All bid deadlines are 11:59pm Pacific Time the date of the bid deadline listed unless otherwise noted.
· Before the listed deadlines, all Questions and Bids must be submitted using the on-line IFCB system. Bids submitted before the bid deadline outside of this system will be disqualified. If the system is down before the deadline, please email your bid to info@crwconsulting.com or fax it to 918.445.0049. Bids or questions submitted in this fashion will be disqualified if the on-line system is active at the time of submission. The applicant reserves the right to request and obtain bids outside of the website system if the bid deadline has passed and zero or one bid is received (the intent for this is to follow USAC guidance on obtaining cost-effective bids).
· For all requested services and/or products listed on this IFCB: proposals that include generic/encyclopedic price lists will be considered non-responsive and will be disqualified. SPAM and/or robotic responses will not be considered valid bid responses and will be disqualified from consideration.
· Bidder must agree to participate in USF Program (AKA “E-rate”) for the corresponding funding year.
· Please include the correct Service Provider Identification Number (SPIN) on your bid.
· By submitting a bid, bidder certifies that the bidder does have a valid (non-red light status) SPIN for the E-rate program at the time of submission. Should the Applicant discover that the bidder is on red light status, or if the FCC classifies the bidder as on red-light status before work is performed and invoices are paid, the contract will be null and void and the applicant will have no payment obligations to the bidder.
· Bidder is expected to provide the lowest corresponding price per E-rate rules. See https://www.usac.org/e-rate/service-providers/step-2-responding-to-bids/lowest-corresponding-price/ for details.
· Contracts must not prohibit SPIN changes.
· Bidder must agree to provide the Applicant the choice of discount methods (SPI or BEAR).
· Bidder will be automatically disqualified if the District determines that the bidding company has offered any employee of the District any individual gift of more than $20 or gifts totaling more than $50 within a 12 month period. This does not apply to the recent FCC exemptions of the Gift Rule for the COVID pandemic.
· All contracts awarded will be contingent upon E-rate funding and final board approval. The applicant may choose to do all or part of the project upon funding notification.
· All applicable fees, surcharges, and taxes must be identified on the bid. E-rate rules require the applicants to evaluate the price of eligible goods and services that will be listed on the 471 application during the competitive bidding process. Fees and surcharges that apply but are not listed on the bid will be the responsibility of the bidding company, should their bid be awarded.
· If there is a request to purchase or lease new equipment, either Category Two or Category One, listed on this IFCB the applicant will accept bids for functionally equivalent equipment.
· DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: The applicant will not accept bids from manufacturers of equipment deemed a national security threat by the Federal Communications Commission. The list of prohibited equipment is available here: https://www.fcc.gov/supplychain/coveredlist . Vendors that submit bids that includes these manufacturers will have their bid disqualified.
· DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: Vendors must complete and include the C2 Cover Page with their bid. Bids received without the cover page will be disqualified.
· DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: Service providers are required to bid the entire hardware project. Bids for individual components, or bids that do not include all of the requested items for the project will be disqualified.
· DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: Applicant will not accept bids for refurbished equipment. Any bids containing refurbished equipment will be disqualified.
· DISQUALIFICATION FACTOR BMIC: Service providers are required to bid the entire maintenance project. Bids for individual components of the project will be disqualified.
· DISQUALIFICATION FACTOR BMIC: Vendors must complete and include the C2 Cover Page with their bid. Bids received without the cover page will be disqualified.
· DISQUALIFICATION FACTOR BMIC: Maintenance bids listing only an hourly rate and not a monthly or annual total will be disqualified. Vendors quoting an hourly rate are required to also a) confirm that you have the ability/expertise to maintain all of the equipment listed and b) propose a number of hours at a particular rate monthly to properly maintain the entire list of equipment. Bids that contain only hourly rates, without confirmation that the company can service the list of equipment, or without a monthly total will be disqualified.
