منافسة عامة ✓ مرسّى

توريد وتركيب موجهات ومزعات الشبكة ونظام السنترال وملحقاته

المباحث العامة

رقم المنافسة

250939014618

المعرّف

#1000771

رقم المنافسة
250939014618
رقم المنافسة الداخلي
3450
الجهة الحكومية
المباحث العامة
الفرع / الإدارة
الـمـنـافـســـات
نوع المنافسة
منافسة عامة
حالة المنافسة
تم اعتماد الترسية
طريقة تقديم العروض
ملف واحد للعرض الفني والمالي معا
رسوم الاشتراك
500 ر.س
سعر كراسة الاشتراط
تكلفة الدعوة
200 ر.س
تكلفة الشراء
500 ر.س
الضمان الإبتدائي
ضمان إبتدائى
الضمان النهائي
5.00%
مدة العقد
4 شهر
التأمين مطلوب
لا
مدة الوقفة (أيام)
5
داخل المملكة

عنوان الضمان الإبتدائى

حسب ملف الضمان البنكي المرفق بملحقات المشروع

الغرض من المنافسة

توريد وتركيب موجهات ومزعات الشبكة ونظام السنترال وملحقاته

التاريخ ميلادي هجري
تاريخ النشر 2025/09/21 12:18
آخر موعد للاستفسارات 2025/10/01 1447-04-09
آخر موعد تقديم العروض 2025/10/12 07:00 1447-04-20
موعد فتح العروض 2025/10/12 07:00 1447-04-20
موعد فحص العروض
التاريخ المتوقع للترسية 2025/10/12 1447-04-20
تاريخ بدء الأعمال 2025/10/19 1447-04-27
تاريخ خطاب تأكيد المشاركة
بداية إرسال الأسئلة 2025/10/11 1447-04-19
أقصى مدة للإجابة 3 يوم
مكان فتح العروض الرياض طريق الملك عبدالعزيز مبنى وزارة الداخلية القديم
مدة الوقفة 5 يوم

