منافسة عامة
قيد التنفيذ
دعم محاكم الاستئناف بأجهزة الربط الذكية (SD-WAN)
وزارة العدل - الديوان العام
رقم المنافسة
210839409070
المعرّف
#276676
| التاريخ | ميلادي | هجري |
|---|---|---|
| تاريخ النشر | 2021/08/31 08:45 | — |
| آخر موعد للاستفسارات | 2021/09/30 | 1443-02-23 |
| آخر موعد تقديم العروض | 2021/10/05 09:30 | 1443-02-28 |
| موعد فتح العروض | 2021/10/05 10:00 | 1443-02-28 |
| موعد فحص العروض | — | — |
| التاريخ المتوقع للترسية | — | — |
| تاريخ بدء الأعمال | — | — |
| تاريخ خطاب تأكيد المشاركة | — | — |
| بداية إرسال الأسئلة | — | — |
موقع التنفيذ
مجال التصنيف
جدول 1 المعدات والأجهزة - تقنية معلومات
| البند | العدد | وصف البند | المواصفات | وحدة القياس | الرقم التسلسلي | منتج من القائمة الإلزامية | ملف البند |
|---|---|---|---|---|---|---|---|
| 1 | 6 | جهاز الشبكة لمركزي المعلومات الرئيسى والاحتياطي uCPE | توريد جهاز موجه الشبكة متوافق مع الأجهزة الموجودة في الجهة الحكومية بحيث يكون بالمواصفات الفنية التالية: uCPE should deliver highly secure data, voice, video, and application services to MPLS Cloud with the following components: 16 cores CPUs intel Skylake Product Preinstalled Application Premier Elite SD-WAN License 4 x 1000BASE-T 2 x 10G SFP/SFP+ 2 x SFP+ SR are included Internal storage 1 TB SSD Memory: 64GB Support for 3 years from vendor. In addition, the router should support the following features: CPU Model : Intel Skylake XEON-D (D-2187NT) CPU Frequency : 2.0 GHz CPU Cores : 16 CPU Socket Count : 1 QAT Co-Processor (Quick Assist Technology) : Yes (100Gb/s) CPU Socket Count : 1 SoC (System On a Chip) : Yes Preinstalled Application(s) : Product Memory : 64GB ECC Memory Configuration : 2x32GB DDR4 DIMM Memory Slots : 4xDDR4 2400 MT/s Memory Max Configuration : 64GB Storage : 1TB Storage Configuration : 1xM.2 SATA SSD Storage Slots : 2 Storage Max Configuration : 2TB Serial Port(s) : 1xBMC , 1xCPU USB Serial Port : 1xMicro USB Management Port(s) : 1x10/100/1000BaseT (BMC) ; 1x10/100/1000BaseT (CPU) Networking Ports : 6x10G SFP+ ; 4x10/100/1000BaseT Additional Expanion : 2xM.2 Additional USB Ports : 2xUSB 3.0 Chassis Form Factor : 1 RU Power Supply : Dual 495W Power Supply Max Configuration : 2 Cooling Fan(s) : 5 TMP (Trust Platfom Module) : Yes IPMI 2.0 Compliant : Yes | جهاز | 1 | 0 | — |
| 2 | 20 | جهاز الشبكة للمواقع الكبيرة uCPE | توريد جهاز موجه الشبكة متوافق مع الأجهزة الموجودة في الجهة الحكومية بحيث يكون بالمواصفات الفنية التالية: uCPE should deliver highly secure data, voice, video, and application services to MPLS Cloud with the following components: 8 cores CUPs intel Skylake Product Preinstalled Application Premier Elite SD-WAN License 4 x 1000BASE-T 2 x 10G SFP/SFP+ Internal storage 240GB SSD Memory: 64GB Support for 3 years from vendor. In addition, the router should support the following features: CPU Model : Intel Skylake XEON-D (D-2145NT) CPU Frequency : 1.9 GHz CPU Cores : 8 CPU Socket Count : 1 QAT Co-Processor (Quick Assist Technology) : Yes (100Gb/s) CPU Socket Count : 1 SoC (System On a Chip) : Yes Preinstalled Application(s) : Product Memory : 64GB ECC Memory Configuration : 2x32GB DDR4 DIMM Memory Slots : 4xDDR4 2400 MT/s Memory Max Configuration : 64GB Storage : 256GB Storage Configuration : 1xM.2 SATA SSD Storage Slots : 2 Storage Max Configuration : 2TB Serial Port(s) : 1xBMC , 1xCPU USB Serial Port : 1xMicro USB Management Port(s) : 1x10/100/1000BaseT (BMC) ; 1x10/100/1000BaseT (CPU) Networking Ports : 2x10G SFP+ ; 4x10/100/1000BaseT Additional Expanion : 2xM.2 Additional USB Ports : 2xUSB 3.0 Chassis Form Factor : 1 RU Power Supply : Dual 495W Power Supply Max Configuration : 2 Cooling Fan(s) : 4 TMP (Trust Platfom Module) : Yes IPMI 2.0 Compliant : Yes | جهاز | 2 | 0 | — |
| 3 | 130 | جهاز الشبكة للمواقع الصغيرة uCPE | توريد جهاز موجه الشبكة متوافق مع الأجهزة الموجودة في الجهة الحكومية بحيث يكون بالمواصفات الفنية التالية: uCPE should deliver highly secure data, voice, video, and application services to MPLS Cloud with the following components: 8 cores CUPs intel Skylake Product Preinstalled Application Premier Elite SD-WAN License 4 x 1000BASE-T 2 x 10G SFP/SFP+ Internal storage 240GB SSD Memory: 64GB Support for 3 years from vendor. In addition, the router should support the following features: CPU Model : Intel Skylake XEON-D (D-2145NT) CPU Frequency : 1.9 GHz CPU Cores : 8 CPU Socket Count : 1 QAT Co-Processor (Quick Assist Technology) : Yes (100Gb/s) CPU Socket Count : 1 SoC (System On a Chip) : Yes Preinstalled Application(s) : Product Memory : 64GB ECC Memory Configuration : 2x32GB DDR4 DIMM Memory Slots : 4xDDR4 2400 MT/s Memory Max Configuration : 64GB Storage : 256GB Storage Configuration : 1xM.2 SATA SSD Storage Slots : 2 Storage Max Configuration : 2TB Serial Port(s) : 1xBMC , 1xCPU USB Serial Port : 1xMicro USB Management Port(s) : 1x10/100/1000BaseT (BMC) ; 1x10/100/1000BaseT (CPU) Networking Ports : 2x10G SFP+ ; 4x10/100/1000BaseT Additional Expanion : 2xM.2 Additional USB Ports : 2xUSB 3.0 Chassis Form Factor : 1 RU Power Supply : Dual 495W Power Supply Max Configuration : 2 Cooling Fan(s) : 4 TMP (Trust Platfom Module) : Yes IPMI 2.0 Compliant : Yes | جهاز | 3 | 0 | — |
| 4 | 300 | محول Transceiver, SFP+,LC,SR,1G,10G | يلتزم المتعاقد بتوريد أجهزة مدخل ألياف ضوئية أصلية من نفس ماركة الشركة المصنعة لأجهزة للشبكة uCPE مع الالتزام بالمواصفات التالية SFP 10/1 Gigabit MultiMode | جهاز | 4 | 0 | — |
| 5 | 2 | جهاز الشبكة لل Controllers uCPE | توريد جهاز موجه الشبكة متوافق مع الأجهزة الموجودة في الجهة الحكومية بحيث يكون بالمواصفات الفنية التالية: uCPE should deliver highly secure data, voice, video, and application services to MPLS Cloud with the following components: 16 cores CUPs intel Skylake Product Preinstalled Application Premier Elite SD-WAN License 4 x 1000BASE-T 2 x 10G SFP/SFP+ 2 x SFP+ SR are included Internal storage 1 TB SSD Memory: 64GB Support for 3 years from vendor. In addition, the router should support the following features: CPU Model : Intel Skylake XEON-D (D-2187NT) CPU Frequency : 2.0 GHz CPU Cores : 16 CPU Socket Count : 1 QAT Co-Processor (Quick Assist Technology) : Yes (100Gb/s) CPU Socket Count : 1 SoC (System On a Chip) : Yes Preinstalled Application(s) : Product Memory : 64GB ECC Memory Configuration : 2x32GB DDR4 DIMM Memory Slots : 4xDDR4 2400 MT/s Memory Max Configuration : 64GB Storage : 1TB Storage Configuration : 1xM.2 SATA SSD Storage Slots : 2 Storage Max Configuration : 2TB Serial Port(s) : 1xBMC , 1xCPU USB Serial Port : 1xMicro USB Management Port(s) : 1x10/100/1000BaseT (BMC) ; 1x10/100/1000BaseT (CPU) Networking Ports : 6x10G SFP+ ; 4x10/100/1000BaseT Additional Expanion : 2xM.2 Additional USB Ports : 2xUSB 3.0 Chassis Form Factor : 1 RU Power Supply : Dual 495W Power Supply Max Configuration : 2 Cooling Fan(s) : 5 TMP (Trust Platfom Module) : Yes IPMI 2.0 Compliant : Yes | جهاز | 5 | 0 | — |
| 6 | 2 | جهاز الشبكة لل PE Routers uCPE | توريد جهاز موجه الشبكة متوافق مع الأجهزة الموجودة في الجهة الحكومية بحيث يكون بالمواصفات الفنية التالية: uCPE should deliver highly secure data, voice, video, and application services to MPLS Cloud with the following components: 8 cores CUPs intel Skylake Product Preinstalled Application Premier Elite SD-WAN License 4 x 1000BASE-T 2 x 10G SFP/SFP+ Internal storage 240GB SSD Memory: 64GB Support for 3 years from vendor. In addition, the router should support the following features: CPU Model : Intel Skylake XEON-D (D-2145NT) CPU Frequency : 1.9 GHz CPU Cores : 8 CPU Socket Count : 1 QAT Co-Processor (Quick Assist Technology) : Yes (100Gb/s) CPU Socket Count : 1 SoC (System On a Chip) : Yes Preinstalled Application(s) : Product Memory : 64GB ECC Memory Configuration : 2x32GB DDR4 DIMM Memory Slots : 4xDDR4 2400 MT/s Memory Max Configuration : 64GB Storage : 256GB Storage Configuration : 1xM.2 SATA SSD Storage Slots : 2 Storage Max Configuration : 2TB Serial Port(s) : 1xBMC , 1xCPU USB Serial Port : 1xMicro USB Management Port(s) : 1x10/100/1000BaseT (BMC) ; 1x10/100/1000BaseT (CPU) Networking Ports : 2x10G SFP+ ; 4x10/100/1000BaseT Additional Expanion : 2xM.2 Additional USB Ports : 2xUSB 3.0 Chassis Form Factor : 1 RU Power Supply : Dual 495W Power Supply Max Configuration : 2 Cooling Fan(s) : 4 TMP (Trust Platfom Module) : Yes IPMI 2.0 Compliant : Yes | جهاز | 6 | 0 | — |
| 7 | 2 | الرخص الخاصة بمركز المعلومات الرئيسي DCSDWAN license 2 Gbps | توريد رخص محولات الشبكة بحيث يكون بالمواصفات الفنية التالية: Product Premier Elite SD-WAN license with 2 Gbps Bandwidth Tier, SDWAN Software should deliver highly secure data, voice, video, and application and should support all advanced SDWAN, NGFW And UTM features, with support for 3 years from vendor. (Note: quantities and bandwith as per the quantity table) In addition, the license should support the following features and capabilities: • QoS (Classification, DSCP marking, HQoS, Traffic shapers & Adaptive rate limiting) • ZTP (ZTP agent & server, 2-factor authentication, Auto upgrade, configuration, Global ZTP server based, Encrypted URL based, Controller for ZTP and securing management channel and Certificate based authentication) • Deployment Options (Whiteboxes, Virtual, Physical, Azure cloud, AWS cloud, GCE cloud and Alibaba cloud) • Provisioning (Template-based provisioning, Custom parameterization and Zero Touch provisioning) • Other Platform Capabilities o Quick Assist support (hw based encryption/decryption) o TPM chip for storing keys & sensitive data • uCPE o uCPE - platform level support w/service chaining o uCPE - 3rd party VM Lifecycle Management • Interface Features o VLAN tagging - single tags, dual tags o Aggregated Ethernet (on LAN interfaces) o PPPoE o T1/E1 interfaces o PPP on T1/E1 interfaces o HDLC on T1/E1 interfaces o ADSL2+/VDSL2 interface support o ATM over xDSL interfaces • Layer 2 - Bridging in Software o Virtual Switch and Bridge Domain instances o VLAN translation o Access and Trunk interfaces o xSTP - as active loop detection o Passive Loop detection o Uplink failure detection for faster convergence o LLDP & IRB • Routing o Static Routing, BFD, ECMP, Policy based routing, Route Reflector o OSPF v2/v3, MP-BGP4, MP-BGP IPv6 SAFI support, RIPv2 o VRRP, VRFs • Multicast o IGMP v2/3 (LAN intf) o PIM SM (LAN/WAN) o PIM SSM o PIM RP, Bootstrap RP, Anycast RP o Anycast RP o Multicast across LAN, WAN interfaces, SD-WAN tunnels • IP Address Management o DHCP client o DHCP relay o DHCP server o DHCP v6 client o DHCP v6 server • CGNAT o Static, Dynamic, NATPT, ALG support, EIM/EIF o PBA support, CGNAT64 • MPLS VPN o MPLS BGP L3VPN o MPLS based EVPNs across SD-WAN tunnels • IKE based IPSec VPN Tunnels o IKEv2/v1 o Pre-shared key/PKI authentication o Dead peer detection o Diffie-Hellman key negotiation o AES 128/256 encryption (IKE/IPsec) o SHA1/SHA256/SHA384/SHA512/null hashing o NAT traproduct l o Perfect forward secrecy o IPsec rekey time/volume based o Anti-replay o Pre/post fragmentation o Route based VPN o IPv6 based IPSec support o Dual Stack support • Stateful (L4) Firewall o Zone and endpoint based stateful firewall o 5 tuple flows based (zone, address, user, region), Geo-IP, blacklisting o Rich actions (accept, drop/discard, rate-limit, log) o ALG support o Flow Mirroring o IPv6 support • DOS Protection o Aggregate and classified DDoS profiles o L3 ICMP Flood, IP flood o UDP, TCP SYN flood o ICMPv6 flood o SCTP flood o Port scans and host sweeps o L2-L4 anomaly detection o IPv6 support • Application Visibility o Identification of 3000+ applications & protocols o Support for user-defined applications & app groups o Support for user defined application filters based on any combination of family, subfamily, risk, product ivity & tag o Nested application support o Enable packet capture based on known/unknown applications • SD-WAN Deployment Options o Behind a NAT device/firewall o Encrypted and Non-encrypted overlays with MPLS/GRE or VXLAN o SD-WAN Controller o WAN circuit support o Full Mesh Topology o Hub-Spoke Topology o Spoke-Hub-Hub-Spoke o Controller behind branch / hub o Collapsed Conroller & Hub (consolidation) o Any Topology o Dynamic IPSec overlays o Direct Internet Access o Number of WAN Links • Carrier-grade SD-WAN o MP-BGP route exchange with SDN controller o Primary to secondary WAN link failover in < 2 seconds o OAM – Handle branch device / link failure to the controller o OAM – Redundant controllers o Multi-tenancy o Stateful high-availability o Link aggregation o Hierarchical QoS o Per tunnel QoS o LTE network optimized probing (adaptive probing) o Shared multi-tenant control plane o Overlay encapsulation options (VXLAN, IPSec) • Dynamic IPSec VPN Tunnel Overlays o Secure (and separate) control and data channels o Automatic Key Management o Secure on-demand data channels with unique key pairs between any two sites o Two factor authentication o Automatic certificate lifecycle management o Control Plane based - dynamic – OTT topology based IPSec tunnels for data • Traffic Steering o Route based traffic steering o Seamless integration with WAN optimization devices o App based intelligent path selection – fixed criteria o App based intelligent path selection – user-defined criteria, least cost, high bandwidth paths o URL based traffic management o IPv6 support • Application traffic management o Application based traffic steering o AppQoS – Traffic shaping o AppQoS – Rate limiting o Application-based SLAs o Selective application encryption (ie: encryption based on app or traffic type) o Application blocking • Uniproduct l SD-WAN Migration Gateway o BGP based SD-WAN gateway o IPSec based SD-WAN gateway o Application performance-based gateway • User & Group Level Traffic Control for SD-WAN o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o SD-WAN QoS Control support by User-ID, Group o SD-WAN Traffic Engineering Policy Control support by User-ID, Group o SD-WAN L7 SLA policy based traffic engineering by User-ID and Group • L4 Load Balancer o Layer 4 load balancing o LB algorithms – Hash/RR/Cost o Persistence profiles o Health monitoring – L4 based (TCP/ICMP) o Health monitoring – L7 based (HTTP) o Direct server return – L2 o Direct server return – L3 o Traffic Load Balancer (TLB) and ADC functionality o LB behind NAT – reverse proxy forwarding o High-availability – active-backup • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • Next-Generation (L7) Firewall o L7 application-based policies o Application triggers - family/sub family, risk, product ivity, tags o Device Identifiction, fingerprinting and logging o Device ID based traffic management policies • Network Access Control o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o 802.1x with RADIUS back-end o 802.1x Certificate and MAC based access control o Policy trigger support by User-ID, Group • Product Forward Proxy o DIA/DCA use-case coverage o SSL-TLS Proxy o Security Service Chaining • URL/Content Filtering & Captive Portal o Predefined/user defined categories and actions o Whitelist/blacklist o Search patterns/strings o Web reputation feeds o Reputation/category based actions / captive portal o URL filter based captive portal w/ rich set of actions o Intelligent Path selection based on URL category o Custom action messages o IPv6 Support (URL Identification and Traffic Engineering) o IPv6 Support (Categoization and Reputation) • Application traffic conditioning o Forward Error Correction (FEC) o Packet Cloning - Decloning o Packet Striping across SD-WAN path bundle o CODEC support for Voice and Video flows o MOS Score based Traffic Engineering for Voice flows o MOS Score based Traffic Engineering for Video flows o DIA/DCA Traffic Optimizations for Cloud SaaS sites o First packet-based traffic steering o IPv6 support • TCP Optimization o TCP Proxy for bookended or single ended deployments o TCP SACK, Window Scaling, Timestamping support o Intelligent TCP Buffer management o Improved TCP Loss Recovery Techniques o Integrated latest congestion control algorithms to manage congestion and random traffic loss • Antivirus o Multiple file types o Multiple protocol detection - FTP, HTTP, Email o Compressed file type detection o Nested compression o Packet direction – client/server • NG-IPS o Vulnerability Profiles by CVE ID/signature set /CVSS Score/Packet direction/Class o Multiple Vulnerability DB Reference o OS/Product based o Signature based & Protocol Anomaly based detection o Packet capture - pre & post window o WAN circuit support o L7 anomaly detection o Javascript anomaly detection • SSL & TLS Proxy o SSL Inspection for invalid, expired, untrusted certificates o HTTPS Proxy o SSLv4 & TLS 1.2 Proxy • File Filtering & DLP o File Feeds and Filtering All below features should be supported for the uCPE/CPE and SDWAN licenses: 1. CPE models of different manufacturers should be used in the edge devices used in SD-WAN architecture. 