less chassis with rack rails & cable management arm
Accessories Side rails and Cable management arm

Compatibility Supports mainstream operating systems, such as Windows, Linux, SuSE Linux and
VMware

Principle Principal presence in Pakistan for last 3 years


Presence
MAL Valid Authorized letter from Manufacturer.
The warranty and specifications (Part No.) must reflect on the authorized portal of
the principal against the service tag.
Specifications for Software & Internet (Mandatory)

Sr. No Items Specification Quantity

4 Server Red Hat Linux (Enterprise Version)/Latest 01 (for 3 years/ May


Software OR extended)
suitable operating system for CPIMS Application

5 Server 01 (for 3 years/ May


Software ESXI (version 7.0) For two slots Server extended)

6 Pub 01 or APA
Software Microsoft Office Suite 365 (family ver. for 6 users)

7 Pub PDF editor | Adobe Acrobat 01 or APA


Software

8 Internet Pool of ‘real’ IP addresses 5 or APA

Specifications for Laptops (Mandatory)

Sr. No. Item Specifications

9 Laptops Processor 11th Generation Intel® Core™ i9-11900H (24MB Cache, up to


4.9 GHz, 8 cores or Higher)
Memory 32GB, 16GBx2, DDR4 3200MHz

Hard Drive 1 TB M.2 PCIe NVMe Solid State Drive

Display 13" / 14" OLED 3.5K (3456x2160) InfinityEdge Touch Anti-


Reflective 400-Nit Display
Graphic Card NVIDIA® GeForce RTX™ 3050 Ti 4GB GDDR6
Connectivity Must Support Wi-Fi 6 + Bluetooth 5.1

Camera 720p at 30 fps HD camera

Keyboard Backlit keyboard, US/International

You might also like