موقع التنفيذ

منطقة التنفيذ
منطقة تبوك
مدن التنفيذ
تبوك
موقع التنفيذ
داخل المملكة

مجال التصنيف

مجال التصنيف
غير مطلوب
يشمل مواد توريد
نعم

الأنشطة

  • الإتصالات
  • تقنية المعلومات

جدول 1 المواد - تقنية معلومات

البند الكمية وصف البند المواصفات وحدة القياس الرقم التسلسلي منتج من القائمة الإلزامية
رقم1 1 توريد وتركيب جهاز موجه شبكة توريد وتركيب جهاز موجه شبكة وعمل التهيئة اللازمة شاملاً جميع التوصيلات اللازمة لتشغيله بالمواصفات التالية: منصات سحابية جاهزة لشبكة 5G ومصممة لخدمة الوصول الآمن Edge SASE والأمان متعدد الطبقات وسرعة الحركة السحابية الأصلية لتسريع رحلة الأعمال إلى السحابة. تصميم الأنظمة الأساسية خصيصًا للأداء وخدمات SD-WAN المتكاملة إلى جانب المرونة في تقديم خدمات الأمان والشبكات معًا من السحابة أو في مكان العمل. يجب أن تحتوي منصات Edge على مجموعة واسعة من خيارات الواجهة للاختيار من بينها، مع التوافق مع الإصدارات السابقة لوحدات WAN وLAN والوحدات الصوتية الحالية. مدعومًا بـ IOS XE، وهي بنية برمجية قابلة للبرمجة بالكامل ودعم واجهة برمجة التطبيقات (API)، تعمل على تسهيل الأتمتة على نطاق واسع لتحقيق إمكانية تكنولوجيا المعلومات بدون لمس أثناء ترحيل أعباء العمل إلى السحابة. تأتي المنصات أيضًا مع بنية أساسية جديرة بالثقة للحل 2.0 والتي تؤمنها ضد التهديدات ونقاط الضعف من خلال التحقق المتقدم من السلامة ومعالجة التهديدات. الحجم: 1RU مع فتحة واجهة الشبكة NIM واحدة ومنافذ WAN 4×1 جيجابيت إيثرنت الميزات الرئيسية: • المعالج: وحدة المعالجة المركزية Intel x86 متعددة النواة مع ذاكرة DRAM سعة 8 جيجابايت افتراضية • يجب استخدام وحدة معالجة مركزية Intel x86 مع ذاكرة افتراضية سعة 8 جيجابايت وأن يكون بها فلاش مدمج سعة 8 جيجابايت ويمكن ترقية التخزين إلى 16 جيجا و32 جيجا USB و600 جيجا. • تدعم المعالجات متعددة النواة عالية الأداء اتصالات WAN عالية السرعة • تعمل بنية التخصيص الأساسي الديناميكي على إعادة استخدام النوى غير المستخدمة في إعادة توجيه الكيانات وفقًا لتكوين المستخدم تسريع أجهزة IPsec VPN المضمنة: • تمكين ما يصل إلى 1 جيجابت في الثانية من حركة مرور IPsec • زيادة قابلية التوسع لمتطلبات إنتاجية IPsec • تسريع أجهزة SSL والتشفير منافذ جيجابت إيثرنت مدمجة • يوفر أربعة منافذ Ethernet WAN مدمجة • منفذا إيثرنت صغيران الحجم قابلان للتوصيل (SFP) ومنفذان RJ45، مما يتيح اتصال الألياف والنحاس • المدمج في تجزئة نهاية إلى نهاية (VPN)، ZBFW، PKI، وأمن طبقة الحمض النووي، SIG • دعم التحكم المركزي من خلال وحدة تحكم SD WAN. • يجب أن يحتوي الحل المقترح على ترخيص لدعم حركة مرور التشفير بسرعة 200 ميجا بت في الثانية على الأقل. مواصفات الأجهزة: الذاكرة DRAM: • 8 جيجا بايت رام • يمكن ترقيتها إلى 16 جيجابايت و32 جيجابايت من ذاكرة الوصول العشوائي الديناميكية (DRAM) للحصول على نطاق وأداء أعلى ذاكرة فلاش: • فلاش 8 جيجا تخزين M.2: • مساحة التخزين (M.2 SSD) الافتراضية: 16 جيجابايت • يمكن ترقيتها إلى سعة تخزين 32 جيجا بايت M.2 USB و600 جيجا بايت M.2 للذاكرة السريعة غير المتطايرة (NVMe) واجهة الشبكة: • يجب أن يكون لديك 4 منافذ Ethernet WAN مدمجة: o منفذا إيثرنت صغيران قابلان للتوصيل (SFP) ومنفذان RJ45، مما يتيح اتصال الألياف والنحاس. نمطية وعامل الشكل • 1-وحدة الرف (1RU) ذات عامل الشكل • يدعم فتحات NIM ووحدة الواجهة القابلة للتوصيل (PIM). مواصفات المنصة: • كثافة منفذ 1G = 4 فتحات: • 1 × نيم • 1 × بيم مزود الطاقة: • مصدر طاقة تيار متردد ثابت • الحد الأقصى لتصنيف الطاقة: 100 واط يجب دعم: أداء المنصة: • إنتاجية SD-WAN IPsec (1400 بايت): ما يصل إلى 1 جيجابت في الثانية • مقياس أنفاق تراكب SD-WAN: 2500 مواصفات أداء الوضع المستقل (غير SD-WAN). • إنتاجية إعادة توجيه IPv4 (1400 بايت): ما يصل إلى 3.8 جيجابت في الثانية • إنتاجية IPsec (1400 بايت): ما يصل إلى 1 جيجابت في الثانية • عدد أنفاق واجهة النفق الافتراضية الثابتة IPsec (SVTI): 2500 • الوضع المستقل (غير SD-WAN) قابلية التوسع في النظام • عدد قوائم التحكم بالوصول (ACLs) لكل نظام: 4000 • عدد إدخالات التحكم في الوصول إلى IPv4 (ACEs) لكل نظام: 72,000 • عدد مسارات IPv4: 1.6 مليون بسعة افتراضية 8 جيجابايت، وما يصل إلى 4 ميجا مع 32 جيجابايت • عدد مسارات IPv6: 1.5 مليون بسعة افتراضية 8 جيجابايت، وما يصل إلى 4 ميجا مع 32 جيجابايت • عدد قوائم الانتظار: 16,000 • عدد جلسات ترجمة عنوان الشبكة (NAT): 1.2 مليون مع السعة الافتراضية 8 جيجابايت، وحتى 2 مليون مع السعة 32 جيجابايت • عدد جلسات جدار الحماية: 512,000 • عدد حالات إعادة توجيه التوجيه الافتراضي (VRF): 4000 • دعم وحدة واجهة شبكة واحدة للمستقبل. • يمكن لجهاز التوجيه دعم منافذ الصوت FXO عند الحاجة. • يمكن لجهاز التوجيه أن يدعم ميزة SRST ويمكنه تكوينها كنسخة احتياطية لمدير مكالمات IP Telephony الموجود. • دعم وحدة Cat 18 لشبكات LTE و5G المتقدمة الجاهزة للمستقبل. • يجب أن يكون لديك علامة RFID ومضمنة تحمل الرقم التسلسلي ومعرف المنتج لسهولة إدارة الأصول والمخزون باستخدام أجهزة قراءة RFID التجارية. • دعم التوجيه الديناميكي: OSPF، EIGRP، BGP مع الوظائف التي تدعمها ميزة وحدة التحكم. • اتصال IPSec مع AES-256 بت • دعم تكرار بوابة VRRP وHSRP • دعم تصحيح الأخطاء إلى الأمام (FEC) على حد سواء تكافؤ الحزمة وازدواجية الحزمة ودعم NAT • دعم وظيفة البث المتعدد Auto-RP أو Static RP وIGMPv1 وIGMPv2 • دعم TACAC+ Radius للمصادقة على الجهاز • دعم التغليف 802.1Q • دعم وظائف جودة الخدمة. التحكم في التطبيق، والتشكيل، والمراقبة، ووضع علامات على DSCP، وإعادة الكتابة باستخدام قوائم انتظار تبلغ 16 ألفًا. • دعم MACSEC وSYBCE على كافة المنافذ • جلسة جدار الحماية تصل إلى 512 كيلو بايت • عدد جلسات ترجمة عنوان الشبكة (NAT) المدعومة يصل إلى 1.2 مليون مع ذاكرة وصول عشوائي افتراضية تبلغ سعتها 8 جيجابايت رخصة: • التوصيل والتشغيل للتوصيل لنشر الجهاز بدون لمس • وكيل TE لـ iOSXE على توجيه المؤسسات • رخصة الامتثال لقيود التصدير الأمريكية • DNA Essentials On-Prem Lic 3Y - حتى 200 متر (Aggr، 400 متر) • وضع التشغيل الذاتي لنظام IOS XE للصورة الموحدة الدعم الفني: 3 سنوات من الشركة المصنعة. في يوم العمل التالي، استبدال الأجهزة مسبقًا 8x5x4. Edge Platforms are 5G-ready cloud edge platforms designed for Secure Access Service Edge (SASE), multilayer security, and cloud-native agility to accelerate business journey to cloud. The platforms are purpose-built for performance and integrated SD-WAN services along with flexibility to deliver security and networking services together from the cloud or on premises. Edge Platforms should wide variety of interface options to choose from, with backward compatibility to existing WAN, LAN, and voice modules. Powered by IOS XE, a fully programmable software architecture, and API support, facilitate automation at scale to achieve zero-touch IT capability while migrating workloads to the cloud. The platforms also come with a trustworthy solution 2.0 infrastructure that secures them against threats and vulnerabilities through advanced integrity verification and remediation of threats. 1RU w/ 1 NIM slot and 4x1 Gigabit Ethernet WAN ports Product Key Features: • Processor: Multicore Intel x86 CPU with 8 GB DRAM memory default • Must use and Intel x86 CPU with 8 GB memory default and have an integrated onboard 8-GB flash and not are upgradeable. Storage can be upgraded to 16G,32G USB and 600G. • High-performance multicore processors support high-speed WAN connections • Dynamic core allocation architecture will repurpose unused cores into forwarding entities as per the user’s configuration Embedded IPsec VPN hardware acceleration: • Enables up to 1 Gbps IPsec traffic • Increases scalability for IPsec throughput requirements • SSL and crypto hardware acceleration Integrated Gigabit Ethernet ports • Provides four built-in Ethernet WAN ports • Two Ethernet ports are Small Form-Factor Pluggable (SFP) and two are RJ45 ports, enabling fiber as well as copper connectivity • Built-in end to end segmentation (VPNs), ZBFW,PKI, DNA layer security, SIG • Support Centralized control through the SD WAN controller. • The proposed solution should contain the license for supporting at least 200Mbps Crypto traffic. Hardware Specification: Memory (DRAM): • 8 GB DRAM • Can be upgraded to 16 GB and 32 GB DRAM for higher scale and performance Flash memory: • 8-GB flash M.2 storage: • Storage (M.2 SSD) default: 16 GB • Can be upgraded to 32G M.2 USB and 600G M.2 Non-Volatile Memory Express (NVMe) Storage Network Interface: • Must have 4 built in Ethernet WAN ports: o Two Ethernet ports are Small From Factor Pluggable (SFP) and two are RJ45 ports, enabling fiber as well as copper connectivity. Modularity and form factor • 1-Rack Unit (1RU) form factor • Supports NIM and Pluggable Interface Module (PIM) slots Platform Specifications: • 1G port density = 4 Slots: • 1 X NIM • 1 X PIM Power supply: • Fixed AC power supply • Power maximum rating:100W Must Support: Platform performance: • SD-WAN IPsec throughput (1400 bytes): Up to 1 Gbps • SD-WAN overlay tunnels scale: 2500 Autonomous mode (non SD-WAN) performance specifications • IPv4 forwarding throughput (1400 bytes): Up to 3.8 Gbps • IPsec throughput (1400 bytes): Up to 1 Gbps • Number of IPsec Static Virtual Tunnel Interface (SVTI) tunnels: 2500 • Autonomous mode (non SD-WAN) system scalability • Number of Access Control Lists (ACLs) per system: 4000 • Number of IPv4 Access Control Entries (ACEs) per system: 72,000 • Number of IPv4 routes: 1.6M with default 8 GB, up to 4M with 32 GB • Number of IPv6 routes: 1.5M with default 8 GB, up to 4M with 32 GB • Number of queues: 16,000 • Number of Network Address Translation (NAT) sessions: 1.2M with default 8 GB, up to 2M with 32 GB • Number of firewall sessions: 512,000 • Number of Virtual Route Forwarding (VRF) instances: 4000 • Support one network interface module for future. • The router can support voice ports FXO whenever needed. • The router can support SRST feature and can configure it as a backup for the existing IP Telephony call manager. • Support Cat 18 Module for advanced LTE and 5G ready for future. • Must have and embedded RFID tag that holds the serial number and product ID for easy asset and inventory management using commercial RFID readers. • Support Dynamic routing: OSPF, EIGRP, BGP with the functionality that the controller feature support. • IPSec Connection with AES-256 bit • Support VRRP & HSRP Gateway Redundancy • Support forward error correction (FEC) both packet parity and packet duplication and support NAT • Support Multicast Functionality Auto-RP or Static RP and IGMPv1 and IGMPv2 • Support TACAC+ Radius for authentication to the device • Support 802.1Q Encapsulation • QoS functionality support. Application Control, Shaping, and policing, DSCP Marking, Rewrite with 16K queues. • Support MACSEC and SYBCE on all the ports • Firewall session up to 512k • Number of Network Address Translation(NAT) sessions supported is up to 1.2M with default 8 GB RAM License: • Plug-n-Play Connect for zero-touch device deployment • TE agent for IOSXE on Enterprise Routing • U.S. Export Restriction Compliance license • DNA Essentials On-Prem Lic 3Y - upto 200M (Aggr, 400M) • IOS XE Autonomous boot up mode for Unified image Technical support: 3 years from manufacturer. Next Business Day, 8x5x4 advance hardware replacement. عدد 1 0
رقم2 1 توريد وتركيب سنترال توريد وتركيب سنترال بسعة (8 خطوط خارجية / 30 تحويلة داخلية IP / 4 تحويلة تماثلية) يحتوي على التالي: - كبينة رئيسية تحتوي على عدد (2) كرت كمبو سعة (12) موزعة (4خارجي/2تماثلي/6رقمي)، وتحتوي على عدد (1) كرت رقمي (digital) سعة (8) تحويلة وعدد (2) كرت (VCM) سعة (32) - توريد كرت (SD Cards) مع تنزيل كافة الرخص على نظام السنترال. - توريد وتركيب كيبل بور. - توريد وتركيب حامل حديدي. - توريد وبرمجة رخصة (IP end) عدد (30) رخصة. - توريد وبرمجة رخصة النظام والرد الالي (Preferred). - توريد وبرمجة رخصة (SIP Trunk) بسعة عدد (10) خطوط. - توريد وبرمجة رخصة (Additional voice mail Pro 2Channel) بعدد (2) رخص لتشغيل (4) خطوط إضافية. عدد 2 0