2. All the routing, sdwan and security features should be delivered with the same device or operating system in a modular way. 3. CPEs will be able to terminate 3G / 4G, MPLS and Internet connection types at the same time. These lines should be able to be used as each application-based active at the same time or different connections for different applications as active other connections as backup. 4. When using multiple connections on the CPE, it should be preconfigured that certain applications do not use certain lines as backup, while all traffic is switched to redundant lines in case of an outage. 5. User-based traffic routing and security policies should be created on CPEs. A local user database should be able to be created over CPEs. In addition, it should be possible to integrate with external user databases via LDAP or Kerberos. 6. CPE options that can actively support at least 3 different physical WAN connections on a single device should be provided. 7. Static Routing, OSPFv2, OSPFv3, BGP protocols must be supported on CPE. 8. More than one VRF should be opened on the CPE and these VRFs should not be allowed to communicate with each other. 9. Recommended SD-WAN solution should support IPv6. In addition, IPv6 should be available for the specified protocols; OSPFv3, DHCPv6 client and server, QoS Profiles, IPsec VPN, Stateful Firewall Application Gateway, DoS, SD-WAN Underlay Support, Dual Stack. 10. CPEs should be able to be located in a redundant structure and two CPEs for each location should be able to work actively. In the event of a single device failure, the other device must be able to meet all traffic and technical requirements within the scope. 11. Two CPEs should be able to be redundantly located in the locations. Regardless of the types of uplinks coming to the CPEs, for example, if there is an MPLS and Internet connection on the CPE number 1 and there is an Internet and LTE connection on the number 2 CPE, the number 1 CPE should be able to use the 4 uplinks in the location as active active or active passive. 12. Different layers 2 and 3 networks isolated from each other should be created on the CPE. 13. CPEs should be able to directly bring the desired traffic directly to the internet without carrying it over SD-WAN and this process should not cause security weakness. 14. In the software on the CPE, the security functions listed below will be supported or if a different VNF will be installed on the CPE for this process, the relevant VNF or physical device should be added to each location within the offer, and their integration should be made to work smoothly. a. Carrier Grade NAT b. NAT64 & DNS64 c. Stateful Firewall d. NextGen Firewall e. URL Filtering f. SSL Decrytion g. DdoS h. File Blocking i. Anti-Virus j. Intrusion Prevention System k. DNS based Security File Blocking l. Anti-Virus m. Intrusion Prevention System n. DNS based Security 15. Proposed CPEs will support the uCPE feature and VNF of a different manufacturer can be operated on the CPE located in the locations if desired. 16. Traffic on the device should be able to be routed based on application. 17. Inter-location line qualities should be measured continuously. Traffic should be routed depending on Packet Loss, Delay and Jitter values. For traffic routing, application-based routing should be possible depending on the SLA conditions. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 18. While more than one line is used simultaneously, the line with the lowest delay should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest delay should be able to use all lines actively. 19. While more than one line is used simultaneously, the line with the Least Packet Loss should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest packet loss should be able to use all lines actively. 20. While more than one line is used actively simultaneously, the line with the Lowest Jitter value should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest jitter value should be able to use all lines actively. 21. If there is more than one line between the locations, the lines should be given priority value. This prioritization should be application-based. 22. Load balancing should be possible on lines located between locations. Load distribution should be made in direct proportion to the bandwidth of the lines. If this feature is not supported on CPE, each separate system must be installed and integrated with the SD-WAN management system. 23. For high-precision traffic types such as Voice and Video, MOS Scores that determine the application quality should be able to calculate between locations and Audio / Video traffic routing should be made accordingly. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 24. CPEs should support advanced SD-WAN features such as Forward Error Correction and Packet Cloning. 25. SD-WAN management should be over a single system. All operations mentioned above should be done through a single interface. System resources and connection status of the devices positioned with this interface should be monitored instantly. In addition, this interface should include diagnostic tools in order to detect system problems. 26. When necessary, SSH or Web connection should be made to CPEs and configuration can be made through them. 27. CPE version updates should be available from the central management unit or directly from the CPE. 28. Security signature database should be able to be sent to CPEs from the central management unit. 29. The security signature database should be able to be loaded directly on the CPEs via internet connection, and periodic timing settings for downloading should be made. 30. All elements in SD-WAN management systems should be geo-redundantly located if desired, and synchronization should be provided between backup locations without the need for Layer 2 connection. 31. Role-based control should be supported on the central application for management purposes. 32. IPSec based security should be supported for both control plane and data plane. 33. Network-based Hub-Spoke or Full-Mesh structures must be configured simultaneously using the same devices on the system. 34. In Hub-Spoke configuration on the system, it should be allowed to simultaneously open Spoke-Spoke, Spoke-Spoke via Hub or only Hub-Spoke access on the same device for different networks. 35. ZTP (Zero Touch Provisining) should be done using the central management system installed in the data center, without the need for cloud. ZTP should be url based or script based. 36. No cloud system from abroad should be required for the management of systems and analytics operations. 37. Network or application based QoS should be able to be done on the product and it should support Hierarchical QoS, AppQoS. 38. DHCP client / server and DHCP Option and DHCP relay must be supported on the device. 39. Different VLANs on CPE can be given over the same port as well as secondary IP address should be assigned for each VLAN. 40. The device will have Syslog and SNMP support. 41. Configuration templates should be created in SD-WAN management system and these templates should be applied to more than one device simultaneously. 42. Speed tests between different locations should be made on demand or dynamically. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 43. All configurations mentioned in the specification and made on the CPE should be able to be made over the central system. 44. URL-based traffic routing should be able to be done on CPEs. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 45. IGMPv2, IGMPv3, PIM-SM and PIM-SSM multicast protocols must be supported. 46. Important information such as protocol passwords, IPSEC PSK values should be kept hashed (hash) in the configurations and templates on the CPEs and the central management system. 47. The software on the CPEs must support Layer 2 Forwarding configuration. a. Virtual Switches b. Bridge Domains c. Bridge Interfaces d. Integrated routing and bridging (IRB) interfaces e. STP / RSTP f. Layer 2 Forwarding additional functions listed below will be supported in the software on the CPE. g. EVPN over SD-WAN h. Multiple Spanning-Tree Protocol (MSTP) i. VLAN Translation 48. TCP and DIA & DCA (SaaS) optimization should be supported. SaaS applications should be recognizable at the end point with the first package inspection. 49. SD-WAN solution should be able to provide Secure Access Service with a client to be installed on end user equipment (Windows 10, MacOS, Android). 50. Network Analysis information kept on SD-WAN management system should be turned off or restricted when necessary. 51. SD-WAN service provider should be able to provide Role-based access control over SD-WAN management system. 52. TCP optimization should be supported | رخصة | 7 | 0 | — |
| 8 | 2 | الرخص الخاصة بمركز المعلومات الاحتياطي DRSDWAN licenes 1Gbps | توريد رخص محولات الشبكة بحيث يكون بالمواصفات الفنية التالية: Product Premier Elite SD-WAN license with 1 Gbps Bandwidth Tier, SDWAN Software should deliver highly secure data, voice, video, and application and should support all advanced SDWAN, NGFW And UTM features, withsu pport for 3 years from vendor. (Note: quantities and bandwith as per the quantity table) In addition, the license should support the following features and capabilities: • QoS (Classification, DSCP marking, HQoS, Traffic shapers & Adaptive rate limiting) • ZTP (ZTP agent & server, 2-factor authentication, Auto upgrade, configuration, Global ZTP server based, Encrypted URL based, Controller for ZTP and securing management channel and Certificate based authentication) • Deployment Options (Whitebox, Virtual, Physical, Azure cloud, AWS cloud, GCE cloud and Alibaba cloud) • Provisioning (Template-based provisioning, Custom parameterization, and Zero Touch provisioning) • Other Platform Capabilities o Quick Assist support (hw based encryption/decryption) o TPM chip for storing keys & sensitive data • uCPE o uCPE - platform level support w/service chaining o uCPE - 3rd party VM Lifecycle Management • Interface Features o VLAN tagging - single tags, dual tags o Aggregated Ethernet (on LAN interfaces) o PPPoE o T1/E1 interfaces o PPP on T1/E1 interfaces o HDLC on T1/E1 interfaces o ADSL2+/VDSL2 interface support o ATM over xDSL interfaces • Layer 2 - Bridging in Software o Virtual Switch and Bridge Domain instances o VLAN translation o Access and Trunk interfaces o xSTP - as active loop detection o Passive Loop detection o Uplink failure detection for faster convergence o LLDP & IRB • Routing o Static Routing, BFD, ECMP, Policy based routing, Route Reflector o OSPF v2/v3 , MP-BGP4 , MP-BGP IPv6 SAFI support , RIPv2 o VRRP , VRFs • Multicast o IGMP v2/3 (LAN intf) o PIM SM (LAN/WAN) o PIM SSM o PIM RP, Bootstrap RP, Anycast RP o Anycast RP o Multicast across LAN, WAN interfaces, SD-WAN tunnels • IP Address Management o DHCP client o DHCP relay o DHCP server o DHCP v6 client o DHCP v6 server • CGNAT o Static , Dynamic, NATPT, ALG support, EIM/EIF o PBA support, CGNAT64 • MPLS VPN o MPLS BGP L3VPN o MPLS based EVPNs across SD-WAN tunnels • IKE based IPSec VPN Tunnels o IKEv2/v1 o Pre-shared key/PKI authentication o Dead peer detection o Diffie-Hellman key negotiation o AES 128/256 encryption (IKE/IPsec) o SHA1/SHA256/SHA384/SHA512/null hashing o NAT traproduct l o Perfect forward secrecy o IPsec rekey time/volume based o Anti-replay o Pre/post fragmentation o Route based VPN o IPv6 based IPSec support o Dual Stack support • Stateful (L4) Firewall o Zone and endpoint based stateful firewall o 5 tuple flows based (zone, address, user, region), Geo-IP, blacklisting o Rich actions (accept, drop/discard, rate-limit, log) o ALG support o Flow Mirroring o IPv6 support • DOS Protection o Aggregate and classified DDoS profiles o L3 ICMP Flood, IP flood o UDP, TCP SYN flood o ICMPv6 flood o SCTP flood o Port scans and host sweeps o L2-L4 anomaly detection o IPv6 support • Application Visibility o Identification of 3000+ applications & protocols o Support for user-defined applications & app groups o Support for user defined application filters based on any combination of family, subfamily, risk, product ivity & tag o Nested application support o Enable packet capture based on known/unknown applications • SD-WAN Deployment Options o Behind a NAT device/firewall o Encrypted and Non-encrypted overlays with MPLS/GRE or VXLAN o SD-WAN Controller o WAN circuit support o Full Mesh Topology o Hub-Spoke Topology o Spoke-Hub-Hub-Spoke o Controller behind branch / hub o Collapsed Conroller & Hub (consolidation) o Any Topology o Dynamic IPSec overlays o Direct Internet Access o Number of WAN Links • Carrier-grade SD-WAN o MP-BGP route exchange with SDN controller o Primary to secondary WAN link failover in < 2 seconds o OAM – Handle branch device / link failure to the controller o OAM – Redundant controllers o Multi-tenancy o Stateful high-availability o Link aggregation o Hierarchical QoS o Per tunnel QoS o LTE network optimized probing (adaptive probing) o Shared multi-tenant control plane o Overlay encapsulation options (VXLAN, IPSec) • Dynamic IPSec VPN Tunnel Overlays o Secure (and separate) control and data channels o Automatic Key Management o Secure on-demand data channels with unique key pairs between any two sites o Two factor authentication o Automatic certificate lifecycle management o Control Plane based - dynamic – OTT topology based IPSec tunnels for data • Traffic Steering o Route based traffic steering o Seamless integration with WAN optimization devices o App based intelligent path selection – fixed criteria o App based intelligent path selection – user-defined criteria, least cost, high bandwidth paths o URL based traffic management o IPv6 support • Application traffic management o Application based traffic steering o AppQoS – Traffic shaping o AppQoS – Rate limiting o Application-based SLAs o Selective application encryption (ie: encryption based on app or traffic type) o Application blocking • Uniproduct l SD-WAN Migration Gateway o BGP based SD-WAN gateway o IPSec based SD-WAN gateway o Application