Modernization of the central firewall system at Forschungsverbund Berlin e.V.
Modernization of the firewall and security architecture: including Next Generation Endpoint Protection for Forschungsverbund Berlin e.V., with the solution required to meet current and future demands for information security, availability, scalability, multi-tenancy, traceability of administrative activities, and economic operation. Requirements for the new firewall structure: multi-stage firewall structure with centrally operated perimeter firewall cluster and segmentation firewall clusters per institute (dual-vendor strategy), VLAN- and IP-based institute-specific segmentation, virtual domains for segmentation of the corporate IT perimeter firewall, at least two appliances per geographical location in active-passive operation, backbone throughput expansion to 10 Gigabit per second (extendable to 40 Gigabit per second without hardware replacement) and loop-free network design, number of simultaneous sessions: 20,000 to 65,000, VPN usage per institute: at least 40 to 70 users (maximum 1,600 employees in FVB), consideration of QoS mechanisms for VoIP and latency-sensitive applications, granular, federation-wide uniform role and authorization concept for administrative access, multi-factor authentication for users (native or via identity provider) and administrators (native), NGFW functionalities (IPS, IDS, Application IP, Geo-IP filter), separation of networks (e.g., laboratory networks) via VLAN, central DNS security service, DoS defense, content filtering and advanced threat protection as well as integration of external blacklists at the perimeter level, powerful and practical DoS defense, shared, multi-tenant WAF service for web applications, platform support for VPN access for Windows, Linux and MacOS, compliance check for all operating systems, central management for perimeter (mandatory) and segmentation firewalls (optional), tenant separation with granular gradation of administration rights, open interfaces to support REST- or XML-based APIs, Syslog, Net-Flow/IPFIX, SAML, LDAP, RADIUS and other market-standard integration interfaces, Remote Access (support for established procedures with split tunneling and carrier-grade NAT), identification of institute affiliation (e.g., via certificates or naming conventions), SSL interception (inbound for published services and outbound for critical servers/clients), email security (multi-tenant, optionally purchasable per institute), sandbox functions, Out-of-Band management, minimum interface for automatic integration of certificates, IPv6 future-proofing (no IPv6 migration planned within the project), central, multi-tenant log management with at least three months retention period, local buffering or short-term fallback retention, and interfaces to a potential SIEM, tenant-related and institute-specific logging. Support and service for hardware, software, subscriptions, and management components: fault resolution, maintenance, software care, manufacturer and system house support, hardware replacement, patch and release management, operational support, and a traceable escalation process. Solution availability: at least 99.9% per year. NOC services with security analysis. SOC services as an additional option/add-on, including monitoring, triage, analysis, alarming, initial processing, incident response, reporting chains, on-call duty, multi-tenancy, SIEM/SOAR integration, log sources, sensor technology, reporting, and communication channels.
Never miss a tender again
We send you 3 current matches that fit your company.
Tender documents
- Portal — LOT-0000NON-RESTRICTED-DOCUMENT
- TED HTML — 575952-2026HTML
- TED PDF — 575952-2026PDF
- TED XML — 575952-2026XML
Unlock documents for free
Enter your email address. If you confirm, we will also send you 3 similar tenders.