رقم3 2 توريد وتركيب أزرار التوسعة KEM توريد وتركيب أزرار التوسعة KEM بالمواصفات التالية: أزرار توسعة سعة (24) زر Button Expansion module 24 وحدة التوسع على زيادة عدد مظهر المكالمات وأزرار الميزات على الهاتف. توفر وحدة التوسع 24 زرًا إضافيًا للمكالمات الواردة/الصادرة، وللميزات مثل الاتصال التلقائي، لطلب جهات الاتصال، أو لتطبيقات أخرى. المواصفات: شاشة ملونة بحجم 4.3 بوصة، بدقة 272 × 480 بكسل. يدعم هاتف ما يصل إلى 3 وحدات أزرار، ويمكن لكل وحدة أزرار أن تأخذ كلا من وضعي الرفع والتركيب على الحائط مع الهاتف. توفر وحدة التوسع الوصول إلى ما يصل إلى 24 زرًا ومصباحًا مع إمكانية عرض 3 صفحات عند استخدام وحدة توسيع واحدة. يحتوي كل زر ميزة/خط على مؤشر باللونين الأحمر والأخضر. تتوفر خلفيات أو شاشات توقف مُعدة مسبقًا لتتناسب مع الهاتف الأساسي. يتم توفير الطاقة من خلال الهاتف الأساسي (PoE) الفئة 2 Key Expansion Module: Expansion Module extends the number of call appearances and feature buttons on the Phone. Expansion module provides 24 additional buttons for incoming/outgoing calls, for features such as autodial, for dialing contacts, or for other applications. Specifications: • 4.3 inches, 272 x 480-pixel color display. • Phone support up to 3 button modules, and each button module can take both Stand and Wall mount positions together with the phone. • Expansion Module provides access to up to 24 buttons and lamps with ability to display 3 pages when a single expansion module is used. • Each feature/line button has a red/green indicator. • Pre-configured background or screensavers are available to match the base phone. Power is supplied by base phone (PoE class 2). عدد 3 0
رقم4 1 توريد وتركيب جهاز خادم لتسجيل المكالمات توريد وتركيب جهاز خادم لتسجيل المكالمات بالمواصفات التالية: تأمين جهاز خادم لرصد وتسجيل المكالمات متوافق مع الافايا شامل كامل الرخص وتوفير رخصة (Media Manger) ويكون بسعة تخزينه لا تقل عن (4) تيرا ويوجد به خاصية التعرف على التحويلات مع شاشة كاشف رقم المتصل نوع (Dell Or hp) (LED) للمآمير وبحجم لا يقل عن (21) بوصة مع كيبل شبكة لربطه بين الشاشة ونظام تسجيل المكالمات. • Processor: o Intel® Xeon® E-2200 Family o Minimum Intel® Xeon® E3-2224 3.4 GHz 12M cache o Number of processors: 1 o Processor core: 8 • Minimum Cache Memory: o 12 MB L3 • Memory: o 32 GB (16 x 8GB) RDIMM –DDR4 smart memory • Storage: Minimum o RAID for matching drives o Storage 1: 2 x SSD 512 GB capacity o Storage 2:  RAW Capacity: 4TB  2 x 2 TB capacity • Storage Controller: Storage As per proposed design requirement. • Network Options o 2 x 1Gb Ethernet 2-port LOM Adapter Operating system: Must be compatible with Avaya. Accessories: server with all accessories Key Board Mouse and, components and cables ready to use. Warranty: 3 years. عدد 4 0
رقم5 1 توريد وتركيب نظام حفظ الطاقة UPS توريد وتركيب نظام حفظ الطاقة (UPS) بالمواصفات التالية: - توريد نظام تغذية احتياطية (UPS) (مواصفات أمريكية أو أوربية) قدرة 6 KVA)) مع البطاريات الجافة نوع راك. - توريد البطاريات الجافة الإضافية لتشغيل السنترال وملحقاته لمدة (4) ساعات على الأقل عند انقطاع التيار الكهربائي مع الأحمال نوع راك. عدد 5 0
رقم6 1 توريد وتركيب جهاز موجه شبكة توريد وتركيب جهاز موجه شبكة وعمل التهيئة اللازمة شاملاً جميع التوصيلات اللازمة لتشغيله بالمواصفات التالية: منصات سحابية جاهزة لشبكة 5G ومصممة لخدمة الوصول الآمن Edge SASE والأمان متعدد الطبقات وسرعة الحركة السحابية الأصلية لتسريع رحلة الأعمال إلى السحابة. تصميم الأنظمة الأساسية خصيصًا للأداء وخدمات SD-WAN المتكاملة إلى جانب المرونة في تقديم خدمات الأمان والشبكات معًا من السحابة أو في مكان العمل. يجب أن تحتوي منصات Edge على مجموعة واسعة من خيارات الواجهة للاختيار من بينها، مع التوافق مع الإصدارات السابقة لوحدات WAN وLAN والوحدات الصوتية الحالية. مدعومًا بـ IOS XE، وهي بنية برمجية قابلة للبرمجة بالكامل ودعم واجهة برمجة التطبيقات (API)، تعمل على تسهيل الأتمتة على نطاق واسع لتحقيق إمكانية تكنولوجيا المعلومات بدون لمس أثناء ترحيل أعباء العمل إلى السحابة. تأتي المنصات أيضًا مع بنية أساسية جديرة بالثقة للحل 2.0 والتي تؤمنها ضد التهديدات ونقاط الضعف من خلال التحقق المتقدم من السلامة ومعالجة التهديدات. الحجم: 1RU مع فتحة واجهة الشبكة NIM واحدة ومنافذ WAN 4×1 جيجابيت إيثرنت الميزات الرئيسية: • المعالج: وحدة المعالجة المركزية Intel x86 متعددة النواة مع ذاكرة DRAM سعة 8 جيجابايت افتراضية • يجب استخدام وحدة معالجة مركزية Intel x86 مع ذاكرة افتراضية سعة 8 جيجابايت وأن يكون بها فلاش مدمج سعة 8 جيجابايت ويمكن ترقية التخزين إلى 16 جيجا و32 جيجا USB و600 جيجا. • تدعم المعالجات متعددة النواة عالية الأداء اتصالات WAN عالية السرعة • تعمل بنية التخصيص الأساسي الديناميكي على إعادة استخدام النوى غير المستخدمة في إعادة توجيه الكيانات وفقًا لتكوين المستخدم تسريع أجهزة IPsec VPN المضمنة: • تمكين ما يصل إلى 1 جيجابت في الثانية من حركة مرور IPsec • زيادة قابلية التوسع لمتطلبات إنتاجية IPsec • تسريع أجهزة SSL والتشفير منافذ جيجابت إيثرنت مدمجة • يوفر أربعة منافذ Ethernet WAN مدمجة • منفذا إيثرنت صغيران الحجم قابلان للتوصيل (SFP) ومنفذان RJ45، مما يتيح اتصال الألياف والنحاس • المدمج في تجزئة نهاية إلى نهاية (VPN)، ZBFW، PKI، وأمن طبقة الحمض النووي، SIG • دعم التحكم المركزي من خلال وحدة تحكم SD WAN. • يجب أن يحتوي الحل المقترح على ترخيص لدعم حركة مرور التشفير بسرعة 200 ميجا بت في الثانية على الأقل. مواصفات الأجهزة: الذاكرة DRAM: • 8 جيجا بايت رام • يمكن ترقيتها إلى 16 جيجابايت و32 جيجابايت من ذاكرة الوصول العشوائي الديناميكية (DRAM) للحصول على نطاق وأداء أعلى ذاكرة فلاش: • فلاش 8 جيجا تخزين M.2: • مساحة التخزين (M.2 SSD) الافتراضية: 16 جيجابايت • يمكن ترقيتها إلى سعة تخزين 32 جيجا بايت M.2 USB و600 جيجا بايت M.2 للذاكرة السريعة غير المتطايرة (NVMe) واجهة الشبكة: • يجب أن يكون لديك 4 منافذ Ethernet WAN مدمجة: o منفذا إيثرنت صغيران قابلان للتوصيل (SFP) ومنفذان RJ45، مما يتيح اتصال الألياف والنحاس. نمطية وعامل الشكل • 1-وحدة الرف (1RU) ذات عامل الشكل • يدعم فتحات NIM ووحدة الواجهة القابلة للتوصيل (PIM). مواصفات المنصة: • كثافة منفذ 1G = 4 فتحات: • 1 × نيم • 1 × بيم مزود الطاقة: • مصدر طاقة تيار متردد ثابت • الحد الأقصى لتصنيف الطاقة: 100 واط يجب دعم: أداء المنصة: • إنتاجية SD-WAN IPsec (1400 بايت): ما يصل إلى 1 جيجابت في الثانية • مقياس أنفاق تراكب SD-WAN: 2500 مواصفات أداء الوضع المستقل (غير SD-WAN). • إنتاجية إعادة توجيه IPv4 (1400 بايت): ما يصل إلى 3.8 جيجابت في الثانية • إنتاجية IPsec (1400 بايت): ما يصل إلى 1 جيجابت في الثانية • عدد أنفاق واجهة النفق الافتراضية الثابتة IPsec (SVTI): 2500 • الوضع المستقل (غير SD-WAN) قابلية التوسع في النظام • عدد قوائم التحكم بالوصول (ACLs) لكل نظام: 4000 • عدد إدخالات التحكم في الوصول إلى IPv4 (ACEs) لكل نظام: 72,000 • عدد مسارات IPv4: 1.6 مليون بسعة افتراضية 8 جيجابايت، وما يصل إلى 4 ميجا مع 32 جيجابايت • عدد مسارات IPv6: 1.5 مليون بسعة افتراضية 8 جيجابايت، وما يصل إلى 4 ميجا مع 32 جيجابايت • عدد قوائم الانتظار: 16,000 • عدد جلسات ترجمة عنوان الشبكة (NAT): 1.2 مليون مع السعة الافتراضية 8 جيجابايت، وحتى 2 مليون مع السعة 32 جيجابايت • عدد جلسات جدار الحماية: 512,000 • عدد حالات إعادة توجيه التوجيه الافتراضي (VRF): 4000 • دعم وحدة واجهة شبكة واحدة للمستقبل. • يمكن لجهاز التوجيه دعم منافذ الصوت FXO عند الحاجة. • يمكن لجهاز التوجيه أن يدعم ميزة SRST ويمكنه تكوينها كنسخة احتياطية لمدير مكالمات IP Telephony الموجود. • دعم وحدة Cat 18 لشبكات LTE و5G المتقدمة الجاهزة للمستقبل. • يجب أن يكون لديك علامة RFID ومضمنة تحمل الرقم التسلسلي ومعرف المنتج لسهولة إدارة الأصول والمخزون باستخدام أجهزة قراءة RFID التجارية. • دعم التوجيه الديناميكي: OSPF، EIGRP، BGP مع الوظائف التي تدعمها ميزة وحدة التحكم. • اتصال IPSec مع AES-256 بت • دعم تكرار بوابة VRRP وHSRP • دعم تصحيح الأخطاء إلى الأمام (FEC) على حد سواء تكافؤ الحزمة وازدواجية الحزمة ودعم NAT • دعم وظيفة البث المتعدد Auto-RP أو Static RP وIGMPv1 وIGMPv2 • دعم TACAC+ Radius للمصادقة على الجهاز • دعم التغليف 802.1Q • دعم وظائف جودة الخدمة. التحكم في التطبيق، والتشكيل، والمراقبة، ووضع علامات على DSCP، وإعادة الكتابة باستخدام قوائم انتظار تبلغ 16 ألفًا. • دعم MACSEC وSYBCE على كافة المنافذ • جلسة جدار الحماية تصل إلى 512 كيلو بايت • عدد جلسات ترجمة عنوان الشبكة (NAT) المدعومة يصل إلى 1.2 مليون مع ذاكرة وصول عشوائي افتراضية تبلغ سعتها 8 جيجابايت رخصة: • التوصيل والتشغيل للتوصيل لنشر الجهاز بدون لمس • وكيل TE لـ iOSXE على توجيه المؤسسات • رخصة الامتثال لقيود التصدير الأمريكية • DNA Essentials On-Prem Lic 3Y - حتى 200 متر (Aggr، 400 متر) • وضع التشغيل الذاتي لنظام IOS XE للصورة الموحدة الدعم الفني: 3 سنوات من الشركة المصنعة. في يوم العمل التالي، استبدال الأجهزة مسبقًا 8x5x4. Edge Platforms are 5G-ready cloud edge platforms designed for Secure Access Service Edge (SASE), multilayer security, and cloud-native agility to accelerate business journey to cloud. The platforms are purpose-built for performance and integrated SD-WAN services along with flexibility to deliver security and networking services together from the cloud or on premises. Edge Platforms should wide variety of interface options to choose from, with backward compatibility to existing WAN, LAN, and voice modules. Powered by IOS XE, a fully programmable software architecture, and API support, facilitate automation at scale to achieve zero-touch IT capability while migrating workloads to the cloud. The platforms also come with a trustworthy solution 2.0 infrastructure that secures them against threats and vulnerabilities through advanced integrity verification and remediation of threats. 1RU w/ 1 NIM slot and 4x1 Gigabit Ethernet WAN ports Product Key Features: • Processor: Multicore Intel x86 CPU with 8 GB DRAM memory default • Must use and Intel x86 CPU with 8 GB memory default and have an integrated onboard 8-GB flash and not are upgradeable. Storage can be upgraded to 16G,32G USB and 600G. • High-performance multicore processors support high-speed WAN connections • Dynamic core allocation architecture will repurpose unused cores into forwarding entities as per the user’s configuration Embedded IPsec VPN hardware acceleration: • Enables up to 1 Gbps IPsec traffic • Increases scalability for IPsec throughput requirements • SSL and crypto hardware acceleration Integrated Gigabit Ethernet ports • Provides four built-in Ethernet WAN ports • Two Ethernet ports are Small Form-Factor Pluggable (SFP) and two are RJ45 ports, enabling fiber as well as copper connectivity • Built-in end to end segmentation (VPNs), ZBFW,PKI, DNA layer security, SIG • Support Centralized control through the SD WAN controller. • The proposed solution should contain the license for supporting at least 200Mbps Crypto traffic. Hardware Specification: Memory (DRAM): • 8 GB DRAM • Can be upgraded to 16 GB and 32 GB DRAM for higher scale and performance Flash memory: • 8-GB flash M.2 storage: • Storage (M.2 SSD) default: 16 GB • Can be upgraded to 32G M.2 USB and 600G M.2 Non-Volatile Memory Express (NVMe) Storage Network Interface: • Must have 4 built in Ethernet WAN ports: o Two Ethernet ports are Small From Factor Pluggable (SFP) and two are RJ45 ports, enabling fiber as well as copper connectivity. Modularity and form factor • 1-Rack Unit (1RU) form factor • Supports NIM and Pluggable Interface Module (PIM) slots Platform Specifications: • 1G port density = 4 Slots: • 1 X NIM • 1 X PIM Power supply: • Fixed AC power supply • Power maximum rating:100W Must Support: Platform