performance-based gateway • User & Group Level Traffic Control for SD-WAN o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o SD-WAN QoS Control support by User-ID, Group o SD-WAN Traffic Engineering Policy Control support by User-ID, Group o SD-WAN L7 SLA policy based traffic engineering by User-ID and Group • L4 Load Balancer o Layer 4 load balancing o LB algorithms – Hash/RR/Cost o Persistence profiles o Health monitoring – L4 based (TCP/ICMP) o Health monitoring – L7 based (HTTP) o Direct server return – L2 o Direct server return – L3 o Traffic Load Balancer (TLB) and ADC functionality o LB behind NAT – reverse proxy forwarding o High-availability – active-backup • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • Next-Generation (L7) Firewall o L7 application based policies o Application triggers - family/sub family, risk, product ivity, tags o Device Identifiction, fingerprinting and logging o Device ID based traffic management policies • Network Access Control o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o 802.1x with RADIUS back-end o 802.1x Certificate and MAC based access control o Policy trigger support by User-ID, Group • Product Forward Proxy o DIA/DCA use-case coverage o SSL-TLS Proxy o Security Service Chaining • URL/Content Filtering & Captive Portal o Predefined/user defined categories and actions o Whitelist/blacklist o Search patterns/strings o Web reputation feeds o Reputation/category based actions / captive portal o URL filter based captive portal w/ rich set of actions o Intelligent Path selection based on URL category o Custom action messages o IPv6 Support (URL Identification and Traffic Engineering) o IPv6 Support (Categoization and Reputation) • Application traffic conditioning o Forward Error Correction (FEC) o Packet Cloning - Decloning o Packet Striping across SD-WAN path bundle o CODEC support for Voice and Video flows o MOS Score based Traffic Engineering for Voice flows o MOS Score based Traffic Engineering for Video flows o DNA assisted Traffic Steering o DIA/DCA Traffic Optimizations for Cloud SaaS sites o First packet based traffic steering o IPv6 support • TCP Optimization o TCP Proxy for bookended or single ended deployments o TCP SACK, Window Scaling, Timestamping support o Intelligent TCP Buffer management o Improved TCP Loss Recovery Techniques o Integrated latest congestion control algorithms to manage congestion and random traffic loss • Antivirus o Multiple file types o Multiple protocol detection - FTP, HTTP, Email o Compressed file type detection o Nested compression o Packet direction – client/server • NG-IPS o Vulnerability Profiles by CVE ID/signature set /CVSS Score/Packet direction/Class o Multiple Vulnerability DB Reference o OS/Product based o Signature based & Protocol Anomaly based detection o Packet capture - pre & post window o WAN circuit support o L7 anomaly detection o Javascript anomaly detection • SSL & TLS Proxy o SSL Inspection for invalid, expired, untrusted certificates o HTTPS Proxy o SSLv4 & TLS 1.2 Proxy • File Filtering & DLP o File Feeds and Filtering All below features should be supported for the uCPE/CPE and SDWAN licenses: 53. CPE models of different manufacturers should be used in the edge devices used in SD-WAN architecture. 54. CPEs will be able to terminate 3G / 4G, MPLS and Internet connection types at the same time. These lines should be able to be used as each application-based active at the same time or different connections for different applications as active other connections as backup. 55. When using multiple connections on the CPE, it should be preconfigured that certain applications do not use certain lines as backup, while all traffic is switched to redundant lines in case of an outage. 56. User-based traffic routing and security policies should be created on CPEs. A local user database should be able to be created over CPEs. In addition, it should be possible to integrate with external user databases via LDAP or Kerberos. 57. CPE options that can actively support at least 3 different physical WAN connections on a single device should be provided. 58. Static Routing, OSPFv2, OSPFv3, BGP protocols must be supported on CPE. 59. More than one VRF should be opened on the CPE and these VRFs should not be allowed to communicate with each other. 60. Recommended SD-WAN solution should support IPv6. In addition, IPv6 should be available for the specified protocols; OSPFv3, DHCPv6 client and server, QoS Profiles, IPsec VPN, Stateful Firewall Application Gateway, DoS, SD-WAN Underlay Support, Dual Stack. 61. CPEs should be able to be located in a redundant structure and two CPEs for each location should be able to work actively. In the event of a single device failure, the other device must be able to meet all traffic and technical requirements within the scope. 62. Two CPEs should be able to be redundantly located in the locations. Regardless of the types of uplinks coming to the CPEs, for example, if there is an MPLS and Internet connection on the CPE number 1 and there is an Internet and LTE connection on the number 2 CPE, the number 1 CPE should be able to use the 4 uplinks in the location as active active or active passive. 63. Different layers 2 and 3 networks isolated from each other should be created on the CPE. 64. CPEs should be able to directly bring the desired traffic directly to the internet without carrying it over SD-WAN and this process should not cause security weakness. 65. In the software on the CPE, the security functions listed below will be supported or if a different VNF will be installed on the CPE for this process, the relevant VNF or physical device should be added to each location within the offer, and their integration should be made to work smoothly. a. Carrier Grade NAT b. NAT64 & DNS64 c. Stateful Firewall d. NextGen Firewall e. URL Filtering f. SSL Decrytion g. DdoS h. File Blocking i. Anti-Virus j. Intrusion Prevention System k. DNS based Security File Blocking l. Anti-Virus m. Intrusion Prevention System n. DNS based Security 66. Proposed CPEs will support the uCPE feature and VNF of a different manufacturer can be operated on the CPE located in the locations if desired. 67. Traffic on the device should be able to be routed based on application. 68. Inter-location line qualities should be measured continuously. Traffic should be routed depending on Packet Loss, Delay and Jitter values. For traffic routing, application based routing should be possible depending on the SLA conditions. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 69. While more than one line is used simultaneously, the line with the lowest delay should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest delay should be able to use all lines actively. 70. While more than one line is used simultaneously, the line with the Least Packet Loss should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest packet loss should be able to use all lines actively. 71. While more than one line is used actively simultaneously, the line with the Lowest Jitter value should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest jitter value should be able to use all lines actively. 72. If there is more than one line between the locations, the lines should be given priority value. This prioritization should be application-based. 73. Load balancing should be possible on lines located between locations. Load distribution should be made in direct proportion to the bandwidth of the lines. If this feature is not supported on CPE, each separate system must be installed and integrated with the SD-WAN management system. 74. For high-precision traffic types such as Voice and Video, MOS Scores that determine the application quality should be able to calculate between locations and Audio / Video traffic routing should be made accordingly. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 75. CPEs should support advanced SD-WAN features such as Forward Error Correction and Packet Cloning. 76. SD-WAN management should be over a single system. All operations mentioned above should be done through a single interface. System resources and connection status of the devices positioned with this interface should be monitored instantly. In addition, this interface should include diagnostic tools in order to detect system problems. 77. When necessary, SSH or Web connection should be made to CPEs and configuration can be made through them. 78. CPE version updates should be available from the central management unit or directly from the CPE. 79. Security signature database should be able to be sent to CPEs from the central management unit. 80. The security signature database should be able to be loaded directly on the CPEs via internet connection, and periodic timing settings for downloading should be made. 81. All elements in SD-WAN management systems should be geo-redundantly located if desired, and synchronization should be provided between backup locations without the need for Layer 2 connection. 82. Role-based control should be supported on the central application for management purposes. 83. IPSec based security should be supported for both control plane and data plane. 84. Network-based Hub-Spoke or Full-Mesh structures must be configured simultaneously using the same devices on the system. 85. In Hub-Spoke configuration on the system, it should be allowed to simultaneously open Spoke-Spoke, Spoke-Spoke via Hub or only Hub-Spoke access on the same device for different networks. 86. ZTP (Zero Touch Provisining) should be done using the central management system installed in the data center, without the need for cloud. ZTP should be url based or script based. 87. No cloud system from abroad should be required for the management of systems and analytics operations. 88. Network or application based QoS should be able to be done on the product and it should support Hierarchical QoS, AppQoS. 89. DHCP client / server and DHCP Option and DHCP relay must be supported on the device. 90. Different VLANs on CPE can be given over the same port as well as secondary IP address should be assigned for each VLAN. 91. The device will have Syslog and SNMP support. 92. Configuration templates should be created in SD-WAN management system and these templates should be applied to more than one device simultaneously. 93. Speed tests between different locations should be made on demand or dynamically. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 94. All configurations mentioned in the specification and made on the CPE should be able to be made over the central system. 95. URL-based traffic routing should be able to be done on CPEs. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 96. IGMPv2, IGMPv3, PIM-SM and PIM-SSM multicast protocols must be supported. 97. Important information such as protocol passwords, IPSEC PSK values should be kept hashed (hash) in the configurations and templates on the CPEs and the central management system. 98. The software on the CPEs must support Layer 2 Forwarding configuration. a. Virtual Switches b. Bridge Domains c. Bridge Interfaces d. Integrated routing and bridging (IRB) interfaces e. STP / RSTP f. Layer 2 Forwarding additional functions listed below will be supported in the software on the CPE. g. EVPN over SD-WAN h. Multiple Spanning-Tree Protocol (MSTP) i. VLAN Translation 99. TCP and DIA & DCA (SaaS) optimization should be supported. SaaS applications should be recognizable at the end point with the first package inspection. 100. SD-WAN solution should be able to provide Secure Access Service with a client to be installed on end user equipment (Windows 10, MacOS). 101. Network Analysis information kept on SD-WAN management system should be turned off or restricted when necessary. 102. SD-WAN service provider should be able to provide Role-based access control over SD-WAN management system. 103. TCP optimization should be supported | رخصة | 8 | 0 | — |
| 9 | 2 | الرخص الخاصة بمركز معلومات MS Asure SDWAN license 200Mbps | توريد رخص محولات الشبكة بحيث يكون بالمواصفات الفنية التالية: Product Premier Elite SD-WAN license with 200Mbps Bandwidth Tier, SDWAN Software should deliver highly secure data, voice, video, and application and should support all advanced SDWAN, NGFW And UTM features, with support for 3 years from vendor. (Note: quantities and bandwith as per the quantity table) In addition, the license should support the following features and capabilities: • QoS (Classification, DSCP marking, HQoS, Traffic shapers & Adaptive rate limiting) • ZTP (ZTP agent & server, 2-factor authentication, Auto upgrade, configuration, Global ZTP server based, Encrypted URL based, Controller for ZTP and securing management channel and Certificate based authentication) • Deployment Options (Whitebox, Virtual, Physical, Azure cloud, AWS cloud, GCE cloud and Alibaba cloud) • Provisioning (Template-based provisioning, Custom parameterization and Zero Touch provisioning) • Other Platform Capabilities o Quick Assist support (hw based encryption/decryption) o TPM chip for storing keys & sensitive data • uCPE o uCPE - platform level support w/service chaining o uCPE - 3rd party VM Lifecycle Management • Interface Features o VLAN tagging - single tags, dual tags o Aggregated Ethernet (on LAN interfaces) o PPPoE o T1/E1 interfaces o PPP on T1/E1 interfaces o HDLC on T1/E1 interfaces o ADSL2+/VDSL2 interface support o ATM over xDSL interfaces • Layer 2 - Bridging in Software o Virtual Switch and Bridge Domain instances o VLAN translation o Access and Trunk interfaces o xSTP - as active loop detection o Passive Loop detection o Uplink failure detection for faster convergence o LLDP & IRB • Routing o Static Routing, BFD, ECMP, Policy based routing, Route Reflector o OSPF v2/v3 , MP-BGP4 , MP-BGP IPv6 SAFI support , RIPv2 o VRRP , VRFs • Multicast o IGMP v2/3 (LAN intf) o PIM SM (LAN/WAN) o PIM SSM o PIM RP, Bootstrap RP, Anycast RP o Anycast RP o Multicast across LAN, WAN interfaces, SD-WAN tunnels • IP Address Management o DHCP client o DHCP relay o DHCP server o DHCP v6 client o DHCP v6 server • CGNAT o Static , Dynamic, NATPT, ALG support, EIM/EIF o PBA support, CGNAT64 • MPLS VPN o MPLS BGP L3VPN o MPLS based EVPNs across SD-WAN tunnels • IKE based IPSec VPN Tunnels o IKEv2/v1 o Pre-shared key/PKI authentication o Dead peer detection o Diffie-Hellman key negotiation o AES 128/256 encryption (IKE/IPsec) o SHA1/SHA256/SHA384/SHA512/null hashing o NAT traproduct l o Perfect forward secrecy o IPsec rekey time/volume based o Anti-replay o Pre/post fragmentation o Route based VPN o IPv6 based IPSec support o Dual Stack support • Stateful (L4) Firewall o Zone and endpoint based stateful firewall o 5 tuple flows based (zone, address, user, region), Geo-IP, blacklisting o Rich actions (accept, drop/discard, rate-limit, log) o ALG support o Flow Mirroring o IPv6 support • DOS Protection o Aggregate and classified DDoS profiles o L3 ICMP Flood, IP flood o UDP, TCP SYN flood o ICMPv6 flood o SCTP flood o Port scans and host sweeps o L2-L4 anomaly detection o IPv6 support • Application Visibility o Identification of 3000+ applications & protocols o Support for user-defined applications & app groups o Support for user defined application filters based on any combination of family, subfamily, risk, product ivity & tag o Nested application support o Enable packet capture based on known/unknown applications • SD-WAN Deployment