About Me

My photo
JHC Technology is a Service Disabled, Veteran-Owned, Small Business based in the Washington, DC Metro area. Our primary focus is to offer customized solutions and IT consulting to our Commercial and Government clients. Our experts have a broad experience delivering and managing Microsoft Enterprise applications and Cloud and Virtualization Solutions, as well as mobilizing Enterprise data.
Showing posts with label Federal Solutions. Show all posts
Showing posts with label Federal Solutions. Show all posts

Monday, July 21, 2014

GSA IT Schedule 70 Offers Amazon Web Services (AWS) Cloud Infrastructure with SDVOSB Status

The United States General Services Administration (GSA), an agency devoted to the efficient acquisition of services for the United States Federal Government, awarded JHC Technology, Inc., with a contract schedule as an approved vendor of Information Technology services to federal, state and local government agencies. Although JHC Technology has worked with all levels of government in the past, the GSA award serves as a formal contract vehicle for government customers to directly procure and leverage JHC Technology's services, including Amazon Web Services (AWS) Cloud Infrastructure products. 

As an expert services integrator and Service Disabled, Veteran-Owned Small Business (SDVOSB), JHC Technology is proud to have been awarded its GSA IT Schedule 70 Contract with Special Item Number 132-51 providing Professional IT Services that include Cloud Engineering and Administration categories; and Special Item Number 132-52 providing AWS Cloud Services to Federal, State and Local governments.


For more information, please contact:

Ms. Wendy Dueri
Director of Business Operations

About JHC
JHC Technology, Inc. is a Service Disabled, Veteran-Owned, Small Business (SDVOSB) that provides Engineering, Architecture, and Subject Matter Expert level services in Microsoft, Citrix, Amazon Web Services and mobility services to apply intelligent technology solutions to a broad range of business needs. Our primary focus is to streamline business processes, securely increase the mobility of end users, and effectively provide customers with highly scalable environments while ensuring necessary computing power and infrastructure by leveraging on-demand, utility-based computing and next generation solutions.
 
JHC Technology is an Amazon Web Services Authorized Government Reseller Partner, Advanced Consulting Partner, and Channel Reseller. In addition, JHC Technology holds partnerships with Citrix Systems and Microsoft Corporation.  For more information on JHC Technology, please visit http://www.jhctechnology.com.

Friday, December 13, 2013

JHC to be Panelist at NIST Industry Day - Dec. 16, 2013

Craig Atkinson, JHC's Chief Technical Officer has been selected to be one of the panelists that will be presenting during this year's NIST Industry Day. The event expects to attract 600 registrants from around the DC Metro area seeking to learn more about the challenges of Cloud computing in the Federal Government.

The industry day will focus on the challenges that the Federal Government is experiencing when it comes to the disruptive technology, specifically around procuring Cloud services and infrastructure. As the landscape for procuring computing power is being transformed by Cloud computing, the industry day will attempt to address the changes in the market that can assist the Government in transforming the way it procures Cloud computing moving forward. The industry day also promises to touch base on the capabilities available in the commercial market space in regards to Cloud web hosting and content management.

JHC Technology will also have a booth set up where you can stop by, meet our team and learn more about what we have cooking in the Cloud today.

The Industry Day will be held at the NIST location at 100 Bureau Drive, Building 101, Gaithersburg, MD 20899 on Monday, December 16th. To register, visit https://www-s.nist.gov/CRS/conf_disclosure.cfm?conf_id=6571

Tuesday, November 12, 2013

Hybrid Cloud Solutions: Amazon Web Service (AWS) and Microsoft Office 365


Can Microsoft Office 365 and Amazon Web Services (AWS) work together?  The answer to this cloud riddle is YES.  

There seems to be an overall confusion between what these Cloud venders provide as services.  To be clear, Amazon Web Services is an Infrastructure as a Service (IaaS) provider and Microsoft Office 365 is a Software as a Service (SaaS).  

In enterprise deployments of Office 365, many organizations have requirements to manage and synchronize user profiles to Office 365, restrict user access, provide secure mobile access, and advanced Exchange/Lync/SharePoint management (Remote PowerShell and management consoles).  

In order to satisfy these requirements, organizations will need to deploy the following components within their controlled environment:
  • Mobile Management Solution (Blackberry Enterprise Server 10)
  • Active Directory Federation Services (ADFS) internal and proxy
  • Exchange and Lync Management Console
  • Remote PowerShell for SharePoint, Exchange, Lync, and other Office 365 components

Some of our clients have elected to move these components into their own Virtual Private Cloud (VPC) within Amazon Web Services (AWS) so that they can take advantage of the power of AWS (Elastic, Pay as you go model, network, high availability, etc…) and remove their dependencies on managing their own data centers. Once these components have been deployed they can be configured to integrate/communicate with Office 365 Exchange, SharePoint, Lync, and other Office 365 components.