performance: • SD-WAN IPsec throughput (1400 bytes): Up to 1 Gbps • SD-WAN overlay tunnels scale: 2500 Autonomous mode (non SD-WAN) performance specifications • IPv4 forwarding throughput (1400 bytes): Up to 3.8 Gbps • IPsec throughput (1400 bytes): Up to 1 Gbps • Number of IPsec Static Virtual Tunnel Interface (SVTI) tunnels: 2500 • Autonomous mode (non SD-WAN) system scalability • Number of Access Control Lists (ACLs) per system: 4000 • Number of IPv4 Access Control Entries (ACEs) per system: 72,000 • Number of IPv4 routes: 1.6M with default 8 GB, up to 4M with 32 GB • Number of IPv6 routes: 1.5M with default 8 GB, up to 4M with 32 GB • Number of queues: 16,000 • Number of Network Address Translation (NAT) sessions: 1.2M with default 8 GB, up to 2M with 32 GB • Number of firewall sessions: 512,000 • Number of Virtual Route Forwarding (VRF) instances: 4000 • Support one network interface module for future. • The router can support voice ports FXO whenever needed. • The router can support SRST feature and can configure it as a backup for the existing IP Telephony call manager. • Support Cat 18 Module for advanced LTE and 5G ready for future. • Must have and embedded RFID tag that holds the serial number and product ID for easy asset and inventory management using commercial RFID readers. • Support Dynamic routing: OSPF, EIGRP, BGP with the functionality that the controller feature support. • IPSec Connection with AES-256 bit • Support VRRP & HSRP Gateway Redundancy • Support forward error correction (FEC) both packet parity and packet duplication and support NAT • Support Multicast functionality Auto-RP or Static RP and IGMPv1 and IGMPv2 • Support TACAC+ Radius for authentication to the device • Support 802.1Q Encapsulation • QoS functionality support. Application Control, Shaping, and policing, DSCP Marking, Rewrite with 16K queues. • Support MACSEC and SYBCE on all the ports • Firewall session up to 512k • Number of Network Address Translation(NAT) sessions supported is up to 1.2M with default 8 GB RAM License: • Plug-n-Play Connect for zero-touch device deployment • TE agent for IOSXE on Enterprise Routing • U.S. Export Restriction Compliance license • DNA Essentials On-Prem Lic 3Y - upto 200M (Aggr, 400M) • IOS XE Autonomous boot up mode for Unified image Technical support: 3 years from manufacturer. Next Business Day, 8x5x4 advance hardware replacement. يجب أن يتم ترميز الجهاز وذلك بوضع ملصق (Labeling) يوضح مسمى الشبكة. عدد 6 0
رقم7 2 توريد وتركيب وتهيئة جهاز موزع شبكة رئيسي توريد وتركيب وتهيئة جهاز موزع شبكة رئيسي (Aggregation Switch) شاملاً جميع التوصيلات اللازمة لتشغيله بالمواصفات الفنية التالية: • 16-port 1/10 Gigabit Ethernet and must Include 8 X 10G Ports uplink module • Service contract should be included to cover for 3 years by the vendor with Advantage license for 3 years • Dual Power supplies • Must include the uplink module with 8 X 10G Ports • Must has DRAM and FLASH of 16GB • Support switching capacity Up to Up to 480 Gbps • Support Forwarding Rate Up to 360 Mpps • Total number of MAC addresses that can be supported is Up to 64,000 • Total number of IPv4 routes (ARP plus learned routes) that can be supported is Up to 64,000 indirect + direct Up to 40,000 host/ARP • Support Multicast scale up to 32,000 • Total number of IPv6 routes that can be supported is Up to 32,000 indirect and Up to 40,000 host • Comes with redundant power supplies each with minimum of 950W AC • Must include Advantage licenses for supporting virtual stacking • Support SDN without the need to replace the hardware • Support for AES-256 with the powerful MACsec 256-bit encryption algorithm • Switch chassis embedded Intel x86 architecture with up to 120GB of USB 3.0 SSD • storage for container-based application hosting • Platinum-rated AC power supplies • Can Support up to 512,000 Flexible NetFlow (FNF) entries in hardware • IPv6 support in hardware, providing wire-rate forwarding for IPv6 networks • Dual-stack support for IPv4/IPv6 and dynamic hardware forwarding table allocations, for ease of IPv4-to-IPv6 migration • Support for both static and dynamic NAT and Port Address Translation (PAT) • Switch have embedded RFID tag which facilitates easy asset/inventory management using commercial RFID readers • Open IOS-XE, a modern operating system for the enterprise with support for model-driven programmability, on-box Python scripting, streaming telemetry, container-based application hosting, and patching for critical bug fixes. The OS also has built-in defenses to protect against runtime attacks • Stack-Wise virtual technology, a network system virtualization technology that increases operational efficiency and boosts nonstop communications and scaled system bandwidth • Support Product Security Incident Response Team (PSIRT) compliance; end of life/end of sale reporting; telemetry quotient; Client 360; Device 360; top talkers/application reporting; syslog, Simple Network Management Protocol (SNMP), NetFlow, streaming telemetry collection and correlation • Support the below Switch fundamentals including: • STP, Trunking, Private VLAN (PVLAN), Q-in-Q, IPv6, OSPF, RIP, Policy-Based Routing (PBR), Virtual Router Redundancy Protocol (VRRP), Internet Group Management Protocol (IGMP), PIM Stub, Weighted Random Early Detection (WRED), UPOE, First Hop Security (FHS), 802.1X, MACsec-128, Control Plane Policing (CoPP), SSO • Support Advanced switch capabilities and scale: • BGP, EIGRP, Hot Standby Router Protocol (HSRP), IS-IS, Bootstrap Router (BSR), Multicast Source Discovery Protocol (MSDP), Class-Based Weighted Fair Queuing (CBWFQ), MACsec-256 • Support Advanced telemetry and visibility including: • Flexible Net-Flow, MPLS, Multicast, CoPP, shared Net-Flow policers, Net-Flow with EEM, Wire-shark • Switch shall support Context-based analytics • Switch shall support Application Visibility and Control capability for both wired and wireless client • Switch shall support automated, dynamic QoS assignment per Application using Group Policy that is easily configurable via SDN Controller • Switch shall support MPLS for network segmentation • Switch shall support push-based, streaming telemetry to send operational data to an external collector • Switch shall be enabled NETCONF/YANG data model to allow programmability • Vendor shall follow the Secure Development Lifecycle that is published and verifiable • Vendor shall provide public references that how their Switch HW or SW has not modified before or during boot up • Software shall be digitally signed • Runtime prevention in the product with forward roadmap to runtime detection • PSIRT function that is active in the community • Switch shall offer autonomic network infrastructure that provides secure, zero-touch device enrollment and virtual out-of-band channel using secure tunnel • Switch shall support Application Hosting feature which allows third-party off-the-shelf applications built using Linux tool chains to run on Switch platforms. Application are hosted in a Linux containers for maximum flexibility on distribution environments and isolation from the main operating system. • Switch Vendor shall support On-box Python and Python scripts are able to take advantage of direct connection to the device. • Switch OS shall support modular Hot patch of software during operation without reboot entire switch • Switch OS shall support comprehensive node isolation framework that allows no or minimal traffic loss. • Warranty: 3 Years warranty from manufacturer. Next-business-day, 8x5xNBD يجب أن يتم ترميز جميع الأجهزة وذلك بوضع ملصق (Labeling) يوضح مسمى الشبكة. عدد 7 0
رقم8 8 توريد وتركيب وتهيئة جهاز موزع شبكة طرفي توريد وتركيب جهاز موزع شبكة طرفي Edge Switches سعة 24 منفذ وعمل التهيئة اللازمة شاملاً جميع التوصيلات اللازمة لتشغيله بالمواصفات الفنية التالية: Supply installation, configuration and testing of 24 ports 1 Gigabit switches that can provide security features that protect the integrity of the hardware as well as the software and all data that flows through the switch. That provides resiliency which keeps business up and running seamlessly. Combine that with open APIs of IOS XE and programmability of the UADP ASIC technology, with full PoE+ capability, power and fan redundancy, stacking bandwidth up to 80 Gbps, modular uplinks, Layer 3 feature support, and cold patching. • 24 x 1G ports full Power over Ethernet Plus (PoE+) capability • Uplink: 4 x 1G fixed uplinks • Supporting stacking bandwidth up to 80 Gbps • UADP 2.0 Mini with integrated CPU • Enhanced security with AES-128 MACsec encryption • Policy-based segmentation, and trustworthy systems • Advanced network monitoring using Full Flexible NetFlow • Software-Defined Access (SD-Access) o Simplified operations and deployment with policy-based automation from edge to cloud managed with Identity Services Engine (ISE) o Network assurance and improved resolution time through DNA Center • Plug and Play (PnP) enabled: A simple, secure, unified, and integrated offering to ease new branch or campus device rollouts or updates to an existing network Performance specifications • Virtual Networks :1 • Stacking bandwidth: 80 Gbps • Total number of MAC addresses: 16,000 • Total number of IPv4 routes (ARP plus learned routes): 11,000 (8,000 direct routes and 3,000 indirect routes) • IPv4 routing entries: 3,000 • IPv6 routing entries: 1,500 • Multicast routing scale: 1,000 • QoS scale entries: 1,000 • ACL scale entries: 1,500 • Packet buffer per SKU: 6 MB buffers • Flexible NetFlow (FNF) entries: 16,000 flows Hardware: • DRAM: 2 GB • Flash: 4 GB • VLAN IDs: 1024 • Total Switched Virtual Interfaces (SVIs): 512 • Jumbo frames: 9198 bytes • IP SGT binding scale: 10K • Number of IPv4 bindings: 10 K • Number of SGT/DGT policies: 2K • Number of SXP Sessions 200 Bandwidth specifications: • Switching capacity: 56 Gbps • Switching capacity with stacking: 136 Gbps • Forwarding rate: 41.66 Mpps • Forwarding rate with stacking: 101 Mpps License: 3 years subscription DNA Essential. Warranty: 3 Years warranty from manufacturer. Next-business-day,8x5x4 advance hardware replacement. يجب أن يتم ترميز جميع الأجهزة وذلك بوضع ملصق (Labeling) يوضح مسمى الشبكة. عدد 8 0