Options o Behind a NAT device/firewall o Encrypted and Non-encrypted overlays with MPLS/GRE or VXLAN o SD-WAN Controller o WAN circuit support o Full Mesh Topology o Hub-Spoke Topology o Spoke-Hub-Hub-Spoke o Controller behind branch / hub o Collapsed Conroller & Hub (consolidation) o Any Topology o Dynamic IPSec overlays o Direct Internet Access o Number of WAN Links • Carrier-grade SD-WAN o MP-BGP route exchange with SDN controller o Primary to secondary WAN link failover in < 2 seconds o OAM – Handle branch device / link failure to the controller o OAM – Redundant controllers o Multi-tenancy o Stateful high-availability o Link aggregation o Hierarchical QoS o Per tunnel QoS o LTE network optimized probing (adaptive probing) o Shared multi-tenant control plane o Overlay encapsulation options (VXLAN, IPSec) • Dynamic IPSec VPN Tunnel Overlays o Secure (and separate) control and data channels o Automatic Key Management o Secure on-demand data channels with unique key pairs between any two sites o Two factor authentication o Automatic certificate lifecycle management o Control Plane based - dynamic – OTT topology based IPSec tunnels for data • Traffic Steering o Route based traffic steering o Seamless integration with WAN optimization devices o App based intelligent path selection – fixed criteria o App based intelligent path selection – user-defined criteria, least cost, high bandwidth paths o URL based traffic management o IPv6 support • Application traffic management o Application based traffic steering o AppQoS – Traffic shaping o AppQoS – Rate limiting o Application-based SLAs o Selective application encryption (ie: encryption based on app or traffic type) o Application blocking • Uniproduct l SD-WAN Migration Gateway o BGP based SD-WAN gateway o IPSec based SD-WAN gateway o Application performance-based gateway • User & Group Level Traffic Control for SD-WAN o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o SD-WAN QoS Control support by User-ID, Group o SD-WAN Traffic Engineering Policy Control support by User-ID, Group o SD-WAN L7 SLA policy based traffic engineering by User-ID and Group • L4 Load Balancer o Layer 4 load balancing o LB algorithms – Hash/RR/Cost o Persistence profiles o Health monitoring – L4 based (TCP/ICMP) o Health monitoring – L7 based (HTTP) o Direct server return – L2 o Direct server return – L3 o Traffic Load Balancer (TLB) and ADC functionality o LB behind NAT – reverse proxy forwarding o High-availability – active-backup • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • Next-Generation (L7) Firewall o L7 application based policies o Application triggers - family/sub family, risk, product ivity, tags o Device Identifiction, fingerprinting and logging o Device ID based traffic management policies • Network Access Control o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o 802.1x with RADIUS back-end o 802.1x Certificate and MAC based access control o Policy trigger support by User-ID, Group • Product Forward Proxy o DIA/DCA use-case coverage o SSL-TLS Proxy o Security Service Chaining • URL/Content Filtering & Captive Portal o Predefined/user defined categories and actions o Whitelist/blacklist o Search patterns/strings o Web reputation feeds o Reputation/category based actions / captive portal o URL filter based captive portal w/ rich set of actions o Intelligent Path selection based on URL category o Custom action messages o IPv6 Support (URL Identification and Traffic Engineering) o IPv6 Support (Categoization and Reputation) • Application traffic conditioning o Forward Error Correction (FEC) o Packet Cloning - Decloning o Packet Striping across SD-WAN path bundle o CODEC support for Voice and Video flows o MOS Score based Traffic Engineering for Voice flows o MOS Score based Traffic Engineering for Video flows o DNA assisted Traffic Steering o DIA/DCA Traffic Optimizations for Cloud SaaS sites o First packet based traffic steering o IPv6 support • TCP Optimization o TCP Proxy for bookended or single ended deployments o TCP SACK, Window Scaling, Timestamping support o Intelligent TCP Buffer management o Improved TCP Loss Recovery Techniques o Integrated latest congestion control algorithms to manage congestion and random traffic loss • Antivirus o Multiple file types o Multiple protocol detection - FTP, HTTP, Email o Compressed file type detection o Nested compression o Packet direction – client/server • NG-IPS o Vulnerability Profiles by CVE ID/signature set /CVSS Score/Packet direction/Class o Multiple Vulnerability DB Reference o OS/Product based o Signature based & Protocol Anomaly based detection o Packet capture - pre & post window o WAN circuit support o L7 anomaly detection o Javascript anomaly detection • SSL & TLS Proxy o SSL Inspection for invalid, expired, untrusted certificates o HTTPS Proxy o SSLv4 & TLS 1.2 Proxy • File Filtering & DLP o File Feeds and Filtering All below features should be supported for the uCPE/CPE and SDWAN licenses: 104. CPE models of different manufacturers should be used in the edge devices used in SD-WAN architecture. 105. CPEs will be able to terminate 3G / 4G, MPLS and Internet connection types at the same time. These lines should be able to be used as each application-based active at the same time or different connections for different applications as active other connections as backup. 106. When using multiple connections on the CPE, it should be preconfigured that certain applications do not use certain lines as backup, while all traffic is switched to redundant lines in case of an outage. 107. User-based traffic routing and security policies should be created on CPEs. A local user database should be able to be created over CPEs. In addition, it should be possible to integrate with external user databases via LDAP or Kerberos. 108. CPE options that can actively support at least 3 different physical WAN connections on a single device should be provided. 109. Static Routing, OSPFv2, OSPFv3, BGP protocols must be supported on CPE. 110. More than one VRF should be opened on the CPE and these VRFs should not be allowed to communicate with each other. 111. Recommended SD-WAN solution should support IPv6. In addition, IPv6 should be available for the specified protocols; OSPFv3, DHCPv6 client and server, QoS Profiles, IPsec VPN, Stateful Firewall Application Gateway, DoS, SD-WAN Underlay Support, Dual Stack. 112. CPEs should be able to be located in a redundant structure and two CPEs for each location should be able to work actively. In the event of a single device failure, the other device must be able to meet all traffic and technical requirements within the scope. 113. Two CPEs should be able to be redundantly located in the locations. Regardless of the types of uplinks coming to the CPEs, for example, if there is an MPLS and Internet connection on the CPE number 1 and there is an Internet and LTE connection on the number 2 CPE, the number 1 CPE should be able to use the 4 uplinks in the location as active active or active passive. 114. Different layers 2 and 3 networks isolated from each other should be created on the CPE. 115. CPEs should be able to directly bring the desired traffic directly to the internet without carrying it over SD-WAN and this process should not cause security weakness. 116. In the software on the CPE, the security functions listed below will be supported or if a different VNF will be installed on the CPE for this process, the relevant VNF or physical device should be added to each location within the offer, and their integration should be made to work smoothly. a. Carrier Grade NAT b. NAT64 & DNS64 c. Stateful Firewall d. NextGen Firewall e. URL Filtering f. SSL Decrytion g. DdoS h. File Blocking i. Anti-Virus j. Intrusion Prevention System k. DNS based Security File Blocking l. Anti-Virus m. Intrusion Prevention System n. DNS based Security 117. Proposed CPEs will support the uCPE feature and VNF of a different manufacturer can be operated on the CPE located in the locations if desired. 118. Traffic on the device should be able to be routed based on application. 119. Inter-location line qualities should be measured continuously. Traffic should be routed depending on Packet Loss, Delay and Jitter values. For traffic routing, application based routing should be possible depending on the SLA conditions. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 120. While more than one line is used simultaneously, the line with the lowest delay should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest delay should be able to use all lines actively. 121. While more than one line is used simultaneously, the line with the Least Packet Loss should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest packet loss should be able to use all lines actively. 122. While more than one line is used actively simultaneously, the line with the Lowest Jitter value should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest jitter value should be able to use all lines actively. 123. If there is more than one line between the locations, the lines should be given priority value. This prioritization should be application-based. 124. Load balancing should be possible on lines located between locations. Load distribution should be made in direct proportion to the bandwidth of the lines. If this feature is not supported on CPE, each separate system must be installed and integrated with the SD-WAN management system. 125. For high-precision traffic types such as Voice and Video, MOS Scores that determine the application quality should be able to calculate between locations and Audio / Video traffic routing should be made accordingly. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 126. CPEs should support advanced SD-WAN features such as Forward Error Correction and Packet Cloning. 127. SD-WAN management should be over a single system. All operations mentioned above should be done through a single interface. System resources and connection status of the devices positioned with this interface should be monitored instantly. In addition, this interface should include diagnostic tools in order to detect system problems. 128. When necessary, SSH or Web connection should be made to CPEs and configuration can be made through them. 129. CPE version updates should be available from the central management unit or directly from the CPE. 130. Security signature database should be able to be sent to CPEs from the central management unit. 131. The security signature database should be able to be loaded directly on the CPEs via internet connection, and periodic timing settings for downloading should be made. 132. All elements in SD-WAN management systems should be geo-redundantly located if desired, and synchronization should be provided between backup locations without the need for Layer 2 connection. 133. Role-based control should be supported on the central application for management purposes. 134. IPSec based security should be supported for both control plane and data plane. 135. Network-based Hub-Spoke or Full-Mesh structures must be configured simultaneously using the same devices on the system. 136. In Hub-Spoke configuration on the system, it should be allowed to simultaneously open Spoke-Spoke, Spoke-Spoke via Hub or only Hub-Spoke access on the same device for different networks. 137. ZTP (Zero Touch Provisining) should be done using the central management system installed in the data center, without the need for cloud. ZTP should be url based or script based. 138. No cloud system from abroad should be required for the management of systems and analytics operations. 139. Network or application based QoS should be able to be done on the product and it should support Hierarchical QoS, AppQoS. 140. DHCP client / server and DHCP Option and DHCP relay must be supported on the device. 141. Different VLANs on CPE can be given over the same port as well as secondary IP address should be assigned for each VLAN. 142. The device will have Syslog and SNMP support. 143. Configuration templates should be created in SD-WAN management system and these templates should be applied to more than one device simultaneously. 144. Speed tests between different locations should be made on demand or dynamically. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 145. All configurations mentioned in the specification and made on the CPE should be able to be made over the central system. 146. URL-based traffic routing should be able to be done on CPEs. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 147. IGMPv2, IGMPv3, PIM-SM and PIM-SSM multicast protocols must be supported. 148. Important information such as protocol passwords, IPSEC PSK values should be kept hashed (hash) in the configurations and templates on the CPEs and the central management system. 149. The software on the CPEs must support Layer 2 Forwarding configuration. a. Virtual Switches b. Bridge Domains c. Bridge Interfaces d. Integrated routing and bridging (IRB) interfaces e. STP / RSTP f. Layer 2 Forwarding additional functions listed below will be supported in the software on the CPE. g. EVPN over SD-WAN h. Multiple Spanning-Tree Protocol (MSTP) i. VLAN Translation 150. TCP and DIA & DCA (SaaS) optimization should be supported. SaaS applications should be recognizable at the end point with the first package inspection. 151. SD-WAN solution should be able to provide Secure Access Service with a client to be installed on end user equipment (Windows 10, MacOS). 152. Network Analysis information kept on SD-WAN management system should be turned off or restricted when necessary. 153. SD-WAN service provider should be able to provide Role-based access control over SD-WAN management system. 154. TCP optimization should be supported | رخصة | 9 | 0 | — |
