The contractor shall provide Palo Alto PA-450 IPS or compatible to US Embassy Tbilisi WRAIR office. The contract type will be a fixed price contract. The price listed below shall door-to-door transportation cost to US Embassy Tbilisi, 29 Georgian American Friendship Ave. Tbilisi 0131, Georgia. .
Specification / Work Statement
The contractor shall provide Palo Alto PA-450R IPS or compatible to US Embassy Tbilisi WRAIR office. The contract type will be a fixed price contract. The price listed below shall door-to-door transportation cost to US Embassy Tbilisi, 29 Georgian American Friendship Ave. Tbilisi 0131, Georgia.
Minimum Essential Characteristic (MEC) for Palo Alto PA-450R IPS or Compatible
Hardware specifications
- 1G RJ45 (6), 1G SFP/RJ45 combo (2)
- Management Console Port – RJ45 (1), USB Port for bootstrapping (1), 1G Management Port (1), micro–USB Console Port (1)
- Storage Capacity 128 GB
- Trusted Platform Module (TPM) Integrated with TPM for secure boot, hardware root of trust, and securing system secrets
- Power Supply: Max Power Consumption: 39.4 W
- Max BTU/hr:136 BTU/hr
- Input Voltage (Input Frequency): 12 V–48 VDC
- Max Current Consumption: 5 A @ 12 VDC
- Max Inrush Current: 5A
- Dimensions: 44.4 mm H x 390 mm W x 238 mm D – 1RU
Performance and Capacities
- Firewall throughput 3.2 Gbps
- Threat Prevention throughput 1.7 Gbps
- IPsec VPN throughput 1.3 Gbps
- Max sessions 200,000
- New sessions per second 48,000
- Virtual systems (base/max) 1/2
Networking Features
- Interface Modes: L2, L3, tap, virtual wire (transparent mode)
- Routing: OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing, Policy-based forwarding, Point-to-Point Protocol over Ethernet (PPPoE), Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3
- SD-WAN: Path quality measurement (jitter, packet loss, latency), Initial path selection (PBF), Dynamic path change
- IPv6: IPv6 L2, L3, tap, virtual wire (transparent mode), ) Features: App-ID, User-ID, Content-ID, Wildfire, and SSL decryption, SLAAC
- IPsec VPN: Key exchange: manual key, IKEv1 and IKEv2 (pre-shared key, certificate-based authentication), Encryption: 3des, AES (128-bit, 192-bit, 256-bit), Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512
- VLANS: 802.1Q VLAN tags per device/per interface: 4,094/4,094, Aggregate interfaces (802.3ad), LACP
Security and Connectivity Features
- Embeds machine learning (ML) in the core of the firewall to provide inline signatureless attack prevention for file-based attacks while identifying and immediately stopping never-before-seen phishing attempts.
- Leverages cloud-based ML processes to push zero-delay signatures and instructions back to the NGFW.
- Uses behavioral analysis to detect internet of things (IoT) devices and make policy recommendations; is a cloud-delivered and natively integrated service on the NGFW.
- Automates policy recommendations that save time and reduce the chance of human error.
- Identifies and Categorizes All Applications, on All Ports, All the Time, with Full Layer 7 Inspection
- Enforces Security for User Devices Anywhere While Adapting Policies Based on User Activity
- Prevents Malicious Activity Concealed in Encrypted Traffic
- Offers Centralized Management and Visibility
- Offers AI-Powered Unified Management and Operations with Strata Cloud Manager
- Cloud-Delivered Security Services Powered by Precision AI:
-
-
-
-
- Advanced Threat Prevention: Stop known and unknown exploits and command-and-control (C2) attacks with inline AI-powered detections, stopping 60% more zero-day injection attacks and 48% more highly evasive command-and-control traffic than traditional IPS solutions.
- Advanced Wildfire: Ensure files are safe by automatically preventing known, unknown, and highly evasive malware 180X faster than competitors with the industry’s largest threat intelligence and malware prevention engine.
- Advanced URL Filtering: Ensure safe access to the internet and prevent 40% more web-based attacks with the industry’s first real-time prevention of known and unknown threats, stopping 88% of malicious sites at least 48 hours before other vendors.
- DNS Security: Gain 68% more threat coverage and stop 85% of malware that abuses DNS for command and control and data theft without requiring changes to your infrastructure.
- SaaS Security: Stay ahead of the SaaS explosion with the industry’s only Next-Generation CASB to automatically see and secure all apps across all protocols
- IoT Safeguard every “thing” and implement Zero Trust device security 20X faster, with the industry’s smartest security for smart devices.
- Delivering a Unique Approach to Packet Processing with Single-Pass Architecture
- Enables SD-WAN Functionality
VALUE ADDED TAX. Value Added Tax (VAT) is not applicable to this contract and shall not be included in the CLIN rates or Invoices because the U.S. Embassy has a tax exemption certificate from the host government.
Shipping Incoterms: DAP (Delivered at Place)
Delivery location:
US Embassy Tbilisi,
29 Georgian American Friendship Ave.
Tbilisi 0131, Georgia.
Delivery Time: 30 days from the date of order.