رقم9 1 توريد وتركيب جهاز جدار ناري توريد وتركيب جهاز جدار ناري وعمل التهيئة اللازمة شاملاً جميع التوصيلات اللازمة لتشغيله بالمواصفات التالية: تضمين التعلم الآلي (ML) في قلب جدار الحماية لتوفير منع أقل للهجمات المضمنة بالتوقيع للهجمات المستندة إلى الملفات مع تحديد محاولات التصيد الاحتيالي التي لم يسبق لها مثيل وإيقافها على الفور. • يوفر الأمان في شكل عامل سطح المكتب • يدعم التوفر العالي مع الأوضاع النشطة/النشطة والنشطة/السلبية • يسلم أداء يمكن التنبؤ به مع خدمات الأمن • تبسيط نشر أعداد كبيرة من جدران الحماية من خلال خدمة Zero Touch Provisioning (ZTP) الاختيارية • يدعم الإدارة المركزية مع إدارة أمن شبكة بانوراما ميزات الأمان والاتصال الرئيسية: جدار الحماية من الجيل التالي الذي يعمل بنظام ML الاستفادة من عمليات التعلم الآلي المستندة إلى السحابة لدفع التوقيعات والتعليمات بدون تأخير إلى NGFW. • يستخدم التحليل السلوكي لاكتشاف أجهزة إنترنت الأشياء (IoT) وتقديم توصيات السياسة. خدمة مقدمة عبر السحابة ومتكاملة أصلاً على NGFW. • أتمتة توصيات السياسة التي توفر الوقت وتقلل من فرص الخطأ البشري. يحدد ويصنف جميع التطبيقات، على جميع المنافذ، طوال الوقت، مع فحص كامل من الطبقة السابعة • يحدد التطبيقات التي تعبر شبكتك بغض النظر عن المنفذ أو البروتوكول أو تقنيات المراوغة أو التشفير (TLS/SSL). • اكتشاف التطبيقات الجديدة والتحكم فيها تلقائيًا لمواكبة انفجار SaaS من خلال اشتراك SaaS Security. • يستخدم التطبيق، وليس المنفذ، كأساس لجميع قرارات سياسة التمكين الآمنة: السماح، والرفض، والجدولة، والفحص، وتطبيق تشكيل حركة المرور. • القدرة على إنشاء علامات معرف التطبيق المخصصة لتطبيقات الملكية أو طلب تطوير معرف التطبيق للتطبيقات الجديدة من شبكات تصنيع الأجهزة المقترحة. • يحدد جميع بيانات الحمولة داخل التطبيق (مثل الملفات وأنماط البيانات) لحظر الملفات الضارة وإحباط محاولات تسريب البيانات. • إنشاء تقارير استخدام التطبيقات القياسية والمخصصة، بما في ذلك تقارير البرامج كخدمة (SaaS) التي توفر نظرة ثاقبة لجميع حركة SaaS المحظورة وغير المصرح بها على شبكتك. • تمكين الترحيل الآمن لمجموعات قواعد الطبقة الرابعة القديمة إلى القواعد المستندة إلى معرف التطبيق باستخدام مُحسِّن السياسة المدمج، مما يوفر لك مجموعة قواعد أكثر أمانًا وأسهل في الإدارة. يفرض الأمان للمستخدمين في أي مكان وعلى أي جهاز أثناء التكيف • تمكين الرؤية وسياسات الأمان وإعداد التقارير والتحليلات الجنائية استنادًا إلى المستخدمين والمجموعات، وليس فقط عناوين IP. • يتكامل بسهولة مع مجموعة واسعة من المستودعات للاستفادة من معلومات المستخدم: وحدات تحكم الشبكة المحلية اللاسلكية، وشبكات VPN، وخوادم الدليل، وSIEMs، والوكلاء، والمزيد. • يتيح لك تحديد مجموعات المستخدمين الديناميكية (DUGs) على جدار الحماية لاتخاذ إجراءات أمنية محددة زمنيًا دون انتظار تطبيق التغييرات على أدلة المستخدم. • تطبيق سياسات متسقة بغض النظر عن مواقع المستخدمين (المكتب والمنزل والسفر وما إلى ذلك) والأجهزة (الأجهزة المحمولة التي تعمل بنظامي التشغيل iOS وAndroid؛ وأجهزة الكمبيوتر المكتبية والمحمولة التي تعمل بنظام التشغيل macOS وWindows وLinux؛ وCitrix وMicrosoft VDI؛ والخوادم الطرفية) • يمنع تسرب بيانات اعتماد الشركة إلى مواقع ويب تابعة لجهات خارجية ويمنع إعادة استخدام بيانات الاعتماد المسروقة من خلال تمكين المصادقة متعددة العوامل (MFA) في طبقة الشبكة لأي تطبيق دون أي تغييرات في التطبيق. • يوفر إجراءات أمنية ديناميكية تعتمد على سلوك المستخدم لتقييد المستخدمين المشبوهين أو الضارين. • يقوم باستمرار بمصادقة المستخدمين وتفويضهم، بغض النظر عن الموقع والمكان الذي توجد فيه مخازن هوية المستخدم، للتحرك بسرعة نحو وضع أمان الثقة المعدومة باستخدام Cloud Identity Engine، وهي بنية جديدة تمامًا قائمة على السحابة للأمان المستند إلى الهوية. يمنع النشاط الضار المخفي في حركة المرور المشفرة • فحص وتطبيق السياسة على حركة المرور المشفرة بـ TLS/SSL، سواء الواردة أو الصادرة، بما في ذلك حركة المرور التي تستخدم TLS 1.3 وHTTP/2. • يوفر رؤية ثرية لحركة مرور TLS، مثل مقدار حركة المرور المشفرة، وإصدارات TLS/SSL، ومجموعات التشفير، والمزيد، دون فك التشفير • تمكين التحكم في استخدام بروتوكولات TLS القديمة، والشفرات غير الآمنة، والشهادات التي تم تكوينها بشكل خاطئ للتخفيف من المخاطر. • يسهل النشر السهل لفك التشفير ويتيح لك استخدام السجلات المضمنة لاستكشاف المشكلات وإصلاحها، مثل التطبيقات ذات الشهادات المثبتة. • تمكين أو تعطيل فك التشفير بمرونة استنادًا إلى فئة عنوان URL ومنطقة المصدر والوجهة والعنوان والمستخدم ومجموعة المستخدمين والجهاز والمنفذ، لأغراض الخصوصية والامتثال التنظيمي. • يسمح بإنشاء نسخة من حركة المرور التي تم فك تشفيرها من جدار الحماية (أي النسخ المتطابق لفك التشفير) وإرسالها إلى أدوات جمع حركة المرور لأغراض الطب الشرعي، أو الأغراض التاريخية، أو منع فقدان البيانات (DLP). • يسمح بإعادة توجيه كل حركة المرور بذكاء (TLS غير المشفرة، TLS غير المشفرة، وغير TLS) إلى أدوات أمان تابعة لجهات خارجية باستخدام وسيط حزم الشبكة وتحسين أداء شبكتك وتقليل نفقات التشغيل الإدارة المركزية والرؤية • الإدارة المركزية والتكوين والرؤية لشبكات NGFWs المصنعة للأجهزة الموزعة المتعددة (بغض النظر عن الموقع أو النطاق) من خلال إدارة أمان شبكة Panorama، في واجهة مستخدم واحدة موحدة. • تبسيط مشاركة التكوين من خلال البانوراما مع القوالب ومجموعات الأجهزة، وقياس جمع السجلات مع زيادة احتياجات التسجيل. • تمكن المستخدمين، من خلال مركز قيادة التطبيقات (ACC)، من الحصول على رؤية عميقة ورؤى شاملة حول حركة مرور الشبكة والتهديدات. يقدم إدارة وعمليات موحدة مدعومة بالذكاء الاصطناعي مع Strata Cloud Manager • منع انقطاع الشبكة: توقع سلامة النشر وحدد بشكل استباقي اختناقات القدرات لمدة تصل إلى سبعة أيام مقدمًا باستخدام التحليلات التنبؤية لمنع الاضطرابات التشغيلية بشكل استباقي. • تعزيز الأمان في الوقت الفعلي: تحليل السياسات المدعوم بالذكاء الاصطناعي وعمليات التحقق من الامتثال في الوقت الفعلي مقابل أفضل ممارسات شبكات الصناعة. • تمكين إدارة وعمليات أمان الشبكة البسيطة والمتسقة: إدارة سياسات التكوين والأمان عبر جميع عوامل الشكل، بما في ذلك SASE وجدران الحماية للأجهزة والبرامج وجميع خدمات الأمان لضمان الاتساق وتقليل الحمل التشغيلي. يكتشف التهديدات المتقدمة ويمنعها باستخدام خدمات الأمان المقدمة عبر السحابة • الوقاية المتقدمة من التهديدات: إيقاف عمليات الاستغلال المعروفة وغير المعروفة وهجمات القيادة والتحكم (C2) من خلال عمليات اكتشاف مضمنة مدعومة بالذكاء الاصطناعي، وإيقاف هجمات الحقن الفوري بنسبة 60% وحركة مرور الأوامر والتحكم الأكثر مراوغة بنسبة 48% مقارنة بالطرق التقليدية حلول IPS. • Advanced Wildfire: تأكد من أن الملفات آمنة عن طريق منع البرامج الضارة المعروفة وغير المعروفة والمراوغة للغاية بشكل أسرع بمعدل 180 مرة من المنافسين باستخدام أكبر محرك لمعلومات التهديدات والوقاية من البرامج الضارة في الصناعة. • تصفية متقدمة لعناوين URL: ضمان الوصول الآمن إلى الإنترنت ومنع المزيد من الهجمات المستندة إلى الويب بنسبة 40% من خلال أول منع فوري للتهديدات المعروفة وغير المعروفة في الصناعة، مما يؤدي إلى إيقاف 88% من المواقع الضارة قبل 48 ساعة على الأقل من البائعين الآخرين. • أمان DNS: احصل على تغطية أكبر للتهديدات بنسبة 68% وأوقف 85% من البرامج الضارة التي تسيء استخدام DNS لأغراض القيادة والتحكم وسرقة البيانات دون الحاجة إلى إجراء تغييرات على البنية الأساسية لديك. • ميزة منع فقدان البيانات (DLP) للمؤسسات: تقليل مخاطر اختراق البيانات، وإيقاف عمليات نقل البيانات خارج نطاق السياسة، وتمكين الامتثال بشكل متسق عبر مؤسستك، مع تغطية أكبر مضاعفة لأي ميزة منع فقدان البيانات (DLP) مؤسسية يتم تسليمها عبر السحابة. • أمان SaaS: ابق في صدارة تطور SaaS مع الجيل التالي الوحيد من CASB في الصناعة الذي يمكنه رؤية جميع التطبيقات وتأمينها تلقائيًا عبر جميع البروتوكولات. • أمان إنترنت الأشياء: يمكنك حماية كل "شيء" وتنفيذ أمان الجهاز Zero Trust بشكل أسرع 20 مرة، مع الأمان الأكثر ذكاءً في الصناعة للأجهزة الذكية. يقدم أسلوبًا فريدًا لمعالجة الحزم باستخدام بنية المرور الفردي • تنفيذ الشبكات والبحث عن السياسات والتطبيقات وفك التشفير ومطابقة التوقيع - لجميع التهديدات والمحتوى - في مسار واحد. وهذا يقلل بشكل كبير من مقدار عبء المعالجة المطلوب لأداء وظائف متعددة في جهاز أمان واحد. • يتجنب إدخال زمن الوصول عن طريق مسح حركة المرور لجميع التوقيعات في مسار واحد، وذلك باستخدام مطابقة التوقيع الموحدة القائمة على الدفق. • تمكين الأداء المتسق والمتوقع عند تمكين الاشتراكات الأمنية. (في الجدول 1، يتم قياس "إنتاجية منع التهديدات" مع تمكين الاشتراكات المتعددة.) تمكين وظيفة SD-WAN • يتيح لك استخدام شبكة SD-WAN بسهولة بمجرد تمكينها على جدران الحماية الموجودة لديك. • يمكّنك من تنفيذ شبكة SD-WAN بأمان، والتي تم دمجها أصلاً مع حلول الأمان الرائدة في الصناعة لدينا. • يوفر تجربة استثنائية للمستخدم النهائي من خلال تقليل زمن الوصول والارتعاش وفقدان الحزمة. أوضاع الواجهة: • L2، L3، اضغط، السلك الافتراضي (الوضع الشفاف) التوجيه: • OSPFv2/v3 مع إعادة تشغيل سلسة، BGP مع إعادة تشغيل سلسة، RIP، توجيه ثابت • إعادة التوجيه على أساس السياسة • بروتوكول نقطة إلى نقطة عبر الإيثرنت (PPPoE) • البث المتعدد: PIM-SM، PIM-SSM، IGMP v1، v2، وv3 شبكة SD-WAN • قياس جودة المسار (الارتعاش، فقدان الحزمة، زمن الوصول) • اختيار المسار الأولي (PBF) • تغيير المسار الديناميكي IPv6: • L2، L3، اضغط، السلك الافتراضي (الوضع الشفاف) • الميزات: معرف التطبيق، ومعرف المستخدم، ومعرف المحتوى، وWildfire، وSSL Decryption SLAAC إيبسيك VPN • تبادل المفاتيح: المفتاح اليدوي، وIKEv1، وIKEv2 (المفتاح المشترك مسبقًا، والمصادقة المستندة إلى الشهادة) • التشفير: 3DES، AES (128 بت، 192 بت، 256 بت) • المصادقة: MD5، SHA-1، SHA-256، SHA-384، SHA-512 شبكات محلية ظاهرية • علامات 802.1Q VLAN لكل جهاز/لكل واجهة: 4,094/4,094 • الواجهات المجمعة (802.3ad)، LACP يجب أن يأتي جدار الحماية المقترح مع: مواصفات الأجهزة قدرات الأداء: • سرعة نقل جدار الحماية (HTTP/appmix) 3.6 جيجابت في الثانية • إنتاجية منع التهديدات (HTTP)/appmix) 2.3 جيجابت في الثانية • إنتاجية IPsec VPN: 1.8 جيجابت في الثانية • الحد الأقصى للجلسات: 300.000 جلسة • جلسات جديدة في الثانية: 56,000 • النظام الافتراضي (الأساسي/الأقصى) 1\5 واجهات إدخال/إخراج البيانات: • 2 × 1G SFP/RJ45 التحرير والسرد • 2 × جي RJ45 • 4 × 1 جيجا RJ45/PoE واجهات الإدخال/الإخراج للإدارة • منفذ إدارة 10/100/1000 خارج النطاق (1) • منفذ وحدة التحكم RJ45 (1) • منفذ USB (2) • منفذ وحدة تحكم USB صغير (1) الطاقة عبر الإيثرنت (PoE) • إجمالي ميزانية PoE: 91 وات • الحد الأقصى للتحميل على منفذ واحد: 60 وات سعة التخزين: • 128 جيجابايت eMMC أمان • cTUVus، CB إيمي • لجنة الاتصالات الفيدرالية (FCC) من الفئة B، وCE من الفئة B، وVCCI من الفئة B درجة حرارة التشغيل: 32 درجة فهرنهايت إلى 104 درجة فهرنهايت، من 0 درجة مئوية إلى 40 درجة مئوية درجة الحرارة أثناء عدم التشغيل: -4 درجة فهرنهايت إلى 158 درجة فهرنهايت، -20 درجة مئوية إلى 70 درجة مئوية التبريد السلبي محول الطاقة: • 1 × 50/60W محول التيار المتردد علبة الرف: • 1 × صينية قابلة للتركيب على حامل لما يصل إلى جداري حماية و4 محولات طاقة للتركيب على 4 رفوف ملحوظة: قم بتضمين أجهزة الإرسال والاستقبال حسب تصميم الشبكة. يدعم: • دعم متميز لمدة 3 سنوات The Tenderer to propose, supply, deliver, install, test, commission and maintain (Next Generation Firewalls with advanced threat prevention capabilities. • The proposed solution should ML-Powered NGFW • Embeds machine learning (ML) in the core of the firewall to provide inline signature less attack prevention for file-based attacks while identifying and immediately stopping never-before-seen phishing attempts. • Offers security in a desktop form factor • Supports high availability with active/active and active/passive modes • Delivers predictable performance with security services • Simplifies deployment of large numbers of firewalls with optional Zero Touch Provisioning(ZTP) • Supports centralized administration with Panorama network security management Key Security and Connectivity Features: ML-Powered Next-Generation Firewall • Embeds machine learning (ML) in the core of the firewall to provide inline signature less attack prevention for file-based attacks while identifying and immediately stopping never-before-seen phishing attempts. • Leverages cloud-based ML processes to push zero-delay signatures and instructions back to the NGFW. • Uses behavioral analysis to detect Internet of Things (IoT) devices and make policy recommendations; cloud-delivered and natively integrated service on the NGFW. • Automates policy recommendations that save time and reduce the chance of human error. Identifies and Categorizes All Applications, on All Ports, All the Time, with Full Layer 7 Inspection • Identifies the applications traversing your network irrespective of port, protocol, evasive techniques, or encryption (TLS/SSL). • Automatically discovers and controls new applications to keep pace with the SaaS explosion with SaaS Security subscription. • Uses the application, not the port, as the basis for all your safe enablement policy decisions: allow, deny, schedule, inspect, and apply traffic-shaping. • Ability to