We are developing a service to help customers monitor and manage networked devices with built-in web servers (i.e. printers, cameras) located in multiple sites from a single interface. We also help them with setting up of VPNs to secure and inter-connect their sites over internet. Previously we've used local server hardware at each client site, but now we want to migrate our concept to a cloud platform (AWS or Azure).
We have IT-technicians in-house, but lack the necessary knowledge about AWS and Azure to know which one is the right choice for us and how to best set up a secure, robust and scalable infrastructure that can support multiple (up to hundreds) clients, each managing their own (secured) network with site-to-site VPNs to several (up to hundred or more) hardware VPN-routers with existing web-servers behind that should be accessible through client-specific reverse proxies.
The desired setup is explained by the attached wireframe and we would like the platform to run in a datacenter within the EU.
We want the bidders to propose a solution to us by providing some simple schematics together with a quote for the operation costs for the proposed solution (including network VPN-traffics) and the bidders quote to set up the proposed solution, including the commissioning of the virtual machines (we install the softwares ourselves) and the necessary configuration of the networking, security policies, VPN-gateways, IP-tables and routes (please explain what is included and excluded from your quotes). The winner (providing the best concept, not necessarily the cheapest one) will get payed guide our technicians with the set-up according to the quote.
The project includes the setup of central resources AND two separate client environments. We will use 4 hardware VPN-routers (ZyXEL ZyWALL USG 20 or similar) that you have to configure to simulate 2 separate clients having 2 sites each (2 site-to-site IPSec VPNs to each of the 2 client VPN-gateways).
We would like to follow each step of the job (i.e. using Teamviewer or equivalent) to learn how the work is done, so that we can manage the infrastructure ourselves. If we work well together, then we might want to hire you for more assignments as we grow.
We will escrow the project amount and release it according to the following milestones:
20 % upon start
30 % upon completion of the cloud setup, including the VPN-gateway and reverse proxy for one client
20 % upon completion of both client VPN-setups (including the hardware VPN-routers)
30 % upon successful tests to and from the client VPN-routers and verification of the setup security and client VPN (and resources) integrity = project completed!