| 10 | 20 | الرخص الخاصة بالمواقع الكبيرة Large branches SDWAN license 100 Mbps | توريد رخص محولات الشبكة بحيث يكون بالمواصفات الفنية التالية: السعة والكميات يجب ان تكون مطابقة لجدول الكميات بالاعلى Product Premier Elite SD-WAN license with 100 Mbps Bandwidth Tier, SDWAN Software should deliver highly secure data, voice, video, and application and should support all advanced SDWAN, NGFW And UTM features, with pport for 3 years from vendor. ( Note: quantities and bandwith as per the quantity table above) In addition, the license should support the following features and capabilities: • QoS (Classification, DSCP marking, HQoS, Traffic shapers & Adaptive rate limiting) • ZTP (ZTP agent & server, 2-factor authentication, Auto upgrade, configuration, Global ZTP server based, Encrypted URL based, Controller for ZTP and securing management channel and Certificate based authentication) • Deployment Options (Whitebox, Virtual, Physical, Azure cloud, AWS cloud, GCE cloud and Alibaba cloud) • Provisioning (Template-based provisioning, Custom parameterization, and Zero Touch provisioning) • Other Platform Capabilities o Quick Assist support (hw based encryption/decryption) o TPM chip for storing keys & sensitive data • uCPE o uCPE - platform level support w/service chaining o uCPE - 3rd party VM Lifecycle Management • Interface Features o VLAN tagging - single tags, dual tags o Aggregated Ethernet (on LAN interfaces) o PPPoE o T1/E1 interfaces o PPP on T1/E1 interfaces o HDLC on T1/E1 interfaces o ADSL2+/VDSL2 interface support o ATM over xDSL interfaces • Layer 2 - Bridging in Software o Virtual Switch and Bridge Domain instances o VLAN translation o Access and Trunk interfaces o xSTP - as active loop detection o Passive Loop detection o Uplink failure detection for faster convergence o LLDP & IRB • Routing o Static Routing, BFD, ECMP, Policy based routing, Route Reflector o OSPF v2/v3 , MP-BGP4 , MP-BGP IPv6 SAFI support , RIPv2 o VRRP , VRFs • Multicast o IGMP v2/3 (LAN intf) o PIM SM (LAN/WAN) o PIM SSM o PIM RP, Bootstrap RP, Anycast RP o Anycast RP o Multicast across LAN, WAN interfaces, SD-WAN tunnels • IP Address Management o DHCP client o DHCP relay o DHCP server o DHCP v6 client o DHCP v6 server • CGNAT o Static , Dynamic, NATPT, ALG support, EIM/EIF o PBA support, CGNAT64 • MPLS VPN o MPLS BGP L3VPN o MPLS based EVPNs across SD-WAN tunnels • IKE based IPSec VPN Tunnels o IKEv2/v1 o Pre-shared key/PKI authentication o Dead peer detection o Diffie-Hellman key negotiation o AES 128/256 encryption (IKE/IPsec) o SHA1/SHA256/SHA384/SHA512/null hashing o NAT traproduct l o Perfect forward secrecy o IPsec rekey time/volume based o Anti-replay o Pre/post fragmentation o Route based VPN o IPv6 based IPSec support o Dual Stack support • Stateful (L4) Firewall o Zone and endpoint based stateful firewall o 5 tuple flows based (zone, address, user, region), Geo-IP, blacklisting o Rich actions (accept, drop/discard, rate-limit, log) o ALG support o Flow Mirroring o IPv6 support • DOS Protection o Aggregate and classified DDoS profiles o L3 ICMP Flood, IP flood o UDP, TCP SYN flood o ICMPv6 flood o SCTP flood o Port scans and host sweeps o L2-L4 anomaly detection o IPv6 support • Application Visibility o Identification of 3000+ applications & protocols o Support for user-defined applications & app groups o Support for user defined application filters based on any combination of family, subfamily, risk, product ivity & tag o Nested application support o Enable packet capture based on known/unknown applications • SD-WAN Deployment Options o Behind a NAT device/firewall o Encrypted and Non-encrypted overlays with MPLS/GRE or VXLAN o SD-WAN Controller o WAN circuit support o Full Mesh Topology o Hub-Spoke Topology o Spoke-Hub-Hub-Spoke o Controller behind branch / hub o Collapsed Conroller & Hub (consolidation) o Any Topology o Dynamic IPSec overlays o Direct Internet Access o Number of WAN Links • Carrier-grade SD-WAN o MP-BGP route exchange with SDN controller o Primary to secondary WAN link failover in < 2 seconds o OAM – Handle branch device / link failure to the controller o OAM – Redundant controllers o Multi-tenancy o Stateful high-availability o Link aggregation o Hierarchical QoS o Per tunnel QoS o LTE network optimized probing (adaptive probing) o Shared multi-tenant control plane o Overlay encapsulation options (VXLAN, IPSec) • Dynamic IPSec VPN Tunnel Overlays o Secure (and separate) control and data channels o Automatic Key Management o Secure on-demand data channels with unique key pairs between any two sites o Two factor authentication o Automatic certificate lifecycle management o Control Plane based - dynamic – OTT topology based IPSec tunnels for data • Traffic Steering o Route based traffic steering o Seamless integration with WAN optimization devices o App based intelligent path selection – fixed criteria o App based intelligent path selection – user-defined criteria, least cost, high bandwidth paths o URL based traffic management o IPv6 support • Application traffic management o Application based traffic steering o AppQoS – Traffic shaping o AppQoS – Rate limiting o Application-based SLAs o Selective application encryption (ie: encryption based on app or traffic type) o Application blocking • Uniproduct l SD-WAN Migration Gateway o BGP based SD-WAN gateway o IPSec based SD-WAN gateway o Application performance-based gateway • User & Group Level Traffic Control for SD-WAN o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o SD-WAN QoS Control support by User-ID, Group o SD-WAN Traffic Engineering Policy Control support by User-ID, Group o SD-WAN L7 SLA policy based traffic engineering by User-ID and Group • L4 Load Balancer o Layer 4 load balancing o LB algorithms – Hash/RR/Cost o Persistence profiles o Health monitoring – L4 based (TCP/ICMP) o Health monitoring – L7 based (HTTP) o Direct server return – L2 o Direct server return – L3 o Traffic Load Balancer (TLB) and ADC functionality o LB behind NAT – reverse proxy forwarding o High-availability – active-backup • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • Next-Generation (L7) Firewall o L7 application based policies o Application triggers - family/sub family, risk, product ivity, tags o Device Identifiction, fingerprinting and logging o Device ID based traffic management policies • Network Access Control o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o 802.1x with RADIUS back-end o 802.1x Certificate and MAC based access control o Policy trigger support by User-ID, Group • Product Forward Proxy o DIA/DCA use-case coverage o SSL-TLS Proxy o Security Service Chaining • URL/Content Filtering & Captive Portal o Predefined/user defined categories and actions o Whitelist/blacklist o Search patterns/strings o Web reputation feeds o Reputation/category based actions / captive portal o URL filter based captive portal w/ rich set of actions o Intelligent Path selection based on URL category o Custom action messages o IPv6 Support (URL Identification and Traffic Engineering) o IPv6 Support (Categoization and Reputation) • Application traffic conditioning o Forward Error Correction (FEC) o Packet Cloning - Decloning o Packet Striping across SD-WAN path bundle o CODEC support for Voice and Video flows o MOS Score based Traffic Engineering for Voice flows o MOS Score based Traffic Engineering for Video flows o DNA assisted Traffic Steering o DIA/DCA Traffic Optimizations for Cloud SaaS sites o First packet based traffic steering o IPv6 support • TCP Optimization o TCP Proxy for bookended or single ended deployments o TCP SACK, Window Scaling, Timestamping support o Intelligent TCP Buffer management o Improved TCP Loss Recovery Techniques o Integrated latest congestion control algorithms to manage congestion and random traffic loss • Antivirus o Multiple file types o Multiple protocol detection - FTP, HTTP, Email o Compressed file type detection o Nested compression o Packet direction – client/server • NG-IPS o Vulnerability Profiles by CVE ID/signature set /CVSS Score/Packet direction/Class o Multiple Vulnerability DB Reference o OS/Product based o Signature based & Protocol Anomaly based detection o Packet capture - pre & post window o WAN circuit support o L7 anomaly detection o Javascript anomaly detection • SSL & TLS Proxy o SSL Inspection for invalid, expired, untrusted certificates o HTTPS Proxy o SSLv4 & TLS 1.2 Proxy • File Filtering & DLP o File Feeds and Filtering All below features should be supported for the uCPE/CPE and SDWAN licenses: 155. CPE models of different manufacturers should be used in the edge devices used in SD-WAN architecture. 156. CPEs will be able to terminate 3G / 4G, MPLS and Internet connection types at the same time. These lines should be able to be used as each application-based active at the same time or different connections for different applications as active other connections as backup. 157. When using multiple connections on the CPE, it should be preconfigured that certain applications do not use certain lines as backup, while all traffic is switched to redundant lines in case of an outage. 158. User-based traffic routing and security policies should be created on CPEs. A local user database should be able to be created over CPEs. In addition, it should be possible to integrate with external user databases via LDAP or Kerberos. 159. CPE options that can actively support at least 3 different physical WAN connections on a single device should be provided. 160. Static Routing, OSPFv2, OSPFv3, BGP protocols must be supported on CPE. 161. More than one VRF should be opened on the CPE and these VRFs should not be allowed to communicate with each other. 162. Recommended SD-WAN solution should support IPv6. In addition, IPv6 should be available for the specified protocols; OSPFv3, DHCPv6 client and server, QoS Profiles, IPsec VPN, Stateful Firewall Application Gateway, DoS, SD-WAN Underlay Support, Dual Stack. 163. CPEs should be able to be located in a redundant structure and two CPEs for each location should be able to work actively. In the event of a single device failure, the other device must be able to meet all traffic and technical requirements within the scope. 164. Two CPEs should be able to be redundantly located in the locations. Regardless of the types of uplinks coming to the CPEs, for example, if there is an MPLS and Internet connection on the CPE number 1 and there is an Internet and LTE connection on the number 2 CPE, the number 1 CPE should be able to use the 4 uplinks in the location as active active or active passive. 165. Different layers 2 and 3 networks isolated from each other should be created on the CPE. 166. CPEs should be able to directly bring the desired traffic directly to the internet without carrying it over SD-WAN and this process should not cause security weakness. 167. In the software on the CPE, the security functions listed below will be supported or if a different VNF will be installed on the CPE for this process, the relevant VNF or physical device should be added to each location within the offer, and their integration should be made to work smoothly. a. Carrier Grade NAT b. NAT64 & DNS64 c. Stateful Firewall d. NextGen Firewall e. URL Filtering f. SSL Decrytion g. DdoS h. File Blocking i. Anti-Virus j. Intrusion Prevention System k. DNS based Security File Blocking l. Anti-Virus m. Intrusion Prevention System n. DNS based Security 168. Proposed CPEs will support the uCPE feature and VNF of a different manufacturer can be operated on the CPE located in the locations if desired. 169. Traffic on the device should be able to be routed based on application. 170. Inter-location line qualities should be measured continuously. Traffic should be routed depending on Packet Loss, Delay and Jitter values. For traffic routing, application based routing should be possible depending on the SLA conditions. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 171. While more than one line is used simultaneously, the line with the lowest delay should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest delay should be able to use all lines actively. 172. While more than one line is used simultaneously, the line with the Least Packet Loss should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest packet loss should be able to use all lines actively. 173. While more than one line is used actively simultaneously, the line with the Lowest Jitter value should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest jitter value should be able to use all lines actively. 174. If there is more than one line between the locations, the lines should be given priority value. This prioritization should be application-based. 175. Load balancing should be possible on lines located between locations. Load distribution should be made in direct proportion to the bandwidth of the lines. If this feature is not supported on CPE, each separate system must be installed and integrated with the SD-WAN management system. 176. For high-precision traffic types such as Voice and Video, MOS Scores that determine the application quality should be able to calculate between locations and Audio / Video traffic routing should be made accordingly. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 177. CPEs should support advanced SD-WAN features such as Forward Error Correction and Packet Cloning. 178. SD-WAN management should be over a single system. All operations mentioned above should be done through a single interface. System resources and connection status of the devices positioned with this interface should be monitored instantly. In addition, this interface should include diagnostic tools in order to detect system problems. 179. When necessary, SSH or Web connection should be made to CPEs and configuration can be made through them. 180. CPE version updates should be available from the central management unit or directly from the CPE. 181. Security signature database should be able to be sent to CPEs from the central management unit. 182. The security signature database should be able to be loaded directly on the CPEs via internet connection, and periodic timing settings for downloading should be made. 183. All elements in SD-WAN management systems should be geo-redundantly located if desired, and synchronization should be provided between backup locations without the need for Layer 2 connection. 184. Role-based control should be supported on the central application for management purposes. 185. IPSec based security should be supported for both control plane and data plane. 186. Network-based Hub-Spoke or Full-Mesh structures must be configured simultaneously using the same devices on the system. 187. In Hub-Spoke configuration on the system, it should be allowed to simultaneously open Spoke-Spoke, Spoke-Spoke via Hub or only Hub-Spoke access on the same device for different networks. 188. ZTP (Zero Touch Provisining) should be done using the central management system installed in the data center, without the need for cloud. ZTP should be url based or script based. 189. No cloud system from abroad should be required for the management of systems and analytics operations. 190. Network or application based QoS should be able to be done on the product and it should support Hierarchical QoS, AppQoS. 191. DHCP client / server and DHCP Option and DHCP relay must be supported on the device. 192. Different VLANs on CPE can be given over the same port as well as secondary IP address should be assigned for each VLAN. 193. The device will have Syslog and SNMP support. 194. Configuration templates should be created in SD-WAN management system and these templates should be applied to more than one device simultaneously. 195. Speed tests between different locations should be made on demand or dynamically. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 196. All configurations mentioned in the specification and made on the CPE should be able to be made over the central system. 197. URL-based traffic routing should be able to be done on CPEs. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 198. IGMPv2, IGMPv3, PIM-SM and PIM-SSM multicast protocols must be supported. 199. Important information such as protocol passwords, IPSEC PSK values should be kept hashed (hash) in the configurations and templates on the CPEs and the central management system. 200. The software on the CPEs must support Layer 2 Forwarding configuration. a. Virtual Switches b. Bridge Domains c. Bridge Interfaces d. Integrated routing and bridging (IRB) interfaces e. STP / RSTP f. Layer 2 Forwarding additional functions listed below will be supported in the software on the CPE. g. EVPN over SD-WAN h. Multiple Spanning-Tree Protocol (MSTP) i. VLAN Translation 201. TCP and DIA & DCA (SaaS) optimization should be supported. SaaS applications should be recognizable at the end point with the first package inspection. 202. SD-WAN solution should be able to provide Secure Access Service with a client to be installed on end user equipment (Windows 10, MacOS). 203. Network Analysis information kept on SD-WAN management system should be turned off or restricted when necessary. 204. SD-WAN service provider should be able to provide Role-based access control over SD-WAN management system. 205. TCP optimization should be supported | رخصة | 10 | 0 | — |