create custom App-ID tags for proprietary applications or request App-ID development for new applications from proposed device manufacture Networks. • Identifies all payload data within the application (e.g., files and data patterns) to block malicious files and thwart data exfiltration attempts. • Creates standard and customized application usage reports, including software-as-a-service (SaaS) reports that provide insight into all sanctioned and unsanctioned SaaS traffic on your network. • Enables safe migration of legacy Layer 4 rule sets to App-ID-based rules with built-in Policy Optimizer, giving you a rule set that is more secure and easier to manage. Enforces Security for Users at Any Location, on Any Device, While Adapting • Enables visibility, security policies, reporting, and forensics based on users and groups—not just IP addresses. • Easily integrates with a wide range of repositories to leverage user information: wireless LAN controllers, VPNs, directory servers, SIEMs, proxies, and more. • Allows you to define Dynamic User Groups (DUGs) on the firewall to take time-bound security actions without waiting for changes to be applied to user directories. • Applies consistent policies irrespective of users’ locations (office, home, travel, etc.) and devices (iOS and Android mobile devices; macOS, Windows, and Linux desktops and laptops; Citrix and Microsoft VDI; and terminal servers) • Prevents corporate credentials from leaking to third-party websites and prevents reuse of stolen credentials by enabling multifactor authentication (MFA) at the network layer for any application without any application changes. • Provides dynamic security actions based on user behavior to restrict suspicious or malicious users. • Consistently authenticates and authorizes your users, regardless of location and where user identity stores live, to move quickly toward a Zero Trust security posture with Cloud Identity Engine—an entirely new cloud-based architecture for identity-based security. Prevents Malicious Activity Concealed in Encrypted Traffic • Inspects and applies policy to TLS/SSL-encrypted traffic, both inbound and outbound, including for traffic that uses TLS 1.3 and HTTP/2. • Offers rich visibility into TLS traffic, such as amount of encrypted traffic, TLS/SSL versions, cipher suites, and more, without decrypting • Enables control over use of legacy TLS protocols, insecure ciphers, and misconfigured certificates to mitigate risks. • Facilitates easy deployment of decryption and lets you use built-in logs to troubleshoot issues, such as applications with pinned certificates. • Enable or disable decryption flexibly based on URL category and source and destination zone, address, user, user group, device, and port, for privacy and regulatory compliance purposes. • Allows to create a copy of decrypted traffic from the firewall (i.e., decryption mirroring) and send it to traffic collection tools for forensics, historical purposes, or data loss prevention (DLP). • Allows to intelligently forward all traffic (decrypted TLS, undecrypted TLS, and non-TLS) to third-party security tools with network packet broker and optimize your network performance and reduce operating expenses Centralized Management and Visibility • Ccentralized management, configuration, and visibility for multiple distributed proposed device manufacture Networks NGFWs (irrespective of location or scale) through Panorama network security management, in one unified user interface. • Streamlines configuration sharing through Panorama with templates and device groups, and scales log collection as logging needs increase. • Enables users, through the Application Command Center (ACC), to obtain deep visibility and comprehensive insights into network traffic and threats. Offers AI-Powered Unified Management and Operations with Strata Cloud Manager • Prevent network disruptions: Forecast deployment health and proactively identify capacity bottlenecks up to seven days in advance with predictive analytics to proactively prevent operational disruptions. • Strengthen security in real time: AI-powered analysis of policies and real-time compliance checks against industry Networks best practices. • Enable simple and consistent network security management and ops: Manage configuration and security policies across all form factors, including SASE, hardware and software firewalls, and all security services to ensure consistency and reduce operational overhead. Detects and Prevents Advanced Threats with Cloud-Delivered Security Services • Advanced Threat Prevention: Stop known and unknown exploits and command-and-control (C2) attacks with inline AI-powered detections, stopping 60% more zero-day injection attacks and 48% more highly evasive command-and-control traffic than traditional IPS solutions. • Advanced Wildfire: Ensure files are safe by automatically preventing known, unknown, and highly evasive malware 180X faster than competitors with the industry’s largest threat intelligence and malware prevention engine. • Advanced URL Filtering: Ensure safe access to the internet and prevent 40% more web-based attacks with the industry’s first real-time prevention of known and unknown threats, stopping 88% of malicious sites at least 48 hours before other vendors. • DNS Security: Gain 68% more threat coverage and stop 85% of malware that abuses DNS for command and control and data theft without requiring changes to your infrastructure. • Enterprise DLP: Minimize risk of a data breach, stop out-of-policy data transfers, and enable compliance consistently across your enterprise, with 2X greater coverage of any cloud-delivered enterprise DLP. • SaaS Security: Stay ahead of the SaaS explosion with the industry’s only Next-Generation CASB to automatically see and secure all apps across all protocols. • IoT Security: Safeguard every “thing” and implement Zero Trust device security 20X faster, with the industry’s smartest security for smart devices. Delivers a Unique Approach to Packet Processing with Single-Pass Architecture • Performs networking, policy lookup, application and decoding, and signature matching—for all threats and content—in a single pass. This significantly reduces the amount of processing overhead required to perform multiple functions in one security device. • Avoids introducing latency by scanning traffic for all signatures in a single pass, using stream-based, uniform signature matching. • Enables consistent and predictable performance when security subscriptions are enabled. (In table 1, “Threat Prevention throughput” is measured with multiple subscriptions enabled.) Enables SD-WAN Functionality • Allows you to easily adopt SD-WAN by simply enabling it on your existing firewalls. • Enables you to safely implement SD-WAN, which is natively integrated with our industry-leading security. • Delivers an exceptional end=user experience by minimizing latency, jitter, and packet loss. Interface Modes: • L2, L3, tap, virtual wire (transparent mode) Routing: • OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing • Policy-based forwarding • Point-to-Point Protocol over Ethernet (PPPoE) • Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 SD-WAN • Path quality measurement (jitter, packet loss, latency) • Initial path selection (PBF) • Dynamic path change IPv6: • L2, L3, tap, virtual wire (transparent mode) • Features: App-ID, User-ID, Content-ID, Wildfire, and SSL Decryption SLAAC IPsec VPN • Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) • Encryption: 3DES, AES (128-bit, 192-bit, 256-bit) • Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 VLANs • 802.1Q VLAN tags per device/per interface: 4,094/4,094 • Aggregate interfaces (802.3ad), LACP The proposed firewall shall come with: Hardware Specification Performance Capabilities: • Firewall throughput (HTTP/appmix) 3.6 Gbps • Threat Prevention throughput (HTTP)/appmix) 2.3 Gbps • IPsec VPN throughput:1.8 Gbps • Max sessions: 300,000 • New sessions per second: 56,000 • Virtual System (base/max) 1\5 Data I/O Interfaces: • 2 x 1G SFP/RJ45 combo • 2 x G RJ45 • 4 x 1G RJ45/PoE Management I/O Interfaces • 10/100/1000 out-of-band management port (1) • RJ45 console port (1) • USB port (2) • Micro USB console port (1) Power Over Ethernet (PoE) • Total PoE Budget: 91 W • Maximum loading on a single port: 60 W Storage Capacity: • 128 GB eMMC Safety • cTUVus, CB EMI • FCC Class B, CE Class B, VCCI Class B Operating temperature: 32°F to 104°F, 0°C to 40°C Non-operating temperature: -4°F to 158°F, -20°C to 70°C Passive cooling Power Adapter: • 1 x 50/60W AC Power Adapter Rack Tray: • 1 x Rack Mountable tray for Up to Two Firewalls and 4 power adapters for a 4 post rack mount Note: Include Transceivers as per network design. Support: • 3 Years premium support خدمات التركيب والتثبيت للجهاز والنظام والرخص المذكورة بالبند يجب أن تتم من قبل مختصين في الشركة المصنعة أو من قبل المختصين لدى المقاول المنفذ للمشروع الذين يملكون صلاحيات التركيب والبرمجة لهذه الأجهزة لمدة (10) أيام. يجب أن يتم ترميز الجهاز وذلك بوضع ملصق (Labeling) يوضح مسمى الشبك عدد 9 0
رقم10 1 توريد وتركيب جهاز تشفير توريد وتركيب جهاز تشفير وعمل التهيئة اللازمة شاملاً جميع التوصيلات اللازمة لتشغيله بالمواصفات التالية: يوفر جهاز التشفير المقترح حماية البيانات وتجزئة التطبيقات. تشفير الشبكة الواسعة • الإنتاجية المشفرة: ما يصل إلى 200 ميجابت في الثانية • قابلية التوسع بسلاسة • البنية التحتية محايدة • شفاف للشبكات والتطبيقات • توفير إنتاجية تشفير عالية دون التأثير على الأداء • قابلة للتشغيل المتبادل مع برنامج الإدارة الرئيسية، CryptoFlow Net Creator، حماية شاملة للبيانات • شبكات IPsec من موقع إلى آخر • شبكات MPLS المتداخلة • شبكات مترو إيثرنت وVPLS • الصوت والفيديو عبر تطبيقات IP • روابط الإنترنت وSDN أداء • ما يصل إلى 200 ميغابت في الثانية منصة • C2358 إنتل اتوم • 2.4 جيجا هرتز • 4 النواة الموانئ • 6 × 10/100/1000 - RJ45 • 2 × USB • 3 غير مستخدمة خوارزميات التشفير • AES-GCM-256 (شهادة AES رقم 5338**) • AES-CBC-256 (شهادة AES رقم 5338**) مصادقة الرسالة وخوارزميات النزاهة • HMAC-SHA2-256 (شهادة HMAC. رقم 3535**) • HMAC-SHA2-512 (شهادة HMAC. رقم 3535**) بيئية • درجة حرارة التشغيل: 32F إلى 104F / 0C إلى 40C • الرطوبة: من 5% إلى 85% (التشغيل) • الرطوبة: 5% إلى 95% (التخزين) قوة: • الإدخال: 100-240 فولت تيار متردد، 50-60 هرتز • الإخراج: غير متوفر • الطاقة: 84 واط • التبريد: نشط الضميمة • رف قابل للتركيب تنظيمية • م • بنفايات • ماي • الجزء 15 من لجنة الاتصالات الفيدرالية (FCC)، الجزء الفرعي ب، الفئة أ • FIPS 140-2، (الشهادة رقم 3347) • CC EAL4+ (ALC_FLR.3) واجهات نشطة • وحدة التحكم التسلسلية RJ-45 • جهاز التحكم عن بعد/المحلي/الإدارة 3 غير مستخدم المصادقة لكل إطار/حزمة: تم اعتماد FIPS والمعايير العامة عند استخدام برنامج الإصدار 5.3 يمكنك الاندماج بسهولة في أي شبكة موجودة، سواء كانت شبكات قديمة أو شبكات خارجية أو مواقع متعددة في مواقع مختلفة سهولة التركيب والإدارة: برنامج إدارة المفاتيح: يجب أن يكون سهل التثبيت وسهل الإدارة وقابلاً للتطوير ليناسب أي حجم للبنية الأساسية، مع أجهزة CEP مخصصة تشفير المجموعة الآمن والقابل للتطوير: يجب استخدام تشفير المجموعة القابل للتطوير لتوفير اتصال مشفر ومصادق عليه وزمن وصول منخفض ومن أي إلى أي اتصال. تشفير المجموعة يقلل