JHC Technology has also designed and implemented virtual application and desktop technology to run on Amazon Web Services.  We are able to deploy the Microsoft Outlook virtual application as well as other office products on AWS and connect them to Office 365.  In this scenario, users are able to connect to an AWS region and access Outlook either via virtual desktop or virtual application from any device and pull down their Office 365 exchange mail securely.

Organizations should not be tied down to use only one cloud model (IaaS vs SaaS). They should look at their overall requirements and choose an architecture that is flexible enough to expand for future requirements.

James Hirmas is the CEO for JHC Technology.  He can be reached at jhirmas(at)jhctechnology.com,@JHC_JamesHirmas, or connect with him on LinkedIn.

Friday, November 8, 2013

Cloud Isn’t All or Nothing

One of the misconceptions that I run into as I visit potential clients is the amount of access a company like ours has when performing a cloud project for a company or individual.  Invariably, at some point, the question of data visibility comes to the forefront.  It usually goes something like this:  “So are you going to be able to see everything, because we can’t have that!”

The answer to this question is the same as many other answers we give when it relates to highly malleable cloud projects:  “It depends.”

Cloud isn’t an all or nothing endeavor.  Your data doesn’t have anything to do with our work, and whether we get to see the data is totally up to you.  I look at it this way:  A cloud provider, such as AWS, can come to the site at which you’re building your dream home.  AWS will put a Home Depot on the site and then leave.  AWS doesn’t tell you how to build your home, what boards to use, or whether that joint requires a nail or a screw.  All they do is keep the Home Depot stocked.  JHC handles the architecture and deployment, and we know all the best practices when it comes to using the material.  But that’s where it ends.  We can build your house without ever knowing what will go in it.

Your data is the same way.  We don’t need to see it and building your cloud environment isn’t dependent on having any access to it at all.

We are doing one project with a global organization in which we have full control of the cloud infrastructure we are deploying.  This infrastructure is being deployed in an AWS Virtual Private Cloud (VPC).  As part of the creation of the VPC, our client’s requirement was that the VPC only allows access from a specific set of IP addresses.  As it stands, that IP range is limited only to our client’s development servers.  What that means is while we can deploy a server into the AWS VPC, we can’t even verify its operation beyond the fact that the server is running.  We have no access to ping the server or remote into it.  The only access comes from the client’s on-premises machines.

Testing the capabilities of the cloud can provide tremendous insight for an organization.  Many times, involving an outside consultant with cloud experience is also the wise step.  But, don’t fret that you’ll need to give the ol’ “Keys to the Kingdom,” to your consultant.  You can build and test all sorts of services without exposing your data outside your organization.

Matt Jordan is the Cloud Services Manager for JHC Technology.  He can be reached at mjordan(at)jhctechology.com, @matt_jhc, or connect with him on LinkedIn.


Wednesday, August 7, 2013

Amazon Web Service (AWS) - Trusted Internet Connection (TIC) Architecture

I have decided to deviate from my blog series about Non-Technical Cloud Barriers and talk about some of the solution architecture work JHC is performing for our Federal clients moving to Amazon Web Services.  One of the major design hurdles the Federal Government has to take into consideration when moving into the Cloud is how to implement Trusted Internet Connection (TIC).  What is Trusted Internet Connection?  Department of Homeland Security describes TIC as an initiative to:

“…optimize and standardize the security of individual external network connections currently in use by federal agencies, including connections to the Internet. The initiative will improve the federal government's security posture and incident response capability through the reduction and consolidation of external connections and provide enhanced monitoring and situational awareness of external network connections.” (You may also refer to OMB Memorandum M-08-05).  
My understanding is that currently, no public Cloud offerings have the capability/ability to natively provide TIC for their federal clients.  In most cases, internet traffic is routed back to the federal government datacenter and out a TIC router provided by a vendor through the vendor’s Managed Trusted Internet Provider Service (MTIPS).  Currently the following vendors are the only MTIPS providers available under the Networx contract:
  • AT&T
  • CenturyLink (formerly Qwest)
  • Sprint
  • Verizon Business
For Federal Agencies looking to expand and/or move all infrastructure operations into the Cloud, but still need to maintain a physical datacenter to allow for a TIC vendor provided router, it is not cost effective and from a networking prospective it is inefficient.  Using AWS features, JHC has been able to design a TIC solution that removes the requirement for Agencies to have to maintain physical datacenters for TIC compliance while providing a TIC solution that is High Availability and has built-in Disaster Recovery.  Below is a high level overview and sample architecture of the TIC Solution:
  1. Utilize AWS Regions in US East and/or GovGloud
  2. Deploy Virtual Private Cloud (VPC) within the AWS Region and associate subnets across Availability Zones.
  3. Within your VPC deploy EC2 virtual routers and EC2 web content filters across Availability Zones for high availability and disaster recovery.
  4. Establish VPN connection between your agency and EC2 virtual router.
  5. (Optional) for additional high availability and disaster recovery connect your AWS regions via EC2 virtual router and load balance user internet traffic across the US.
  6. Use AWS Direct Connect feature to route your internet traffic to Equinix facility in either Seattle Washington and/or Ashburn, VA utilizing AWS Virtual Private Gateway.
  7. Drop TIC provider router into Equinix and connect AWS Direct Connect Router to TIC Router