| 11 | 130 | الرخص الخاصة بالمواقع الصغيرة Small branches SDWAN license 100Mbps | توريد رخص محولات الشبكة بحيث يكون بالمواصفات الفنية التالية: Product Premier Elite SD-WAN license with 100 Mbps Bandwidth Tier, SDWAN Software should deliver highly secure data, voice, video, and application and should support all advanced SDWAN, NGFW And UTM features, with support for 3 years from vendor. ( Note: quantities and bandwith as per the quantity table above) In addition, the license should support the following features and capabilities: • QoS (Classification, DSCP marking, HQoS, Traffic shapers & Adaptive rate limiting) • ZTP (ZTP agent & server, 2-factor authentication, Auto upgrade, configuration, Global ZTP server based, Encrypted URL based, Controller for ZTP and securing management channel and Certificate based authentication) • Deployment Options (Whitebox, Virtual, Physical, Azure cloud, AWS cloud, GCE cloud and Alibaba cloud) • Provisioning (Template-based provisioning, Custom parameterization, and Zero Touch provisioning) • Other Platform Capabilities o Quick Assist support (hw based encryption/decryption) o TPM chip for storing keys & sensitive data • uCPE o uCPE - platform level support w/service chaining o uCPE - 3rd party VM Lifecycle Management • Interface Features o VLAN tagging - single tags, dual tags o Aggregated Ethernet (on LAN interfaces) o PPPoE o T1/E1 interfaces o PPP on T1/E1 interfaces o HDLC on T1/E1 interfaces o ADSL2+/VDSL2 interface support o ATM over xDSL interfaces • Layer 2 - Bridging in Software o Virtual Switch and Bridge Domain instances o VLAN translation o Access and Trunk interfaces o xSTP - as active loop detection o Passive Loop detection o Uplink failure detection for faster convergence o LLDP & IRB • Routing o Static Routing, BFD, ECMP, Policy based routing, Route Reflector o OSPF v2/v3 , MP-BGP4 , MP-BGP IPv6 SAFI support , RIPv2 o VRRP , VRFs • Multicast o IGMP v2/3 (LAN intf) o PIM SM (LAN/WAN) o PIM SSM o PIM RP, Bootstrap RP, Anycast RP o Anycast RP o Multicast across LAN, WAN interfaces, SD-WAN tunnels • IP Address Management o DHCP client o DHCP relay o DHCP server o DHCP v6 client o DHCP v6 server • CGNAT o Static , Dynamic, NATPT, ALG support, EIM/EIF o PBA support, CGNAT64 • MPLS VPN o MPLS BGP L3VPN o MPLS based EVPNs across SD-WAN tunnels • IKE based IPSec VPN Tunnels o IKEv2/v1 o Pre-shared key/PKI authentication o Dead peer detection o Diffie-Hellman key negotiation o AES 128/256 encryption (IKE/IPsec) o SHA1/SHA256/SHA384/SHA512/null hashing o NAT traproduct l o Perfect forward secrecy o IPsec rekey time/volume based o Anti-replay o Pre/post fragmentation o Route based VPN o IPv6 based IPSec support o Dual Stack support • Stateful (L4) Firewall o Zone and endpoint based stateful firewall o 5 tuple flows based (zone, address, user, region), Geo-IP, blacklisting o Rich actions (accept, drop/discard, rate-limit, log) o ALG support o Flow Mirroring o IPv6 support • DOS Protection o Aggregate and classified DDoS profiles o L3 ICMP Flood, IP flood o UDP, TCP SYN flood o ICMPv6 flood o SCTP flood o Port scans and host sweeps o L2-L4 anomaly detection o IPv6 support • Application Visibility o Identification of 3000+ applications & protocols o Support for user-defined applications & app groups o Support for user defined application filters based on any combination of family, subfamily, risk, product ivity & tag o Nested application support o Enable packet capture based on known/unknown applications • SD-WAN Deployment Options o Behind a NAT device/firewall o Encrypted and Non-encrypted overlays with MPLS/GRE or VXLAN o SD-WAN Controller o WAN circuit support o Full Mesh Topology o Hub-Spoke Topology o Spoke-Hub-Hub-Spoke o Controller behind branch / hub o Collapsed Conroller & Hub (consolidation) o Any Topology o Dynamic IPSec overlays o Direct Internet Access o Number of WAN Links • Carrier-grade SD-WAN o MP-BGP route exchange with SDN controller o Primary to secondary WAN link failover in < 2 seconds o OAM – Handle branch device / link failure to the controller o OAM – Redundant controllers o Multi-tenancy o Stateful high-availability o Link aggregation o Hierarchical QoS o Per tunnel QoS o LTE network optimized probing (adaptive probing) o Shared multi-tenant control plane o Overlay encapsulation options (VXLAN, IPSec) • Dynamic IPSec VPN Tunnel Overlays o Secure (and separate) control and data channels o Automatic Key Management o Secure on-demand data channels with unique key pairs between any two sites o Two factor authentication o Automatic certificate lifecycle management o Control Plane based - dynamic – OTT topology based IPSec tunnels for data • Traffic Steering o Route based traffic steering o Seamless integration with WAN optimization devices o App based intelligent path selection – fixed criteria o App based intelligent path selection – user-defined criteria, least cost, high bandwidth paths o URL based traffic management o IPv6 support • Application traffic management o Application based traffic steering o AppQoS – Traffic shaping o AppQoS – Rate limiting o Application-based SLAs o Selective application encryption (ie: encryption based on app or traffic type) o Application blocking • Uniproduct l SD-WAN Migration Gateway o BGP based SD-WAN gateway o IPSec based SD-WAN gateway o Application performance-based gateway • User & Group Level Traffic Control for SD-WAN o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o SD-WAN QoS Control support by User-ID, Group o SD-WAN Traffic Engineering Policy Control support by User-ID, Group o SD-WAN L7 SLA policy based traffic engineering by User-ID and Group • L4 Load Balancer o Layer 4 load balancing o LB algorithms – Hash/RR/Cost o Persistence profiles o Health monitoring – L4 based (TCP/ICMP) o Health monitoring – L7 based (HTTP) o Direct server return – L2 o Direct server return – L3 o Traffic Load Balancer (TLB) and ADC functionality o LB behind NAT – reverse proxy forwarding o High-availability – active-backup • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • DNS Proxy & Security o DNS Forwarder o DNS Split Proxy o DNS Proxy o DNS Proxy for IPv6 o DNS Security Feeds and DNS Firewall • Next-Generation (L7) Firewall o L7 application based policies o Application triggers - family/sub family, risk, product ivity, tags o Device Identifiction, fingerprinting and logging o Device ID based traffic management policies • Network Access Control o User/Group based policies with support for Active Directory & LDAP o Kerberos, Captive Portal Form, Oauth, SAML SP support o 802.1x with RADIUS back-end o 802.1x Certificate and MAC based access control o Policy trigger support by User-ID, Group • Product Forward Proxy o DIA/DCA use-case coverage o SSL-TLS Proxy o Security Service Chaining • URL/Content Filtering & Captive Portal o Predefined/user defined categories and actions o Whitelist/blacklist o Search patterns/strings o Web reputation feeds o Reputation/category based actions / captive portal o URL filter based captive portal w/ rich set of actions o Intelligent Path selection based on URL category o Custom action messages o IPv6 Support (URL Identification and Traffic Engineering) o IPv6 Support (Categoization and Reputation) • Application traffic conditioning o Forward Error Correction (FEC) o Packet Cloning - Decloning o Packet Striping across SD-WAN path bundle o CODEC support for Voice and Video flows o MOS Score based Traffic Engineering for Voice flows o MOS Score based Traffic Engineering for Video flows o DNA assisted Traffic Steering o DIA/DCA Traffic Optimizations for Cloud SaaS sites o First packet based traffic steering o IPv6 support • TCP Optimization o TCP Proxy for bookended or single ended deployments o TCP SACK, Window Scaling, Timestamping support o Intelligent TCP Buffer management o Improved TCP Loss Recovery Techniques o Integrated latest congestion control algorithms to manage congestion and random traffic loss • Antivirus o Multiple file types o Multiple protocol detection - FTP, HTTP, Email o Compressed file type detection o Nested compression o Packet direction – client/server • NG-IPS o Vulnerability Profiles by CVE ID/signature set /CVSS Score/Packet direction/Class o Multiple Vulnerability DB Reference o OS/Product based o Signature based & Protocol Anomaly based detection o Packet capture - pre & post window o WAN circuit support o L7 anomaly detection o Javascript anomaly detection • SSL & TLS Proxy o SSL Inspection for invalid, expired, untrusted certificates o HTTPS Proxy o SSLv4 & TLS 1.2 Proxy • File Filtering & DLP o File Feeds and Filtering All below features should be supported for the uCPE/CPE and SDWAN licenses: 206. CPE models of different manufacturers should be used in the edge devices used in SD-WAN architecture. 207. CPEs will be able to terminate 3G / 4G, MPLS and Internet connection types at the same time. These lines should be able to be used as each application-based active at the same time or different connections for different applications as active other connections as backup. 208. When using multiple connections on the CPE, it should be preconfigured that certain applications do not use certain lines as backup, while all traffic is switched to redundant lines in case of an outage. 209. User-based traffic routing and security policies should be created on CPEs. A local user database should be able to be created over CPEs. In addition, it should be possible to integrate with external user databases via LDAP or Kerberos. 210. CPE options that can actively support at least 3 different physical WAN connections on a single device should be provided. 211. Static Routing, OSPFv2, OSPFv3, BGP protocols must be supported on CPE. 212. More than one VRF should be opened on the CPE and these VRFs should not be allowed to communicate with each other. 213. Recommended SD-WAN solution should support IPv6. In addition, IPv6 should be available for the specified protocols; OSPFv3, DHCPv6 client and server, QoS Profiles, IPsec VPN, Stateful Firewall Application Gateway, DoS, SD-WAN Underlay Support, Dual Stack. 214. CPEs should be able to be located in a redundant structure and two CPEs for each location should be able to work actively. In the event of a single device failure, the other device must be able to meet all traffic and technical requirements within the scope. 215. Two CPEs should be able to be redundantly located in the locations. Regardless of the types of uplinks coming to the CPEs, for example, if there is an MPLS and Internet connection on the CPE number 1 and there is an Internet and LTE connection on the number 2 CPE, the number 1 CPE should be able to use the 4 uplinks in the location as active active or active passive. 216. Different layers 2 and 3 networks isolated from each other should be created on the CPE. 217. CPEs should be able to directly bring the desired traffic directly to the internet without carrying it over SD-WAN and this process should not cause security weakness. 218. In the software on the CPE, the security functions listed below will be supported or if a different VNF will be installed on the CPE for this process, the relevant VNF or physical device should be added to each location within the offer, and their integration should be made to work smoothly. a. Carrier Grade NAT b. NAT64 & DNS64 c. Stateful Firewall d. NextGen Firewall e. URL Filtering f. SSL Decrytion g. DdoS h. File Blocking i. Anti-Virus j. Intrusion Prevention System k. DNS based Security File Blocking l. Anti-Virus m. Intrusion Prevention System n. DNS based Security 219. Proposed CPEs will support the uCPE feature and VNF of a different manufacturer can be operated on the CPE located in the locations if desired. 220. Traffic on the device should be able to be routed based on application. 221. Inter-location line qualities should be measured continuously. Traffic should be routed depending on Packet Loss, Delay and Jitter values. For traffic routing, application based routing should be possible depending on the SLA conditions. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 222. While more than one line is used simultaneously, the line with the lowest delay should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest delay should be able to use all lines actively. 223. While more than one line is used simultaneously, the line with the Least Packet Loss should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest packet loss should be able to use all lines actively. 224. While more than one line is used actively simultaneously, the line with the Lowest Jitter value should be activated depending on the instantaneous measurements for a specific application. In the meantime, applications other than the application that actively uses the line with the lowest jitter value should be able to use all lines actively. 225. If there is more than one line between the locations, the lines should be given priority value. This prioritization should be application-based. 226. Load balancing should be possible on lines located between locations. Load distribution should be made in direct proportion to the bandwidth of the lines. If this feature is not supported on CPE, each separate system must be installed and integrated with the SD-WAN management system. 227. For high-precision traffic types such as Voice and Video, MOS Scores that determine the application quality should be able to calculate between locations and Audio / Video traffic routing should be made accordingly. If this feature is not supported on CPE, a separate system must be installed and integrated with the SD-WAN management system. 228. CPEs should support advanced SD-WAN features such as Forward Error Correction and Packet Cloning. 229. SD-WAN management should be over a single system. All operations mentioned above should be done through a single interface. System resources and connection status of the devices positioned with this interface should be monitored instantly. In addition, this interface should include diagnostic tools in order to detect system problems. 230. When necessary, SSH or Web connection should be made to CPEs and configuration can be made through them. 231. CPE version updates should be available from the central management unit or directly from the CPE. 232. Security signature database should be able to be sent to CPEs from the central management unit. 233. The security signature database should be able to be loaded directly on the CPEs via internet connection, and periodic timing settings for downloading should be made. 234. All elements in SD-WAN management systems should be geo-redundantly located if desired, and synchronization should be provided between backup locations without the need for Layer 2 connection. 235. Role-based control should be supported on the central application for management purposes. 236. IPSec based security should be supported for both control plane and data plane. 237. Network-based Hub-Spoke or Full-Mesh structures must be configured simultaneously using the same devices on the system. 