من تعقيد النشر. فهو يوفر تشفيرًا شبكيًا بالكامل يسهل إدارته. يتوافق تشفير المجموعة مع تصميمات الشبكات المتاحة للغاية وأدوات مراقبة جودة الخدمة والشبكة. تشفير إطار Ethernet: يجب أن يكون متوافقًا مع طبولوجيا الطبقة الثانية للبث الأحادي والبث المتعدد ومن نقطة إلى نقطة ومن نقاط إلى عدة نقاط. يقوم CEP أيضًا بمصادقة جميع إطارات Ethernet، مما يمنع هجمات الرجل في الوسط. تشفير حزم IP: يجب توفير تشفير كامل للبيانات لشبكات IP من الطبقة الثالثة باستخدام تنسيق حزمة IPSEC القياسي مع الحفاظ على رأس IP الأصلي. تشفير الطبقة الرابعة لحماية حمولة حزمة IP مع الحفاظ على رأس IP الأصلي ورؤوس TCP/UDP الأصلية. تحافظ هذه القدرة الفريدة على شفافية الشبكة، مع توفير حماية قوية للبيانات. من خلال الحفاظ على الرأس الأصلي وتشفير الحمولة فقط، يتم حماية البيانات عبر أي شبكة IP. يتضمن ذلك أي شبكة متعددة الموجات، أو متوازنة التحميل، أو عالية التوفر، وتسمح بالحفاظ على خدمات الشبكة، مثل Netflow/Jflow، وتشكيل حركة المرور على أساس فئة الخدمة (CoS)، في جميع أنحاء الشبكة إدارة السياسة المركزية: يجب أن يكون نظام CryptoFlow Net Creator (CFNC) المقترح بمثابة نظام إدارة مفاتيح مركزي ينظم العمليات ويبسطها مع تزويدك بالتحكم الكامل في وضع الأمان الخاص بك. باستخدام واجهة المستخدم الرسومية سهلة الاستخدام وأداة السحب والإفلات، لديك القدرة لتحديد السياسات ونشرها بسهولة من نقطة تحكم مركزية واحدة. الشهادات: شهادة FIPS رقم 3411 وجهاز CEP تم التحقق من صحته وفقًا لمعايير FIPS 140-2 (الشهادة رقم 3347). كما تم إصدار شهادة Common Criteria لبرنامج CFNC v5.3 مع جهاز يعمل بالبرنامج الثابت CEP v5.3. يتوافق المنتج مع متطلبات معيار ISO/IEC 15408 (المعايير العامة) الإصدار 3.1 لمستوى الضمان: EAL4+ (ALC_FLR.3) الرخصة المطلوبة: • 3FSE-200M-SL3 برنامج CEP المنفذ وبرنامج تشفير السرعة الثابتة (FSE). • ترخيص لجهاز CEP-250-H-P واحد يتضمن ترخيص برنامج لجهاز CEP-250-H-P واحد وترخيص عرض النطاق الترددي يصل إلى 200 ميجابايت في الثانية (يعتمد على حجم الحزمة 512 أو أكبر). • يجب شراء الأجهزة بشكل منفصل، ويشمل الاشتراك رسوم صيانة البرامج البلاتينية خلال فترة الاشتراك والتي تغطي جميع صيانة البرامج وتحديثاتها بما في ذلك الدعم الفني عبر الهاتف على مدار 24 ساعة طوال أيام الأسبوع ودعم البريد الإلكتروني لمدة 3 سنوات. • الأجهزة الرف قابلة للتركيب. ملاحظة: قم بتضمين جميع المكونات اللازمة للاتصال بالشبكة. يدعم: • ضمان ودعم لمدة 3 سنوات. Proposed encryption appliance provides data protection and application segmentation. WAN Encryptor • Encrypted throughput: up to 200 Mbps • Seamless scalability • Infrastructure neutral • Transparent to network and applications • Provide high encryption throughput without impacting performance • Interoperable with key management software, CryptoFlow Net Creator, COMPREHENSIVE DATA PROTECTION • IPsec site-to-sitenetworks • MPLS meshed networks • Metro Ethernet and VPLS networks • Voice and video over IP applications • Internet and SDN links PERFORMANCE • Up to 200 Mbps PLATFORM • C2358 Intel ATOM • 2.4 GHz • 4-core PORTS • 6 x 10/100/1000 - RJ45 • 2 x USB • 3 unused ENCRYPTION ALGORITHMS • AES-GCM-256 (AES Cert. # 5338**) • AES-CBC-256 (AES Cert. # 5338**) MESSAGE AUTHENTICATION & INTEGRITY ALGORITHMS • HMAC-SHA2-256 (HMAC Cert. # 3535**) • HMAC-SHA2-512 (HMAC Cert. # 3535**) ENVIRONMENTAL • Operating Temperature: 32F to 104F / 0C to 40C • Humidity: 5% to 85% (operation) • Humidity: 5% to 95% (storage) POWER: • Input: 100-240VAC 50-60Hz • Output: NA • Power: 84W • Cooling: Active ENCLOSURE • Rack mountable REGULATORY • CE • RoHS • UL • FCC part 15 subpart B, class A • FIPS 140-2, (Cert. #3347) • CC EAL4+ (ALC_FLR.3) ACTIVE INTERFACES • RJ-45 Serial Console • Remote/Local/Management 3 unused Per-frame/packet authentication: FIPS and Common Criteria certified when utilizing version 5.3 software Integrate easily into any existing network, whether Legacy networks, 3rd party networks or multiple sites in different locations Easy installation and management: key management software: Should be easy to install, simple to manage and scalable for any size infrastructure, With dedicated CEP appliances Scalable and Secure Group Encryption: should use scalable group encryption to provide encrypted, authenticated, low- latency, any-to-any connectivity. Group encryption reduces deployment complexity. It provides fully meshed encryption that is easy to manage. Group encryption is compatible with highly available network designs and QoS and network monitoring tools. Ethernet Frame Encryption: Must be compatible with Layer 2 unicast, multicast, point-to-point, and multipoint-to-multipoint topologies. The CEP also authenticates all Ethernet frames, preventing man-in- the-middle attacks. IP Packet Encryption: must provide full data encryption for Layer 3 IP networks using standard IPSEC packet format while preserving the original IP header. Layer 4 encryption to protect the IP packet payload while preserving the original IP header and original TCP/UDP headers. This unique capability maintains network transparency, while providing strong data protection. By preserving the original header and encrypting only the payload, protects data over any IP network. This includes any multi-carrier, load-balanced, or high availability network, and allows network services, such as Netflow/Jflow, and Class of Service (CoS) based traffic shaping, to bemaintained throughout the network Central Policy Management: Proposed CryptoFlow Net Creator (CFNC) should centralized key management system that organizes and streamlines operations while providing you with full control of your security posture.With a user-friendly GUI and drag-and- drop tool, you have the ability to define and deploy policies with ease from one central point of control. Certifications: FIPS certificate #3411 and the CEP appliance is FIPS 140-2 validated (certificate #3347). Also, a Common Criteria certificate has been issued for CFNC v5.3 Software with device running CEP v5.3 Firmware. The product complies with the requirements of the standard ISO/IEC 15408 (Common Criteria) v. 3.1 for the assurance level: EAL4+ (ALC_FLR.3) الرخص المطلوبة: • 3FSE-200M-SL3 CEP enforcer software and fixed speed encryption (FSE) software • license for one CEP-250-H-P Appliance Includes a software license for one CEP-250-H-P appliance and a bandwidth license up to 200 MBPS (dependent upon packet size of 512 or larger). • Hardware must be purchased separately, Subscription includes Platinum software maintenance fee during the subscription period which covers all software maintenance and updates including technical phone support 24/7/365 and email support for 3 years • hardware rack mountable appliance. Note: Include all components needed to connect with network. Support: • 3 Years warranty and support. • رخصة برنامج إنفاذ التشفير السرعة الثابتة (FSE) • ترخيص لجهاز تشفير واحد يتضمن ترخيص برنامج لـلجهاز وترخيص عرض النطاق الترددي يصل إلى 200 ميجابايت في الثانية (يعتمد على حجم الحزمة 512 أو أكبر). • يجب شراء الأجهزة بشكل منفصل يشمل اشتراك البرنامج البلاتيني مع الصيانة الدورية خلال فترة الاشتراك والتي تغطي جميع صيانة البرامج والتحديثات بما في ذلك الدعم الفني عبر الهاتف ودعم البريد الإلكتروني لمدة 3 سنوات. • يجب أن يكون جهاز تشفير قابل للتركيب على رف حافظات الخوادم. خدمات التركيب والتثبيت لجميع الأجهزة والأنظمة والرخص المذكورة بالبند يجب أن تتم من قبل مختصين في الشركة المصنعة أو من قبل المختصين لدى المقاول المنفذ للمشروع الذين يملكون صلاحيات التركيب والبرمجة لهذه الأجهزة لمدة (10) أيام. يجب أن يتم ترميز الجهاز وذلك بوضع ملصق (Labeling) يوضح مسمى الشبكة. عدد 10 0
رقم11 16 توريد وتركيب موائمات الياف ضوئية توريد وتركيب موائمات ألياف ضوئية بالمواصفات الفنية التالية: 1G SFP-GLC-SX-SM 1000 Base عدد 11 0
رقم12 1 توريد وتركيب سنترال توريد وتركيب سنترال بسعة (8 خطوط خارجية/ 50 تحويلة داخلية (IP) / 4 تحويلة تماثلية) يحتوي على التالي: - كبينة رئيسية تحتوي على عدد (2) كرت كمبو سعة (12) موزعة (4خارجي/2تماثلي/6رقمي). - توريد وتركيب عدد (2) كرت (VCM) سعة (64) - توريد كرت (SD Cards) مع تنزيل كافة الرخص على نظام السنترال. - توريد وتركيب كيبل بور. - توريد وتركيب حامل حديدي. - توريد وبرمجة رخصة (IP end) عدد (50) رخصة. - توريد وبرمجة رخصة النظام والرد الالي (Preferred). - توريد وبرمجة رخصة (SIP Trunk) بسعة عدد (20) خطوط. توريد وبرمجة رخصة (Additional voice mail Pro 2Channel) بعدد (4) رخص لتشغيل (8) خطوط إضافية. عدد 12 0
رقم13 2 توريد وتركيب لوحة أزرار التوسعة KEM توريد وتركيب أزرار التوسعة KEM بالمواصفات التالية: أزرار توسعة سعة (24) زر Button Expansion module 24 وحدة التوسع على زيادة عدد مظهر المكالمات وأزرار الميزات على الهاتف. توفر وحدة التوسع 24 زرًا إضافيًا للمكالمات الواردة/الصادرة، وللميزات مثل الاتصال التلقائي، لطلب جهات الاتصال، أو لتطبيقات أخرى. المواصفات: شاشة ملونة بحجم 4.3 بوصة، بدقة 272 × 480 بكسل. يدعم هاتف ما يصل إلى 3 وحدات أزرار، ويمكن لكل وحدة أزرار أن تأخذ كلا من وضعي الرفع والتركيب على الحائط مع الهاتف. توفر وحدة التوسع الوصول إلى ما يصل إلى 24 زرًا ومصباحًا مع إمكانية عرض 3 صفحات عند استخدام وحدة توسيع واحدة. يحتوي كل زر ميزة/خط على مؤشر باللونين الأحمر والأخضر. تتوفر خلفيات أو شاشات توقف مُعدة مسبقًا لتتناسب مع الهاتف الأساسي. يتم توفير الطاقة من خلال الهاتف الأساسي (PoE) الفئة 2 Key Expansion Module: Expansion Module extends the number of call appearances and feature buttons on the Phone. Expansion module provides 24 additional buttons for incoming/outgoing calls, for features such as autodial, for dialing contacts, or for other applications. Specifications: • 4.3 inches, 272 x 480-pixel color display. • Phone support up to 3 button modules, and each button module can take both Stand and Wall mount positions together with the phone. • Expansion Module provides access to up to 24 buttons and lamps with ability to display 3 pages when a single expansion module is used. • Each feature/line button has a red/green indicator. • Pre-configured background or screensavers are available to match the base phone. Power is supplied by base phone (PoE class 2). عدد 13 0
رقم14 1 توريد وتركيب جهاز خادم لتسجيل المكالمات توريد وتركيب جهاز خادم لتسجيل المكالمات بالمواصفات التالية: تأمين جهاز خادم لرصد وتسجيل المكالمات متوافق مع الافايا شامل كامل الرخص وتوفير رخصة (Media Manger) ويكون بسعة تخزينه لا تقل عن (4) تيرا ويوجد به خاصية التعرف على التحويلات مع شاشة كاشف رقم المتصل نوع (Dell Or hp) (LED) للمآمير وبحجم لا يقل عن (21) بوصة مع كيبل شبكة لربطه بين الشاشة ونظام تسجيل المكالمات. • Processor: o Intel® Xeon® E-2200 Family o Minimum Intel® Xeon® E3-2224 3.4 GHz 12M cache o Number of processors: 1 o Processor core: 8 • Minimum Cache Memory: o 12 MB L3 • Memory: o 32 GB (16 x 8GB) RDIMM –DDR4 smart memory • Storage: Minimum o RAID for matching drives o Storage 1: 2 x SSD 512 GB capacity o Storage 2:  RAW Capacity: 4TB  2 x 2 TB capacity • Storage Controller: Storage As per proposed design requirement. • Network Options o 2 x 1Gb Ethernet 2-port LOM Adapter Operating system: Must be compatible with Avaya. Accessories: server with all accessories Key Board Mouse and, components and cables ready to use. Warranty: 3 years. عدد 14 0
رقم15 1 توريد وتركيب نظام حفظ الطاقة UPS توريد وتركيب نظام حفظ الطاقة (UPS) بالمواصفات التالية: - توريد نظام تغذية احتياطية (UPS) (مواصفات أمريكية أو أوربية) قدرة 6 KVA)) مع البطاريات الجافة نوع راك. - توريد البطاريات الجافة الإضافية لتشغيل السنترال وملحقاته لمدة (4) ساعات على الأقل عند انقطاع التيار الكهربائي مع الأحمال نوع راك. عدد 15 0

