Specifications include, but are not limited to: ● Sufficient capacity for non-blocking routing traffic from multiple 25Gb/s interfaces ● Sufficient capacity for operation of all security features enabled, at minimum of 20Gb/s ● Provide automated HA failover for our environment, with each single firewall node capable of running with all security features enabled, at minimum of 20Gb/s ● Sufficient capacity and/or licensing for log retention of 30 days ● SSL Deep Packet Inspection and Certificate Only Inspection ○ Inspection rate should be 20Gb/s or greater ● Basic Features ○ HA (active-active) ○ Access Control Rules ○ Packet capture capabilities ● Protecting our network from the outside ○ IDS/IPS ○ Web Application Firewall ○ Antivirus/Botnet detection/prevention ○ Inline malware detection/prevention (sandboxing) ○ External threat feed support ● Filtering ○ Ability to filter users based on Active Directory groups ○ Override filtering categories ○ Customize block pages ○ URL filtering (wild card, regex, simple) ○ Based on geolocation ● Application Control ○ By single application or category to allow/block resources (TikTok, Twitch, P2P, Proxy, etc) ○ Ability to add custom applications ● VPN ○ SSL/IPSEC client VPN (with Entra-ID, SAML for MFA) ○ IPSEC point-to-point VPN ○ Web VPN portal to resources (shared drives, RDP/VNC) ○ Ability to manage/deploy VPN client using Jamf and SCCM ● Reporting ○ Must provide logs that can be ingested and used for forensic evaluation on user, device, application, source/destination for up to 30 days. In addition, log files need to be in a format that can be forwarded to Rapid7 or other correlation/analysis tools. ○ Netflow-style real time reporting of traffic allowing granular filtering and analysis of top-talkers, individual source/destinations. ○ Automated scheduled reporting of summary data (eg. Executive summary, Top Talkers, etc.) ○ Alerts on threshold limits. ○ SNMP support for basic appliance platform health/performance statistics. ● Training ○ Provide training for three (3) network specialists