238. In Hub-Spoke configuration on the system, it should be allowed to simultaneously open Spoke-Spoke, Spoke-Spoke via Hub or only Hub-Spoke access on the same device for different networks. 239. ZTP (Zero Touch Provisining) should be done using the central management system installed in the data center, without the need for cloud. ZTP should be url based or script based. 240. No cloud system from abroad should be required for the management of systems and analytics operations. 241. Network or application based QoS should be able to be done on the product and it should support Hierarchical QoS, AppQoS. 242. DHCP client / server and DHCP Option and DHCP relay must be supported on the device. 243. Different VLANs on CPE can be given over the same port as well as secondary IP address should be assigned for each VLAN. 244. The device will have Syslog and SNMP support. 245. Configuration templates should be created in SD-WAN management system and these templates should be applied to more than one device simultaneously. 246. Speed tests between different locations should be made on demand or dynamically. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 247. All configurations mentioned in the specification and made on the CPE should be able to be made over the central system. 248. URL-based traffic routing should be able to be done on CPEs. If this feature is not supported, it should provide an additional solution for all locations and be integrated into the SD-WAN system. 249. IGMPv2, IGMPv3, PIM-SM and PIM-SSM multicast protocols must be supported. 250. Important information such as protocol passwords, IPSEC PSK values should be kept hashed (hash) in the configurations and templates on the CPEs and the central management system. 251. The software on the CPEs must support Layer 2 Forwarding configuration. a. Virtual Switches b. Bridge Domains c. Bridge Interfaces d. Integrated routing and bridging (IRB) interfaces e. STP / RSTP f. Layer 2 Forwarding additional functions listed below will be supported in the software on the CPE. g. EVPN over SD-WAN h. Multiple Spanning-Tree Protocol (MSTP) i. VLAN Translation 252. TCP and DIA & DCA (SaaS) optimization should be supported. SaaS applications should be recognizable at the end point with the first package inspection. 253. SD-WAN solution should be able to provide Secure Access Service with a client to be installed on end user equipment (Windows 10, MacOS). 254. Network Analysis information kept on SD-WAN management system should be turned off or restricted when necessary. 255. SD-WAN service provider should be able to provide Role-based access control over SD-WAN management system. 256. TCP optimization should be supported | رخصة | 11 | 0 | — |
| 12 | 6 | خادم رئيسي Server | يجب على المتعاقد القيام بتوريد الخوادم بالموصفات التالية مع 3 سنوان ضمان وصيانة: • Dual, Hot Plug, Redundant Power Supply (1+1), 550W (1) • C13 to C14, PDU Style, 10 AMP, 6.5 Feet (2m), Power Cord (2) • Dual-Port 1GbE On-Board LOM (1) • ReadyRails Sliding Rails Without Cable Management Arm (1) • Intel Xeon Silver 4216 2.1G, 16C/32T, 9.6GT/s, 22M Cache, Turbo, HT (100W) DDR4-2400 (1) • 2.5" Chassis with up to 8 Hot Plug Hard Drives (1) • 960GB SSD SATA Read Intensive 6Gbps 512 2.5in Hot-plug AG Drive, 1 DWPD, 1752 TBW (2) • 16GB RDIMM, 3200MT/s, Dual Rank (2) • PERC H730P RAID Controller, 2GB NV Cache, Adapter, Low Profile (1) • Trusted Platform Module 2.0 (1) • Intel X710 Quad Port 10GbE Direct Attach SFP+ Adapter, PCIe Full Height (1) • ProDeploy Plus Server R Series 1U/2U – Deployment (1) • ProDeploy Plus Server R Series 1U/2U - Deployment Verification (1) • ProSupport Plus and 4Hr Mission Critical Extension, 24 Month(s) 1 • ProSupport Plus and 4Hr Mission Critical Initial, 12 Month(s) 1 • SFP+, SR, Optical Transceiver, Intel, 10Gb-1Gb (4) | جهاز | 12 | 0 | — |
| 13 | 2 | خادم Server | يجب على مقدم العرض القيام بتوريد الخوادم بالموصفات التالية مع 3 سنوان ضمان و صيانة : • C13 to C14, PDU Style, 10 AMP, 6.5 Feet (2m), Power Cord (2) • Riser Config 1, 1 x 16 FH (1) • Dual-Port 1GbE On-Board LOM (1) • ReadyRails Sliding Rails Without Cable Management Arm (1) • iDRAC,Legacy Password (1) • iDRAC Group Manager, Enabled (1) • Intel Xeon Silver 4216 2.1G, 16C/32T, 9.6GT/s, 22M Cache, Turbo, HT (100W) DDR4-2400 (1) • 2.5" Chassis with up to 8 Hot Plug Hard Drives (1) • 960GB SSD SATA Read Intensive 6Gbps 512 2.5in Hot-plug AG Drive, 1 DWPD, 1752 TBW (2) • 16GB RDIMM, 3200MT/s, Dual Rank (2) • PERC H730P RAID Controller, 2GB NV Cache, Adapter, Low Profile (1) • Trusted Platform Module 2.0 (1) • Intel X710 Quad Port 10GbE Direct Attach SFP+ Adapter, PCIe Full Height (1) • ProDeploy Plus Server R Series 1U/2U – Deployment (1) • ProDeploy Plus Server R Series 1U/2U - Deployment Verification (1) • ProSupport Plus and 4Hr Mission Critical Extension, 24 Month(s) (1) • ProSupport Plus and 4Hr Mission Critical Initial, 12 Month(s) (1) • iDRAC9,Enterprise (1) • OpenManage Enterprise Advanced (1) • SFP+, SR, Optical Transceiver, Intel, 10Gb-1Gb (4) • VMware ESXi NFI (License Not Included) (1) VMware vSphere 7 Standard for 1 CPU, up to 32 cores, 3 Year License and Subscription (1) | جهاز | 13 | 0 | — |
| 14 | 2 | جهاز المقسم للشبكة OOB switches | يجب على مقدم العرض القيام بتوريد محولات الشبكة بالموصفات التالية مع 3 سنوان ضمان و صيانة : Support 24 x 1GbT ports with and 2 x 1G/10G uplinks SFP/SFP+ fixed ports. Wired speed switching capacity none nonblocking in ports/interfaces. Supports stacking of up to 8 switches and 80 Gbps bandwidth. Software Image with adviced L2 and L3 LAN services. Switch should support Layer2 and Layer3 features Support IO to PSU airflow with AC power supply. Support Redundant Power Supply. Must have 3 Years ProSupport with NBD replacment/repare | جهاز | 14 | 0 | — |
| 15 | 4 | جهاز المقسم للشبكة ToR switches | يجب على مقدم العرض القيام بتوريد محولات الشبكة بالموصفات التالية مع 3 سنوان ضمان و صيانة : • Data Center/TOR switch support 28 x 1/10ports and 2 x 100G ports. • Scalable L2 and L3 Ethernet switching with QoS and a full com¬plement of standards-based IPv4 and IPv6 features, including OSPF and BGP routing support • L2 multipath support via Virtual Link Trunking (VLT) and Routed VLT support • Converged network support for DCB, with priority flow control (802.1Qbb), ETS (802.1Qaz), DCBx and iSCSI TLV support • Redundant hot-swappable power supplies and fans. • Supports the open source Open Network Install Environment (ONIE) for zero touch installation of alternate network operating systems • Standard networking features, interfaces and scripting functions for legacy network operations integration • Increase VM Mobility region by stretching L2 VLAN within or across two DCs with unique VLT capabilities • Scalable L2 and L3 Ethernet Switching with QoS, ACL and a full complement of standards based IPv4 and IPv6 features including OSPF, BGP and PBR • Converged network support for Data Center Bridging, with priority flow control (802.1Qbb), ETS (802.1Qaz), DCBx and iSCSI TLV. • Must support for open networking, providing freedom to run third-party operating systems (OS). • Must have 3Yr ProSupport Plus and 4Hr Mission Critical Below optics and cable must be included in each switch: - 24 x DAC Cable, SFP+ to SFP+, 10GbE, Copper Twinax Direct Attach Cable, 3 Meter - 2 x Transceiver, SFP, 1000BASE-T - 8 x Transceiver, SFP, 1000BASE-LX, 1310nm Wavelength, 10km Reach | جهاز | 15 | 0 | — |
| 16 | 1 | on Prim SDWAN deployment and implementation | يجب على مقدم العرض القيام بجمع الاعمال المتعلقة ب: 2- On Prim SDWAN deployment in the main DC, and DR and all the branches across Saudi Arabia. 3- Product SDWAN design, HLD, LLD 4- Product SDWAN implementation plan 5- Product SDWAN Project management 6- Product SDWAN full deployment for DC, DR, MS DC, and all branches across Saudi, including replacing all existing routers with SDWAN uCPE 7- Product SDWAN on Prim deign and deployment/implementation 8- Product SDWAN knowledge transfer | خدمة | 16 | 0 | — |
| 17 | 150 | جهاز المقسم الرئيسي للشبكة Core Switch | موضحة بالمرفقات | جهاز | 17 | 0 | مواصفات البند رقم 17.pdf 150 KB |
| 18 | 600 | جهاز مقسم الشبكة الفرعي Access Switch | موضحة بالمرفقات | جهاز | 18 | 0 | مواصفات البند رقم 18.pdf 156 KB |
| 19 | 2 | جهاز التحكم بالشبكة اللاسلكية Wireless Controller | • Below are the required specs for Wi-Fi AC Controller • Optimized for 802.11ax (Wi-Fi 6) next-generation networks. • Minimum 80-Gbps throughput • Support up to 6000 access points • Support up to 64,000 clients • Provides 8 x 10GE optical interfaces and 12 x GE electrical interfaces. • Should be configured with 4 units of 10G Multi-mode SFP+. • Should have built-in Portal/AAA server and can provide Portal/802.1X authentication for users. • The WLAN AC is compatible with full-series 802.11n, 802.11ac and 802.11ax APs and supports hybrid networking of 802.11n, 802.11ac and 802.11ax APs for simple scalability. • High availability: Stateful switchover with 1:1 active standby and N+1 redundancy keeps your network, services, and clients always on, even in unplanned events. • It enables network access in minutes for any user or device to any application without compromising on security • Multisite upgrades can now be done in stages, and access points can be upgraded intelligently without restarting the entire network. • Smart roaming: Enables sticky terminals to roam to APs with better signals. 802.11k and 802.11v smart roaming, 802.11r fast roaming (≤ 50 ms) • Quality of service • Superior Quality of Service (QoS): QoS technologies are tools and techniques for managing network resources and are considered the key enabling technologies for the transparent convergence of voice, video, and data networks • QoS on this WLC consists of classification of traffic based on packet data as well as application recognition and traffic control actions. • Network analytics and automation help IT quickly resolve issues, so you can increase availability and deliver a better user experience Scalability and performance • WebUI: WebUI is an embedded GUI-based device-management tool that provides the ability to provision the device, simplifying device deployment and manageability and enhancing the user experience. WebUI comes with the default image. There is no need to enable anything or install any license on the device. You can use WebUI to build a day-0 and day-1 configuration and from then on monitor and troubleshoot the device without having to know how to use the CLI. • All software, operating systems, and licenses must be provided to ensure requested features and technologies functionality. • Should propose Advanced License with 3 years support subscription. 3 years 9X5XNBD Vendor Support and Replacement warranty. | جهاز | 19 | 0 | — |
| 20 | 2000 | نقاط الوصول بالشبكة اللاسلكية Access Point | Below are the required specs for Indoor Wi-Fi6 AP Wi-Fi Standards supported 802.11a/b/g/n/ac/ax Dual band 2.4GHz and 5 GHz Should support Triple-Radio including RF scanning radio. Should support Software-Defined Radio (SDR) that can perform advanced RF spectrum analysis with independent radio scanning mode and achieving real-time detection of interference and rogue devices in real time and timely network optimization. Flexible Radio Assignment with tri-radio mode allows the access points to intelligently determine the operating mode of serving radios based on the RF environment and traffic demands. The access points can operate in the following modes: Dual-radio mode: One 4x4 5 GHz and one 4x4 2.4 GHz. One radio will serve clients on the 5-GHz band, while the other serves clients on the 2.4-GHz band. Tri-radio mode: Dual 5 GHz and One 2.4 GHz. With two 5-GHz and one 2.4-GHz radios (tri-radio) inside the access point, client device capacity can be increased on demand. Should have Multi-gig port 5G/2.5GE + 1 x GE ports. Smart antenna array technology enables targeted signal coverage for mobile terminals, reduces interferences, and improves signal quality. USB interface can be used for external power supply, external IoT expansion, and storage. Integrated Bluetooth Low Energy (BLE) 5 radio enables location-based use cases such as asset tracking, wayfinding, and analytics. Uplink/downlink MU-MIMO with eight spatial streams Uplink/downlink OFDMA TWT BSS coloring MRC 802.11ax beamforming 20-, 40-, 80-, and 160-MHz channels Support PHY data rates not less than 5.0 Gbps for the device. 802.11 DFS CSD support WPA3 support Coupled with ACs, the APs should identify over thousands common applications in various office scenarios Built-in dual-band omnidirectional antennas Should propose Advanced License with 3 years support subscription. 3 years 9X5XNBD Vendor Support and Replacement warranty. | جهاز | 20 | 0 | — |
| 21 | 1500 | نقاط الشبكة النحاسية UTP | نقطة الشبكة هي عملية توصيل جميع المكونات الخاملة (Passive Components) وهي تشمل كابلات Cat6A مع تركيبها بالكامل وتشمل الـ patch panels, وتشمل الـ patchcord داخل الكبائن (متر واحد) لكل نقطة وخارج الكبائن (ثلاثة أمتار ) لتوصيل الهواتف الشبكي بالشبكة، وتشمل أيضًا الـ faceplate وجميع ملحقات الكيابل النحاسية الضرورية للتركيب وأي أعمال مدنية ضرورية داخل المباني ضرورية لتمديد الكيابل كخرم الجدران مثلاً ووضع مسارات للكيابل. وعلى المتعاقد الالتزام بالكامل المواصفات التالية: الكيابل النحاسية الخاصة بالشبكة: 1- المواصفات العامة: جميع الأنابيب المطلوبة لتمديد كيابل الشبكات من داخل وخارج غرف تجميعها وخلال الأنابيب في الموقع العام يجب أن لا تكون بها انحناءات أكثر من 90 درجة وبطول لا يتجاوز 90متر. يجب توفر مسارات لجميع نقاط الاتصال بين الأجهزة في الطابق الواحد وبين الطوابق. يجب ان تكون جميع الكيابل في مسارات مستقلة عن كيابل الكهرباء. يجب أن تكون العلب الجدارية الخاصة بالنقاط متناسبة مع حجم NEMA المعتمد عالمياً. يجب أن تكون الأنابيب المستخدمة لتمديد الكابلات النحاسية فيها السعة الكافية لتمديد كيابل الشبكات ذات الأربع أزواج وأيضاً لتمديد أكثر من كيبل على أن تكون مستقلة عن أي كيابل تخص أنظمة اخرى. جميع لوحات التجميع وملحقات الكيابل النحاسية من مخارج وموصلات ان تكون من شركة مصنعة واحدة. 2- ضمان الجودة: جميع مكونات الكيابل يجب ان يتم تركيبها استنادا الى كتالوجات الشركة المصنعة. جميع مكونات الكيابل يحب أن تتحمل نظام UL او ETL في الأداء. تركيب الكيابل يجب أن يتوافق مع المعايير المحلية وأنظمة السلامة. جميع مواد الكيابل يجب أن تكون جديدة وغير مستخدمة من قبل. الشركة المصنعة للمواد يجب أن تكون حائزة على شهادة ISO 9001 ويجب أن تطبق معيار Sigma Methodology خلال عملية التصنيع وذلك لضمان جودة الكيابل. 3- مؤهلات اختبار النظام: يجب على المتعاقد أو متعاقد الباطن الذي سيعمل على تركيب النظام أن تكون له خبرة في مجال تركيب الكيابل النحاسية والألياف الضوئية واختبار هذه الكيابل بالطرق المعترف بها دوليا وتقديم جميع المستندات الخاصة بالاختبار. 4- التركيب: • تركيب جميع المواد بشكل مرتب وانيق داخل الكبائن وفي مسارات و حوامل الكيابل. • يجب ان لا يتجاوز طول الكيابل النحاسية 90 متر. • تمديد الكيابل الرئيسية بناءا على توصيات الجهة المصنعة. • جميع كيابل تمدد داخل مواسير بلاستيكية داخل المبنى وتمدد داخل مواسير مدعمة بالحديد خارج المبنى. • جميع مسارات كيابل الاتصالات الرئيسية يجب ان يكون بها فتحات للصيانة والتمديد. • المتعاقد المنفذ يجب ان يوفر القطع المتضررة بسبب العمالة بسرعة خلال فترة العمل ولن يكون عليها اي تكاليف اضافية. • توفير مسافة تساوي 20 انش للصيانة في كل غرف الاتصال. • توصيل النهايات بحيث لا تكون هناك اي قوة شد عليها. • التأكد من ترقيم الكيابل الرئيسية بعناية ودقة لضمان عدم مسحها في جميع النهايات. • ترقيم جميع التمديدات بملصقات بلاستكية من طرفي لوحات التجميع والمخرج الحائطي والعلب لكل كيبل. 5- الحماية: يجب على المتعاقد الذي سيعمل على تركيب أن يعمل على التخلص من المواد الغير لازمة للمشروع خلال وبعد تنفيذها للمشروع وتتأكد من النظافة. يجب على المتعاقد الذي سيعمل على تركيب المواد أن يعمل على تخزين المواد في بيئة مناسبة الى حين تنفيذ المشروع وذلك بناءً على ما يلي:- درجة الحرارة لا تتجاوز 120 درجة فهرنهايت ولاتقل عن 32 درجة فهرنهايت. الرطوبة لا تزيد عن 80%. لا تتعرض مباشرة الى أشعة الشمس. 