SIPRNET Technical Implementation Criteria October 2010
Total Page:16
File Type:pdf, Size:1020Kb
SIPRNET Technical Implementation Criteria October 2010 DEPARTMENT OF THE ARMY UNITED STATES ARMY INFORMATION SYSTEMS ENGINEERING COMMAND FORT HUACHUCA, ARIZONA 85613-5300 SECRET INTERNET PROTOCOL ROUTER NETWORK (SIPRNET) TECHNICAL IMPLEMENTATION CRITERIA VERSION 6 OCTOBER 2010 FORT DETRICK ENGINEERING DIRECTORATE Distribution C Distribution authorized to U.S. Government agencies and their contractors only, for administrative or operational use, as of October 2010. Refer other requests for this document to Director, U.S. Army Information Systems Engineering Command, Fort Detrick Engineering Directorate, ATTN: ELIE-ISE-DE, Fort Detrick, MD 21702-5047. FOR OFFICIAL USE ONLY SIPRNET Technical Implementation Criteria October 2010 DISCLAIMER The use of trade names in this document does not constitute an official endorsement or approval of the use of such commercial hardware or software. Do not cite this document for advertisement. CHANGES Refer requests for all changes that affect this document to: USAISEC, ATTN: ELIE-ISE-DE, Fort Detrick, MD 21702- 5047. DISPOSITION INSTRUCTIONS Destroy this document when no longer needed. Do not return it to the organization. Safeguard and destroy this document with consideration given to its classification or distribution statement requirements. ii FOR OFFICIAL USE ONLY SIPRNET Technical Implementation Criteria October 2010 SECRET INTERNET PROTOCOL ROUTER NETWORK (SIPRNET) TECHNICAL IMPLEMENTATION CRITERIA VERSION 6 OCTOBER 2010 U.S. ARMY INFORMATION SYSTEMS ENGINEERING COMMAND FORT DETRICK ENGINEERING DIRECTORATE Distribution C Distribution authorized to U.S. Government agencies and their contractors only, for administrative or operational use, as of October 2010. Refer other requests for this document to Director, U.S. Army Information Systems Engineering Command, Fort Detrick Engineering Directorate, ATTN: ELIE-ISE-DE, Fort Detrick, MD 21702-5047. _________________________ KIMBERLY K. REED Group Leader, Data Team Fort Detrick Engineering Directorate _________________________ _________________________ EUGENE W. BAKER ALBERT M. RIVERA Director Technical Director Fort Detrick Engineering U.S. Army Information Systems Engineering Command iii FOR OFFICIAL USE ONLY SIPRNET Technical Implementation Criteria October 2010 TABLE OF CONTENTS Page 1.0 INTRODUCTION ............................................................................................................ 1 1.1 Purpose .......................................................................................................................... 1 1.2 Scope ............................................................................................................................ 1 1.3 SIPRNET Project Goal ................................................................................................. 1 1.4 Disclaimer ..................................................................................................................... 2 1.5 Mandatory and Advisory Terminology ........................................................................ 2 2.0 REFERENCES ................................................................................................................. 2 2.1 National Security Agency (NSA) Publications ............................................................ 2 2.2 Department of Defense (DOD) Publications ................................................................ 4 2.3 Defense Information Systems Agency (DISA) Publications ........................................ 5 2.4 Department of the Army (DA) Publications ................................................................. 5 2.5 Miscellaneous Publications ........................................................................................... 6 3.0 MAJOR PARTICIPANTS AND RESPONSIBILITIES .................................................. 8 3.1 U.S. Army Information Systems Engineering Command (USAISEC) ........................ 8 3.2 Designated Approving Authority (DAA) ..................................................................... 8 3.2 NEC / Communications Provider ................................................................................. 8 3.4 Local Site / User / Tenant IMO .................................................................................... 9 3.5 Army CTTA ................................................................................................................ 10 3.6 Joint .......................................................................................................................... 10 4.0 TECHNICAL SOLUTIONS DESCRIPTION AND CRITERIA .................................. 10 4.1 SIPRNET Programs .................................................................................................... 10 4.2 Connectivity Areas of Responsibility ......................................................................... 12 4.3 Access Areas and Threat Levels ................................................................................. 17 4.4 Protected Distribution Systems (PDS) ........................................................................ 20 4.5 SIPRNET Physical Architecture ................................................................................. 25 4.6 Tunneling .................................................................................................................... 31 4.7 Installation of PDS ...................................................................................................... 31 4.8 Encryption Devices ..................................................................................................... 39 4.9 Secure Wireless Local Area Networks (SWLANs) .................................................... 45 4.10 Voice over Secure Internet Protocol (VoSIP) ........................................................... 48 4.11 Video Teleconferencing (VTC) ................................................................................ 52 4.12 Thin Client ................................................................................................................ 56 4.13 Information Assurance (IA) ...................................................................................... 59 5.0 SIPRNET CONNECTION PROCESS ........................................................................... 61 5.1 DISN Connection Approval Process (CAP) ............................................................... 61 5.2 Accreditation and ATC ............................................................................................... 62 6.0 COST MODELING AND ESTIMATING FOR FINANCIAL PLANNING ................ 64 6.1 General ........................................................................................................................ 64 6.2 Cost Typing ................................................................................................................. 65 6.3 Funding Requirements and Limitations ...................................................................... 66 iv FOR OFFICIAL USE ONLY SIPRNET Technical Implementation Criteria October 2010 Page Appendices Appendix A. Figures, Drawings, and Diagrams ................................................................. A-1 Appendix B. Encryption Devices ........................................................................................B-1 Appendix C. PDS Inspection Checklist ...............................................................................C-1 Appendix D. Sample SIPRNET Site Survey Considerations ............................................. D-1 Appendix E. SIPRNET User and Allocation Tables ............................................................ E-1 Appendix F. SIPRNET Allocations for New Military Construction ................................... F-1 Appendix G. Sample SOP for SIPRNET Connections ...................................................... G-1 Appendix H. Sample SIPRNET PDS Specification for BRAC/MCA Construction.......... H-1 Appendix I. SIPRNET Gross Cost Estimation Tool ............................................................ I-1 Appendix J. Sample IPS Containers with Movable Racks ................................................... J-1 Appendix K. MCA/BCA Funding Breakout ...................................................................... K-1 Glossary. Abbreviations, Acronyms, And Definitions ............................................. Glossary-1 Tables Table 1. VoSIP Area Codes ...................................................................................................51 Table B-1. COMSEC Device NSNs ....................................................................................B-1 Table E-1. User Allocation and Distribution at Brigade HQ BCT ...................................... E-1 Table E-2. User Allocation and Distribution at Battalion BCT ........................................... E-2 Table E-3. User Allocation and Distribution at Division HQ ............................................. E-3 Table E-4. User Allocation and Distribution at Corps HQ .................................................. E-4 Table E-5. User Allocation and Distribution at School Commandant and U.S. Army Engineer School ................................................................................................. E-5 Table E-6. User Allocation and Distribution at Depot Commander and Production Operations .......................................................................................................... E-5 Table E-7. User Allocation and Distribution at Garrison