15 بند

لا توجد مرفقات لهذه المنافسة

اسم المورد قيمة العرض (ر.س) قيمة الترسية (ر.س) النتيجة الفنية الحالة
مؤسسة تجانس للمقاولات 610,144.00 مطابق مشارك
شركة السنمار للتجارة 658,732.65 غير مطابق مشارك
شركة حوسبة التقنية لتقنية المعلومات شركة شخص واحد 794,356.75 مطابق مشارك
شركة تقنية الاتصالات المحدودة 969,284.48 مطابق مشارك
شركة بعد للاتصالات السلكية واللاسلكية شركة شخص واحد 743,793.55 مطابق مشارك
مؤسسة تجانس للمقاولات 610,144.00 610,144.00 مرسّى

الآليات

آلية التفضيل السعري للمنتج الوطني

تفضيل المنشآت الصغيرة والمتوسطة

وثائق المحتوى المحلي

معايير التقييم

معايير التقييم الفني

المستوى الاول المستوى الثاني المستوى الثالث الوزن النهائي
التقييم الفني 1 2 100%

معايير التقييم المالي

المستوى الاول المستوى الثاني المستوى الثالث الوزن النهائي
التقييم المالي السعر التكلفة الكلية 100%

أخبار المنافسة

title تاريخ الإنشاء
value 29/03/47 10:57:10 ص
title تاريخ فتح العروض
value 20/04/47 07:00:00 ص
title تمديد تواريخ المنافسة
value تاريخ فتح العروض20/04/47 07:00:00 صآخر موعد لتقديم العروض20/04/47 07:00:00 صآخر موعد لإستلام الإستفسارات09/04/47 12:00:00 ص
title تاريخ الترسيه
value 17/06/1447