6- الضمان: يجب على المتعاقد الذي سيعمل على تركيب التمديدات أن يقدم ضمان لمدة خمس سنوات لجودة التركيب. يجب على المتعاقد الذي سيعمل على تركيب التمديدات أن يقدم ضمان لمدة 15 سنة من الشركة المصنعة على المواد ضد عيوب التصنيع. الكيابل النحاسية CAT 6A UTP 1. وصف الكيابل CAT 6A :- • الكيابل النحاسية خالية من الهالوجين ومضاد للاحتراق حسب الاشتراطات (Low-Smoke, Zero-Halogen LSOH/LSZH) • الكيابل النحاسية التي سوف تمدد أفقيا يجب أن تكون من نوع CAT 6A UTP, كل أربعة ازواج من هذا الكيبل توصل في موصل من نوع CAT 6 بواسطة نظام 110 IDCs. يجب أن تتوافق أحجام هذه الموصلات مع حجم علبة النقطة في الموقع وكذلك مع حجم لوحة التوزيع النحاسية في الكابينة. • يجب ان تكون مصنفة ضمن معيار (RFT). • نوعية ربط المقابس في منتجات يحمي من الاضرار المتوقعة من المجال الكهرومغناطيسي وتأثيراته المتزايدة على المدى الطويل. • الكيابل النحاسية (CAT 6A) يضمن الارتفاع الى أكثر من 250 ميغاهيرتز ( وهي مدى قياسي) في مجال تقييم التأثيرات البيئية القياسية. • سهولة تركيب (الجاك JackRapid) في منتجات علاوة على انها تعطي معدل 8 مرات أسرع من المعدلات الطبيعية • سهولة الوصول وقابلية تحمل الاستخدام المكثف في التطبيقات والذي يرفع من الأداء العام لشبكات المعلومات على المدى الطويل. • الكيابل النحاسية لها القدرة لدعم وتوصيل الخطوط الصوتية العادية والرقمية. • الكيابل النحاسية تكون مقاومة للحريق حسب النظام العالمي. 2. يجب أن تكون جميع الكيابل تتوافق مع المعايير العالمية التالية:- ANSI – American Northern Standards Institute AWG – American Wire Gauge BICSI – Building Industry Consulting Service International EIA – Electronics Industry Alliance ETL – Intertek Semko Labs FCC – Federal Communications Commission IEC – International Electrotechnical Commission IEEE – Institute of Electrical and Electronic Engineers IDC – Insulation displacement contact ISO – International Standards Organization J-STD – Joint Standard NECA – National Electrical Contractors Association NFPA – National Fire Protection Agency SC – Subscriber Channel TIA – Telecommunications Industry Association UL – Underwriters Laboratory 10GBase-T – networking protocol capable of transmitting 1 billion bits of information per second over copper twisted pair 10GBase-SX – networking protocol capable of transmitting 10billion bits of information per second over optical fiber at 850 nanometers. Fire performance: Comply with the following Standards - EN 50288-1 / - EN 50173 - ISO/IEC 11801 - TIA/EIA 568-B - IEC 611156-5 | نقطة | 21 | 0 | — |
| 22 | 200 | نقاط الألياف الضوئية داخل المباني Indoor Fiber (per uplink) | الألياف الضوئية هي عملية توصيل جميع المكونات الخاملة (Passive Components) للكابلات الألياف البصرية اللازمة مع تركيبها بالكامل وتشمل الـ patch panels, وتشمل الـ patchcord داخل الكبائن (متر واحد) ) لكل نقطة وكيابل الألياف الضوئية نفسها وجميع ملحقات الألياف الضوئية الضرورية للتركيب وأي أعمال مدنية ضرورية داخل المباني لتمديد الكيابل كخرم الجدران مثلاً ووضع مسارات للكيابل. وعلى المتعاقد الالتزام بالمواصفات التالية بالكامل: 1- المواصفات العامة : • جميع الأنابيب المطلوبة لتمديد كيابل الشبكات من داخل وخارج غرف تجميعها وخلال الأنابيب في الموقع العام يجب أن لا تكون بها انحناءات أكثر من 90 درجة. • يجب توفر مسارات لجميع نقاط الاتصال بين الأجهزة في الطابق الواحد و بين الطوابق. 2- ضمان الجودة : 1) جميع مكونات الكيابل يجب ان يتم تركيبها استنادا الى كتالوجات الشركة المصنعة. 2) جميع مكونات الكيابل يحب أن تتحمل نظام UL او ETL في الأداء. 3) تركيب الكيابل يجب أن يتوافق مع المعايير المحلية وأنظمة السلامة. 4) جميع مواد الكيابل يجب أن تكون جديدة وغير مستخدمة من قبل. 6) الشركة المصنعة للمواد يجب أن تكون حائزة على شهادة ISO 9001 ويجب أن تطبق معيار Sigma Methodology خلال عملية التصنيع. 3- مؤهلات المتعاقد المنفذ: المتعاقد الذي سوف يعمل على تركيب النظام يجب أن يكون معتمدة من الشركة المصنعة ويجب أن يوفر مهندس وفنين حاصلين على شهادات التركيب من الشركة المصنعة. 4- مؤهلات اختبار النظام: يجب على المتعاقد الذي سيعمل على تركيب النظام أن تكون شركة لها الخبرة في مجال تركيب الكيابل النحاسية والألياف الضوئية واختبار هذه الكيابل بالطرق المعترف بها دوليا وتقديم جميع المستندات الخاصة بالاختبار. 5- التركيب : • تركيب جميع المواد بشكل مرتب وانيق داخل الكبائين وفي مسارات و حوامل الكيابل. • يجب ان لا يتجاوز طول كيبل الالياف الضوئية 300 متر. • جميع كيابل تمدد داخل مواسير بلاستيكية داخل المبنى وتمدد داخل مواسير مدعمة بالحديد خارج المبنى. • جميع مسارات كيابل الاتصالات الرئيسية يجب أن يكون بها فتحات للصيانة والتمديد. • التأكد من أن أكبر قوة لشد كيبل الألياف الضوئية لا تتجاوز 50 باوند لكل قدم. • معدل الخسارة في الإشارة لابد أن لا يتجاوز فيSM 0.03 dB وفيMM 0.00 dB خلال عملية اللحام. • المتعاقد المنفذ يجب ان يوفر القطع المتضررة بسبب العمالة بسرعة خلال فترة العمل ولن يكون عليها اي تكاليف اضافية. • توفير مسافة تساوي 20 انش للصيانة في كل غرف الاتصال. • توصيل النهايات بحيث لا تكون هناك اي قوة شد عليها. • التأكد من ان معدات اللحام لكيابل الالياف الضوئية معتمدة للعمل بها. • التأكد من ترقيم الكيابل الرئيسية بعناية ودقة لضمان عدم مسحها في جميع النهايات. • ترقيم جميع التمديدات بملصقات بلاستكية من طرفي لوحات التجميع والمخرج الحائطي والعلب لكل كبيل. 6- الحماية • يجب على المتعاقد الذي سيعمل على تركيب أن يعمل على التخلص من المواد الغير لازمة للمشروع خلال وبعد تنفيذها للمشروع وتتأكد من النظافة. • يجب على المتعاقد الذي سيعمل على تركيب المواد أن يعمل على تخزين المواد في بيئة مناسبة الى حين تنفيذ المشروع وذلك بناءا على ما يلي:- • درجة الحرارة لا تتجاوز 120 درجة فهرنهايت ولاتقل عن 32 درجة فهرنهايت. • الرطوبة لا تزيد عن 80%. • لا تتعرض مباشرة الى أشعة الشمس. 7- الضمان • يجب على المتعاقد الذي سيعمل على تركيب التمديدات أن يقدم ضمان لمدة خمس سنوات لجودة التركيب. • يجب على المتعاقد الذي سيعمل على تركيب التمديدات أن يقدم ضمان لمدة 20 سنة من الشركة المصنعة على المواد ضد عيوب التصنيع وعلى أن كيابل الألياف تنقل البيانات بسرعة 10GBase-SX لمسافة 300 متر. كيابل الألياف الضوئية Fiber Optic 1. المواصفات العامة : كيابل الألياف الضوئية تتكون من نوع الليزر المحسن OM3. جميع نهايات الألياف الضوئية توصل على موصل من نوع SC وتوضع على لوحة التوزيع الضوئية عن طريق محول بلاستيكي، كل محول له سعه لمجموعة من الموصلات من نوع SC لا تقل عن 8 موصلات مزدوج لكل محول. موصلات كيبل الفايبر Fiber connectors الذي تحتاجه الجهة الحكومية يتم تأمين نوع .LC-LC both sides 2. يجب ان تكون جميع الكيابل تتوافق مع المعايير العالمية التالية:- • CAD – Computer Assisted Design • Decibel – unit of measurement that expresses the magnitude of power relative to a specified reference level • ICEA – Insulated Cable Engineers Association • IL – Insertion Loss is a decrease in transmitted power • MHz – Megahertz • Micron (um) – unit of measure for width which is one millionth of a meter • Multi-mode – optical fiber designed to carry multiple carrier signals distinguished by frequency or phase at the same time • Nanometer (nm) – unit of measure for light wavelength which is one billionth of a meter • Ohm – Measure of electrical resistance or impedance • OLTS – Optical Loss Test Set • OTDR – Optical Time Domain Reflectometer • RL – Return Loss is the ratio, expressed in decibels, of the power of the outgoing signal to the power of the signal reflected back • Tier 1 – testing of power loss through an optical fiber expressed as decibels • Tier 2 – testing using a backscatter method to capture characteristics of an optical fiber link • TSB – Telecommunications Supplemental Bulletin 3. وصف كيابل الألياف الضوئية: • كيابل الألياف الضوئية تقدم خدمة نقل البيانات بسرعات عالية وكميات كبيرة بين أجزاء النظام أو نقاط الاتصال عن طريق استخدام موجات ضوئية ذات طول موجي قصير • كيابل الألياف الضوئية محمية بمادة (HDPE and PVC Jackets with Jell Filled) للحماية من الحريق والتلف. • كيابل الألياف الضوئية يتم توصيلها عن طريق موصلات من نوع SC مزدوجة بحسب نقطة التوصيل في اجهزة الشبكات. • كيبل ضوئي له القدرة لدعم التردد القاعدي لترددات تطبيقات عالية من الصوت والبيانات والفيديو باستخدام 850 نانو ما يكون او 1300 نانو مايكرون. • كيبل ألياف ضوئية يوصل من لوحة الى اخرى باستخدام موصلات من نوع SC عبر محولات بلاستيكية توجد على اللوحات. • كيبل ألياف ضوئية يقدم نقل مستمر لبيانات باستخدام طول موجي ضوئي قصير بدون تقطع او خطأ. • كيبل ألياف ضوئية ييكون سمكه وحجمه صغير اثناء التمديد. • كيبل ألياف ضوئية له قطر يساوي .52”0.مع خلال تمديد الكيبل. • كيبل ألياف ضوئية له قطر يساوي .58”0.مع خلال تشابك الكيابل. 4. متطلبات كيبل الألياف الضوئية: • كيبل ألياف ضوئية خالي من الهالوجين ومضاد للاحتراق حسب الاشتراطات (Low-Smoke, Zero-Halogen LSOH/LSZH) • كيبل ألياف ضوئية OM3 قادر على نقل البيانات بسرعة 10 جيجا لمسافة 300 متر باستخدام طول موجي صغير يساوي 850 نانو مايكرون. • كيبل ألياف ضوئية ذو 8 شعرة ضوئية. • كيبل ألياف ضوئية له طبقة حامية لكل شعرة تساوي 900 مايكور متر. • كيبل ألياف ضوئية له طبقة حامية من مادة PVC تقي من الاحتراق. • كيبل الياف ضوئية مضمونة لنقل البيانات بسرعة 10 جيجا لمسافة 300 متر عند الطول الموجي الضوئي والذي يساوي 850 نانو متر. • كيبل الياف ضوئية يدعم التطبيقات ذات السرعات 10GBase-SX طوال مدة عمل النظام. • كيبل الياف ضوئية محمي من الداخل ومن الخارج. • موصلات من نوع SC يمكن اعادة فكها وتركيبها و تستخدم داخلياً وخارجياً. 5. معايير نظام كيابل الألياف الضوئية:- a) كيبل الياف ضوئية له القدرة لتحقيق ادنى المتطلبات التالية: • معدل خسارة في الاشارة يساوي 3.5 dB لكل كيلو متر عند الطول الموجي الضوئي والذي يساوي 850 نانو متر. • معدل خسارة في الاشارة يساوي 1.25 dB لكل كيلو متر عند الطول الموجي الضوئي والذي يساوي 1300 نانو متر • كيبل ألياف ضوئية يملك تأثير ليزري يساوي 2000 MHz عند الطول الموجي الضوئي 850 نانو متر و تأثير ليزري يساوي 500 MHz عند الطول الموجي الضوئي 1300 نانو متر. • كيبل ألياف ضوئية يملك اقصى تردد يساوي 1500MHz/Km. b) موصل كيبل ألياف ضوئية متعدد الأنظمة من نوع SC يحقق الخواص الميكانيكية عند اختبار TIA-604(FOCIS) و TIA-455(FOTP). • معدل خسارة في الاشارة يساوي 0.2 dB عند التركيب. • معدل انعكاس في الاشارة يساوي -25dB. • معدل خسارة في الاشارة عند تكرارية الموصل اقل من 0.01 dB. • يعمل في درجة حرارة ما بين -40 ال 85 درجة مئوية. 6. الاختبار المطلوب لكيابل الألياف الضوئية • يجب أن يختبر الكيبل بواسطة OLTS عند الطول الموجي الضوئي 850 و 1300 نانو متر. • الاختبار للكيبل ينفذ من النهايتين ليوضح الخسارة في الاشارة والتي يجب ان لا تكون اعلى من 2 dB. • اختبار OTDR مطلوب اذا استخدم اي نوع من انواع لحام شعيرات الكيبل | نقطة | 22 | 0 | — |
| 23 | 50 | نقاط كهرباء220 فولت Socket outlet (220V) | • توريد وتركيب وتشغيل واختبار نقاط كهرباء وتشمل مخرج قوى 220 فولت (P+N+E) مع مفتاح تشغيل بلمبة إشارة 13A وربطه وتوصيله بدائرة التغذية واللوحة الفرعية. • يشمل السعر أيضاً المواسير والعلب والجلب والأكواع والإكسسوارات والاسلاك 2X6+6mm2 والربط مع اللوحة الفرعية. • القيام عند التركيب بأي أعمال مدنية ضرورية داخل المباني لتمديد الأسلاك كخرم الجدران مثلاً مع إعادتها كما كانت. • يجب ان تكون جميع الأسلاك في مسارات مستقلة عن كيابل شبكة الحاسب الآلي. • يلتزم المتعاقد بتقديم عينات للاعتماد. | نقطة | 23 | 0 | — |
| 24 | 10 | كبينة رئيسية مع مروحة وموزع طاقة Cabinet 42U with PDU | منتج وطني ذو ماركة مسجلة ومعروفة بجودة عالية. مقاس (800mm x 1000mm). الملائمة: ذات فتحات كبيرة لوصول الكابل من السقف، وتصميم الجزء السفلي يسمح لوصول الكابل دون عائق. التهوية : مثقب من الأمام والأبواب الخلفية لتوفير تهوية وافرة للخوادم ومعدات الشبكات. أبواب تفتح بشكل سريع ويمكن نقل جبهة الباب على الجانب الآخر أو بشكل تبادلي مع الأبواب الخلفية تتم إزالته بسهولة مع تصميم بسيط عند التركيب. ضبط تصاعد القضبان. الأبواب الخلفية سبليت لتحسين خدمة الجزء الخلفي من رفوف المعدات. الأبواب الخلفية يجب أن تكون مقسمة لزيادة المساحة . قوائم ضبط الاستواء بحيث يمكن أن يتم تعديل قوائم الاستواء بسرعة عن طريق استخدام مفك البراغي ، مما يلغي الحاجة للوصول إلى الأسفل. أسس متكاملة كهربائية السقف، وترتكز الألواح الجانبية والأمامية والأبواب الخلفية إلى الإطار من الكابينة. وتقع ثمانية إدراج إضافية على الإطار الخارجي للتأريض. مع الالتزام بالمواصفات الفنية التالية: Compatibility Guaranteed Compatability Vendor-neutral mounting for guaranteed compatibility with all EIA-310 compliant 19" equipment. Convenience Cable Access Large cable access slots in the roof to provide access for overhead cable egress. The bottom design should allow for unobstructed cable access through a raised floor if needed. Ventilated Perforated front and rear doors provide ample ventilation for servers and networking equipment. Quick release doors Front door can be moved to the opposite side or interchanged with rear doors. Doors are easily removed with simple lift-off design. Agility Adjustable mounting rails The vertical mounting rails can be adjusted in 1/4 in (6.4 mm) increments covering virtually any mounting requirement for IT equipment. U positions are numbered front and back for rapid installation of equipment. Split rear doors Split rear doors improve access and serviceability to rear of rack mounted equipment. The split rear doors help to maximize floor space. Only 11 inches (279 mm) of clearance is required behind the enclosures to allow for door swing. Adjustable leveling feet Leveling feet can be quickly adjusted through the use of a screwdriver or drill, eliminating the need to reach underneath with a wrench. Joining capability Enclosures include pre-installed joining hardware to join enclosures in a row and provide additional stability to the enclosure. Safety Integrated electrical grounding The roof, side panels and front and rear doors are grounded to the frame of the enclosure. Eight additional electrical grounding inserts are located on the frame for external grounding. All cabinets should come from the same manufacturing company of the cabinets in the data center. موزع الكهرباء PDU لتوزيع الكهرباء على الأجهزة وإمكانية تركيبها بالكبائن دون اخذ اي مساحة في مكان الأجهزة مع ربطها بالتيار الكهربائي دون اي مخاطرة حيث يقوم بإعطاء كل جهاز الطاقة الكهربائية اللازمة فلذلك يجب تامين موزع الكهرباء الذي يحمل الموصفات التالية:- Basic Rack PDU, Input: 200V, 208V, 230V, Input Connections: IEC 309 16A 2P+E, Cord Length: 3 feet 0.91 (meters), Output: 230V, Output Connections: IEC 320 C13, IEC 320 C19 • Tool less mounting into SX enclosure • A single rack-mount PDU is capable of providing up to 3,7kW of power, eliminating multiple connector strips per rack • Localized amperage LED indicator • Uniproduct l IEClocking input plug. •From the vendor of the cabinets • يجب ان تكون جميع الكبائن تتوافق مع المقاييس العالمية CE, GOST, IRAM & VDE يجب أن تكون الموزعات من نفس الشركة المصنعة للكبائن المروحة Fan توريد مروحة الكبينة من نفس الشركة المصنعة للكبائن وتكون جزءًا من الكابينة وتحمل المواصفات الفنية التالية: Facilitates overhead cable management Overhead cable troughs and partitions install toollessly on the roof of the enclosure eliminating the need for ceiling mounted or underfloor mounted cable trays. Cable troughs and partitions are designed to manage both power and data cables while maintaining separation. Promotes bottom to top airflow Tool-less mounting Cable pass-through Grommeted Edges Powder coat paint finish Rack Air Distribution Features & Benefits Availability Increases Airflow Provides proper intake temperatures, increasing equipment life. Dual A-B Power Inputs Draws power from the UPS for power protection with dual feeds for redundancy. Agility Air Filtration Removes dirt and other particulates from the intake air for cleaner supply air. • From the same vendor of the cabinets | كبينة | 24 | 0 | — |
24 بند
كراسة الشروط الرئيسية
كراسة الشروط والمواصفات وملاحق المنافسة
2.7 MB
تم التحميل
2021/276676/main_booklet_كراسة_الشروط.html
المستندات الداعمة (1 ملف)
دعم محاكم الاستئناف بأجهزة الربط الذكية.zip
3.3 MB
تم التحميل
2021/276676/idd_EA6F4295-02B0-C4E6-8536-7B96AEB00000_دعم_محاكم_الاستئناف_بأجهزة_الربط_الذكية.zip
لم يتم ترسية هذه المنافسة بعد
لا توجد بيانات للمحتوى المحلي
معايير التقييم
لا توجد معايير تقييم
أخبار المنافسة
لا توجد أخبار