James Hirmas is the CEO for JHC Technology.  He can be reached at jhirmas (at) jhctechnology.com,@JHC_JamesHirmas, or connect with him on LinkedIn.

Wednesday, April 24, 2013

AWS Management Console for AWS GovCloud (US), by Jeff Barr (@jeffbarr)

Read Full Article Here: http://aws.typepad.com/aws/2013/04/aws-management-console-for-aws-govcloud-us.html

The AWS GovCloud (US) was built with government customers in mind. It is an isolated AWS Region designed to allow US government agencies and customers to move sensitive workloads into the cloud. AWS GovCloud (US) adheres to US International Traffic in Arms Regulations (ITAR) as well as a variety of other audited and certified compliance regimes (see the AWS Security and Compliance Center for more info).

I'm happy to announce that the AWS Management Console can now be used to manage AWS resources in the AWS GovCloud (US) Region. This instance of the console is separate and distinct from the instance used to manage AWS resources in the public AWS Regions. The UI is the same and all of the functionality is there, but access to the console is restricted and the console works only for AWS GovCloud (US).
The Console in Action at JHC
While working on this post, I spoke to James Hirmas, CEO of JHC Technology, to learn about how his company uses the new console to build and run applications for the US government. James told me that they have been beta testing the console and that they are happy to see it launched. Their federal clients generally run from locked-down desktops and cannot install ElasticWolf or other client-side applications. The new console GUI and the wizards make AWS more accessible to their customers and runs well in government environments.
We also talked about some of the systems and applications that JHC has built for their US government clients. Here's what I learned:
To help transition developers to cloud computing, JHC built a templated development environment that can be launched on-demand. The environment includes Active Directory, SQL Server, Lync, and a set of development tools. By launching copies of this stack as needed, developers can work within a clean, isolated environment. They avoid running out of resources and no longer get in each other's way.
JHC built an AWS-powered source control environment using TeamFoundation and Active Directory. Developers sign in and are connected to the on-demand development environment by means of an RDP session.
They also build public-facing government websites using EC2, Elastic Load Balancing, the Relational Database Service, and S3 (Earlier in his career, James designed and managed the implementation of Recovery.gov, the first AWS-powered federal government website).
Getting Access to the Console
AWS GovCloud (US) accounts can be obtained only by individuals or entities that qualify as U.S. Persons under applicable regulations. To initiate the sign-up process, contact your AWS GovCloud (US) Region Business Representative. You will need to sign the AWS Customer Agreement and the AWS GovCloud (US) Region Addendum.
If you are an AWS GovCloud (US) user and you want to gain access to the new console, please consult the AWS GovCloud (US) User's Guide.
-- Jeff Barr, Amazon Web Services

Tuesday, May 11, 2010

Federal Cloud SharePoint Architecture

Problem: The Federal government and other large organizations (Financial and Medical Markets) want to take advantage of cloud infrastructure as a Service (IAAS). The most mature clouds on the market are Public IAAS providers like Amazon Web Services (AWS); however, due to security concerns and federal compliance requirements these clouds have become difficult to implement for the federal government. Some common reasons why Cloud infrastructure as a Service are difficult to adopt in Federal Government:

1. FISMA Compliant Cloud

2. Risk of failing Certification and Accreditation (C&A) for Low, Moderate, and/or High

3. Security concerns with the hypervisor

4. Pay as you go model for IAAS can be difficult to adopt because Federal Agencies are seeking Firm Fixed price contracts in the traditional RFP process.

I believe the major adoption issue with Cloud IAAS is centered on FISMA compliance and security concerns. A lot of the security concerns around Cloud Computing are not warranted and require agencies to adopt new policies and procedures to handle disruptive technologies. However, the FISMA compliance and data security classification levels are real concerns that public clouds have not been able to address in their current state. So how does the Federal government take advantage of cloud solutions?

