Specifications include, but are not limited to: 1. MINIMUM REQUIREMENTS Utilizing E-rate funds, Newport News Public Schools (“NNPS”) is seeking to upgrade/replace its current firewall solution with next generation firewall hardware, software, support, and related services. The goals of the proposed solution are to provide: • Full Data Inspection (Deep Packet Inspection) services to all inbound/outbound traffic with at least 40 GBs of combined throughput. • Protect the districts users, network, and data from internal and external threats. • Create firewall policies based on authentication of internal users and devices. • Integration with the district’s existing network hardware and software solutions. 2. CONNECTIVITY AND HARDWARE REQUIREMENTS • Support at a minimum 40 Gbps sustained throughput with all threat management extensions enabled. The proposed firewall solution must be extensible to accommodate the school division’s growing needs and keep up with higher throughput requirements. • Per firewall, include a minimum of four (4) 10 Gbps SFP+ ports. Additional ports along with the ability to utilize QSFP+ are desired. All ports must compatible and work with the existing network equipment. • Hardware compatibility with 60km SFP+ modules that support single mode fiber (SMF). • The proposed solution should provide a modular hot swappable (1+1 redundant) dual power supply. • It is preferred that the proposed firewall solution should utilize solid-state hard drives (SSD), with sufficient storage to retain the operational data on the device. • The proposed solution must support dual stacking of IPv4 and IPv6 protocols for all firewall features and functions. It should also support the implementation of IPv6 in the future. • The proposed solution must offer platforms including Windows operating system, Linux operating system, and all virtual environments including but not limited to VMWare, Azure, and Hyper-V. • The proposed solution must support stateful protocol filtering, deep packet inspection, and detection of attacks within the payload. • It is desired that the proposed solution provides micro segmentation capabilities to block the lateral movement of nefarious network traffic in the data center network. • It is desired that the proposed solution integrates with the school divisions’ SIEM solution and other 3rd party logging tools. •A minimum of 8 network interfaces on the proposed device for connections to the internet, network core, and other switch gear.