Juniper Astra SME 100% Remote Long-Term Contract Project Details
In-Scope Hardware (“In-Scope Hardware”)
Up to six (6) QFX5120-32C (2x spines, 2x ToR leaves, 2x core routers)
Up to two (2) QFX5120-48Y (2x border leaves)
Up to four (4) QFX5110-48S (2x edge agg switches, 2x wan agg switches)
Up to two (2) PA-5410 firewalls (2x VSYS for Internet FW, 2x VSYS for WAN FW)
Up to (2) PA-3410 firewalls (2x DC firewalls)
Up to four (4) MX-204 routers (2x Internet routers, 2x WAN/Cloud routers)
Up to two (2) C8500-12X routers (2x SD-WAN routers)
Up to two (2) C9300-24Y switches (OOB mgmt. core stack)
Up to two (2) C9300-48T switches (OOB mgmt access stack)
One (1) OpenGear Serial Console
One (1) PA-440 (OOB firewall)
One (1) Apstra VM instance
In-Scope Sites (“In-Scope Sites”)
Philidelphia Data Center
Ashburn Data Center
Discovery Phase
Phase 1 – Discovery and Assessment
Current Philadelphia application and virtual machine assessment
Ashburn datacenter capacity and readiness review
Inventory and assessment of existing Juniper switching hardware
Review of current network and security architecture
Review of existing Software-Defined Wide Area Network (“SD-WAN” ) environment
Review of inter-datacenter connectivity, dependencies, and telemetry
Review Current firewalls for Routing, Policy and Network Address Translation (“NAT” )
Design Phase
Phase 2 – Planning and Design
Application migration strategy using vMotion
Greenfield Philadelphia datacenter architecture design
Juniper spine-leaf fabric design using:
Up to two (2) QFX5120 spine switches
Up to three (3) pairs of QFX5110 leaf switches
Apstra fabric design and policy definition
Palo Alto firewall architecture design including:
PA-3410 firewalls for core routing and segmentation
PA-5410 firewalls for edge, Wide Area Network (“WAN” ), and Virtual Routing and Forwarding (“VRF” ) firewall services
Not exceeding current policies and routing configurations
Replicate the existing firewall policies and applying them to the new segmented firewalls; this includes copying the current policies from the existing firewall and distributing them across the newly separated firewalls
Management and Out-of-Band (“OOB” ) network design using:
EX4400 switches
PA-440 firewalls
Base policies of up to ten (10) rules
Global Protect with base configurations and access
Edge and WAN networks designs
Circuits
SDWAN
Multiprotocol Label Switching (“MPLS” )
Internet
Cloud Circuits
Migration sequencing and cutover planning
Buildout of cabling and connections table
Execute Phase
Phase 3 – Execution and Migration – Up to four (4) eight (4) hour Cutover Windows Included
Isolation of production compute/application environment in Philadelphia
Disconnect core uplinks from QFX5110 Top-of-Racks (“ToRs” ) supporting the existing compute environment
Prepare QFX5110 ToRs for Multiple Spanning Tree Protocol (“MSTP” ) and to accept E-LINE circuits from Ashburn
Migrate E-LINE circuits from existing cores to QFX5110 ToRs
Client Post-migration validation and application verification
Greenfield Philadelphia Datacenter Build (Rack, stack, cable, label of hardware)
Deployment of spine layer using up to two (2) QFX5120-32C switches
Deployment of border leaves using one (1) pair of QFX5120-48Y switches
Deployment of leaf layer using one (1) pair of QFX5120-32C switches
Apstra fabric build, configuration, and validation
Deployment of core routing segment using QFX5120-32C switches
Deployment of edge and WAN switching using QFX5110-48S switches
Security, WAN and SD-WAN Integration (Rack, stack, cable, label of hardware)
Deployment of Palo Alto PA-3410 firewalls for core and segmentation
Deployment of Palo Alto PA-5410 firewalls for edge and WAN services
Configuration of VRF firewall services on PA-5410
Deployment of management and OOB network using EX4400 switches and PA-440 firewalls
Integration of Cisco C8500 routers into the SD-WAN environment
MPLS Data Center Interconnect (“DCI” ) connectivity
Telemetry connectivity
Cloud Connectivity circuits
OOB
Build out of OOB hardware
Configurations of firewall Policy
Virtual Private Network (“VPN” ) remote access
Phase 4 – Reconnection and Documentation
Re-establishment of Layer 2 inter-datacenter connectivity between Ashburn and Philadelphia
Validation of inter-datacenter connectivity and transport
Client will start migrations
Phase 5 – Moving of Data Center routing (Done at 50% of move)
Move all SVI interfaces and routing:
Including Domain Name System (“DNS”) (to be managed by Client)
Public Internet Protocol (“IP” ) and Classless Inter-Domain Routing (“CIDR” ) blocks (to be managed by Client)