Federal Government should take a practical approach to Cloud IAAS. One tactic Federal Agencies can take to make the adoption of IAAS easier is to find projects that deal with public data. Public facing websites are great projects for cloud adoption in the Federal government. Due to the nature of Public facing content, the data classification level for websites are considered low. However, the IAAS Cloud provider would still need to meet Federal FISMA compliance requirements. Cloud providers have been actively moving towards making their technologies and facilities compliant to these standards. Terramark Enterprise Cloud (Private Cloud) is certified for FISMA compliance and has achieved Moderate security level for Certification and Accreditation (C&A). That begin said, Terramark is also up to 10 times more expensive than other Cloud providers like Amazon. So it appears that FISMA compliance and C&A process comes with an expensive price tag. To complicate manners, Federal Agencies want enterprise class website that can provide features like content management, customizable business workflows, and LDAP connection to their directory services. The LDAP connection requires a secure VPN tunnel back to the agencies directory service, to allow agency users to user their credentials to sign into the solution, which raises the security requirements of the IAAS cloud solution. So how do you provide the Federal Government a cost effective Cloud Solution for Public Facing Websites that still meets the Federal compliance standards and technical requirements?

One way to tackle this problem is to provide a best of breed cloud solution that breaks down the security and technical requirements and assess which IAAS provider is appropriate for each aspect of the solution.

Use Case:

Federal Agency wants to migrate their public facing websites to SharePoint 2010 and host SharePoint 2010 on a cloud IAAS provider. The following requirements need to be taken into account:

• Cost effective

• Connect back to the Agencies LDAP environment for user authentication

• Moderate Security Certification and Accreditation

• FISMA Compliance

• Scalable and High Availability

• Disaster Recovery

• Anonymous Access to Public facing website

• Advance Content Deployment scenario with Authoring, Staging, and Production

Solution:

In order to meet the moderate security level, cost, FISMA, and technical requirements, we will use a multi-cloud solution utilizing Terremark enterprise cloud and Amazon Web Service. By separating the environments, the most critical security requirements only apply to areas of the solution that have data accuracy, data timeliness, and LDAP requirements.

Our design recommends to use Amazon Web Services for:

• Approved public content

• Read only copy of web site content

• Removes security model during Content deployment

• Removes user account information during Content deployment

• Anonymous access.

Terremark Enterprise Cloud is FISMA compliant and has obtained a moderate security Certification & Accreditation for multiple government agencies. Therefore, all areas of the solution that require user authentication and content generation will be deployed in Terremark enterprise cloud. However, based on the high cost of the Terremark Cloud solution, we don’t recommend using this environment for the public facing website which does not require the same level of security. Additionally, the Terremark enterprise cloud will have a secure connection to the federal agency’s LDAP.




1. Federal Agency LDAP – The solutions supports connectivity to the Federal Agency LDAP. Agency users will have access to the environment seamlessly using their agency username and password. Content authors will be able to perform user acceptance testing, creating new content, editing existing content, delete content, submit workflows, and approve/reject content. Additionally, the environment will be configured to integrate with LDAP profile data into SharePoint 2010 profile store.


2. Terremark Enterprise Cloud: Terremark private cloud is FISMA compliant and has obtained moderate security Certification and Accreditation.

a. Content Deployment: The solution uses an advance content deployment scenarios utilizing SharePoint 2010. The content deployment, using secure encryption, will deploy approved public content to the Amazon Web Service corresponding nodes. Content is authored in the Authoring Node and deployed to AWS Staging Node. Once content is verified in the Staging Node it is then push to the AWS Production Node. Content deployment jobs will be configured to remove security models and users account information.

3. Amazon Web service (AWS) Public Cloud: AWS delivers a set of services that form a reliable, scalable, and inexpensive computing platform in the cloud. AWS cloud platform will only contain a read only version of the data and will accept content deployment jobs from the Terremark private cloud. Additionally, the solution provides for disaster recovery, high availability, on demand scalability, and anonymous access to public content.

a. Active West Availability Zone: Handles all web traffic for the eastern United States. In the event that the Node fails, users will be redirected to west availability zone.

i. Production Node: The production node contains a highly scalable and elastic SharePoint 2010 solution in the cloud. The production node will be configured to allow anonymous access to public facing websites.

ii. Testing Node: Identical to the Production Node.

b. Active East Availability Zone: Handles all web traffic for the eastern United States. In the event that the Node fails, users will be redirected to west availability zone.

i. Production Node: The production node contains a highly scalable and elastic SharePoint 2010 solution in the cloud. The production node will be configured to allow anonymous access to public facing websites.

ii. Testing Node: Identical to the Production Node.

4. Elastic Load Balancer/DNS Solution: The Elastic Load Balancer/DNS solution distributes the user request between the Amazon Web Services west and east active zones, which creates a highly scalable and optimal SharePoint 2010 solution. If an active zone fails then the elastic load balancer/DNS solution distributes the requests to the other active zone; therefore, the solution provides real time disaster recovery.

5. Content Delivery Network: Delivers applications and Web content quickly and reliably.