UPDATE 01.13.26 - THE QA DEADLINE HAS BEEN UPDATED TO 01.30.26. THE BID DEADLINE HAS BEEN UPDATED TO 02.27.26
Category Two:
Hutto ISD is seeking to modernize and strengthen our network perimeter security by replacing aging Palo Alto Networks firewalls that are nearing end-of-support. The project involves deploying a high-availability (HA) pair of 10 Gbps next-generation firewalls (NGFWs) at our primary/administrative site to provide redundant, stateful inspection, intrusion prevention, application-layer control, advanced threat detection and DNS filtering. A matching single NGFW will be deployed at our secondary site to ensure consistent security policies and simplified management across locations. Professional services are requested for physical installation, configuration and policy migration from our existing Palo Alto Networks firewalls (to minimize downtime and ensure continuity of current rulesets), and SD-WAN setup (if supported by the proposed solution) to enable secure, optimized connectivity and automatic failover between sites.
This upgrade will significantly enhance protection against malware, ransomware, and data exfiltration attempts; threats that directly jeopardize student data privacy and instructional continuity; while supporting reliable, high-performance access to cloud-based learning platforms, digital curriculum resources, and administrative systems for our students, teachers, and staff.
We require multi-year security subscriptions (preferably 5 years) for full next-generation firewall functionality with comprehensive threat detection and prevention on all proposed appliances.
At minimum, these subscriptions must include:
· Advanced threat protection with cloud-based sandboxing/analysis
INTERNAL CONNECTIONS
|
Quantity Vendor Should Bid
|
Preferred Make/Manufacturer |
|
|
Firewall Service & Components |
3 |
No preference - 10Gb/s capable throughput, stateful inspection, intrusion prevention (IPS), application-layer visibility and control, advanced threat protection |
NOTE: We are requesting firewall licenses on this IFCB, which sometimes may be categorized as BMIC or MIBS by USAC (the BMIC and MIBS boxes on the 470 have been checked to cover this scenario).
DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: The applicant will not accept bids from manufacturers of equipment deemed a national security threat by the Federal Communications Commission. The list of prohibited equipment is available here: https://www.fcc.gov/supplychain/coveredlist . Vendors that submit bids that includes these manufacturers will have their bid disqualified.
DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: Vendors must complete and include the C2 Cover Page with their bid. Bids received without the cover page will be disqualified.
DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: Service providers are required to bid the entire hardware project. Bids for individual components, or bids that do not include all of the requested items for the project will be disqualified.
DISQUALIFICATION FACTOR INTERNAL CONNECTIONS: Applicant will not accept bids for refurbished equipment. Any bids containing refurbished equipment will be disqualified.
BASIC MAINTENANCE OF INTERNAL CONNECTIONS:
The district would like a manufacturer’s support contract for these items:
|
Type of Equipment |
Quantity Vendor Should Bid
|
Preferred Make/Manufacturer |
|
Firewall Service & Components |
3 |
No preference - 10Gb/s capable throughput, stateful inspection, intrusion prevention (IPS), application-layer visibility and control, advanced threat protection |
DISQUALIFICATION FACTOR BMIC: Service providers are required to bid the entire maintenance project. Bids for individual components of the project will be disqualified.
DISQUALIFICATION FACTOR BMIC: Vendors must complete and include the C2 Cover Page with their bid. Bids received without the cover page will be disqualified.
DISQUALIFICATION FACTOR BMIC: Maintenance bids listing only an hourly rate and not a monthly or annual total will be disqualified. Vendors quoting an hourly rate are required to also a) confirm that you have the ability/expertise to maintain all of the equipment listed and b) propose a number of hours at a particular rate monthly to properly maintain the entire list of equipment. Bids that contain only hourly rates, without confirmation that the company can service the list of equipment, or without a monthly total will be disqualified.
| 2026_C2_Bidding_Instructions_223.pdf |
| HUTTO_C2_COVER_PAGE4.pdf |
Answer:
The existing Palo Alto firewalls are configured with 77 security policies (access rules) and 30 NAT rules.
Stateful packet filtering is enabled by default on all security policies. The firewall maintains session state for all allowed connections and only permits return traffic that matches an established session.
Application-Level Gateway (ALG) functionality is currently disabled on our firewalls.
Circuit-level gateways are not a separate configurable rule set that I can find.