HomeMy WebLinkAboutCORRESPONDENCE - PURCHASE ORDER - 9114815DIRSEC
The security People,„
City of Fort Collins
Network Consulting
Proposal
Proposal Number City of Fort Collins-04
About this Document This document describes the services
and materials DirSec will provide for
(City of Fort Collins). This document
includes the time and costs,
deliverables, and assumptions for the
services.
DirSec is a consulting leader and
About DirSec reseller of security products and
services.
Lou Rubbo DIRSEC, INC. (303) 960-6106
DI�iR��SEC
ree5 curity Pam ,
BACKGROUND.
DESCRIPTION OF WORK
DELIVERABLES
t]
ASSUMPTIONS........................................................................................................................................ 4
TASKTIME.............................................................................................................................................. 5
TASKPRICE............................................................................................................................................ 6
SCHEDULE FOR PAYMENT OF TASK PRICE................................................................................ 6
CITY OF FORT COLLINS
DIRSEC, INC.................
........... 7
........... 7
DirSec Confidential Copyright 20119 DirSec, Inc. All Rights Reserved
DirSec Statement of Work 8/812011
2
95P.
�C People
Background
This Statement of Work is a proposal to provide firewall and network consulting services for City of
Fort Collins. It is based on correspondence between City of Fort Collins and Lou Rubbo in June 2011.
Description of Work
DirSec will provide firewall consulting to the City of Fort Collins to replace their existing Check Point
firewall cluster from a Nokia IP350 pair to a pair of Point 3070s. This includes the replacement of the
management bundle. Services include support, configuration, testing, troubleshooting, and
documentation. DirSec would also provide consulting to clean up firewall rules and migrate.VPN client
access from Check Point to Cisco.
Deliverables
Based on the transactions described in background, DirSec proposes to deliver the following to City of
Fort Collins.
1. Upgade current SmartCenter to R70 from R61. This includes backing up current SmartCenter
image for a full restore as a back out.
2. Upgade existing and internal portal firewalls from R61 to R70.
3. Upgrade Edge device(s) as necessary.
4. Review existing firewall configurations.
5. Modify firewall rules as necessary. All rule changes will be documented. Estimated rule count
of 222. Perform rule clean up.
6. Move firewall rules and configuration from existing management center to UTM-3070
management on a VM instance.
7. Set up UTM-3070 cluster in active -passive HA pair. Includes network configuration of units.
8. Implement UTM-3070 pair in production.
9. Upgrade SmartCenter to R75.
10. Upgrade internal firewall pair to R75.
11. Perform `go live' of internal firewalls to production.
12. Upgrade UTM-3070 cluster to R75.
13. Upgrade Eventia to bladed architecture of SmartV iew Reporter/analyzer.
14. Migrate Eventia to new hardware platform.
15. Implement new IPS blades on UTM-3070.
16. Review additional blades as necessary.
DirSec Confidential Copyright 2009 DirSec, Inc. All Rights Reserved
DirSec Statement of Work 818/2011
DIRSFC
The Security Peoples
17. Set up baseline IPS policies.
18. Validate firewall rules in the new environment.
19. Migrate VPN users from Check Point to Cisco — target of approximately 50 vendor and partner
VPN profiles to migrate.
20. Perform follow on support as necessary.
21. Testing and troubleshooting of firewall environment.
22. Operational documentation as needed.
Assumptions
DirSec assumes the following conditions regarding the engagement with City of Fort Collins's:
Most work will be delivered on City of Fort Collins's premises using City of Fort Collins's
computer resources.
2. City of Fort Collins's staff will be required to support DirSec throughout the life of the project
performing specific tasks and system testing and acceptance.
3. City of Fort Collins will have all licensing for the underlying software and hardware completed
prior to software installation.
4. The existing environment is a pair of Check Point (Nokia) IP350s running NGX R61 and Nokia
IP265 also running R61.
5. The schedules and hours listed in this Statement of Work are based on input derived from previous
correspondence with the City of Fort Collins. These schedules and hours can change pending
further discovery or change in the scope of work.
6. Additional work that is not covered in this Statement of Work will be added in a separate
document. Changes to the work described in the Statement of Work may require additional time
and money.
7. While work is performed at City of Fort Collins's facilities, City of Fort Collins will provide
DirSec the proper access and support to perform the work in the time frames listed.
8. DirSec is sensitive to City of Fort Collins's security concerns. To ensure the DirSec consultants can
deliver the solution on time, however, the DirSec consultants may require root, super user, or an
equivalent level of administrative access for any systems on which the consultants work at City of
Fort Collins's. (When this is not possible, City of Fort Collins's must provide an administrator to
perform root level tasks in a timely manner.)
DirSec Confidential Copyright 2009 DirSec, Inc. All Rights Reserved
DirSec Statement of Work 8/812011
DIRSEC
TheecKu�rl�ty Pe�op
9. The engagement cycle for DirSec is based on an agreed upon work schedule. Although this
schedule can be altered to accommodate personal emergencies, such as illnesses, business
operations at City of Fort Collins's must be planned to accommodate this schedule.
10. City of Fort Collins will provide reasonable access for DirSec consultants who will work on site to
the appropriate facilities. Access methods may include security badges, escorts, or other means as
necessary.
Task Time
Work will begin based on a completed purchase order or and a mutually agreed upon start date. .
Task time not to exceed 16 hours consulting for line item #4, firewall rules clean up.
Task time not to exceed 20 hours for VPN migration, line item #15.
Task time not to exceed 30 regular hours and S after hours for remaining line.
DirSec Confidential Copyright 2009 DirSec, Inc. All Rights Reserved
DirSec Statement of Work 818/2011
DiRSEC
The Secunty�People„
Task Price
• The total service cost is not to exceed $2,560 for firewall rule clean up.
• Total service cost not to exceed $3,200 for VPN migration.
• Total service cost not to exceed $6,400 for all other work defined in this SOW including
upgrades and migrations.
This is a not to exceed price, City of Fort Collins will be invoiced only for actual hours worked. This is
based on a rate of $160 per hour for regular hours and an after hour rate of $200/hour. This cost does
not include travel and expenses. Travel expenses limited to mileage and hourly travel rate, not to exceed
$500.
Schedule for Payment of Task Price
The payment is due net 30 days after the invoice is received.
DirSec Confidential Copyright 2009 DirSec, Inc. All Rights Reserved
DirSec Statement of Work 8/8/2011
BMfit�)Pibipze-
Authorization C
to Proceed with this Proposal:
City of Fort CDllin
Signature:
Name: Aocer .L 9/NGltr'WU/
Title: Nq-ka. G k _
DirSec, Inc.
Signature
Lou Rubboo
Principal
Tel: 303 9606106
Reply to:
Attn. Lou Rubbo
Lou(a),DIRSEC.com
DirSec Confidential
DirSec Statement of Work
Date: 9, N)-o I I
Date:
Copyright 2009 DirSec, Inc All Rights Reserved
8/8/2011