This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Packet Capture Appliance Server

0

I'm wondering if anyone on this board has experience to recommend (or not) a dedicated packet capture appliance. The goal would be to separate the idea of packet analysers/probes from the time-sensitive capture process itself, such that mirrors or a tap network would feed a central "packet capture appliance", and that system would make resulting packet capture files available to remote servers for analysis (be it wireshark, snort, etc.).

A short list of things that such a system would need to do well:

  • Record timestamps very accurately, preferably with nanosecond precision.
  • Write captures to disk very rapidly, such that several Gbps of payload on incoming interfaces would not exceed the rate at which capture data can be stored.
  • Disk capacity would need to be a lot, and ideally would be redundant/recoverable.
  • Ideally, the ability to sort/organize capture data based on app-level criteria would help (allowing some of this type of responsibilty to be offloaded from probes).
  • Ideally, the ability to host packet captures to remote Wireshark clients (via the GUI "remote interface").
  • Should to be rack-mountable (no need for portability).

While an off-the-shelf server can do most of this, I also know that a few vendors have dedicated appliances tailored to some of these kinds of capture-specific requirements. So, my overall question here is, do people here have any good/bad experience to share about such appliances? In such a niche space, are there any that particularly stand out? Realizing it isn't directly a Wireshark tool question, I'm not sure if there is a better place where such a question would be asked.

asked 24 Feb '16, 14:38

Quadratic's gravatar image

Quadratic
1.9k6928
accept rate: 13%

if you send me an email creusch[at]crnetworks.de I can provide you my experience

(25 Feb '16, 09:16) Christian_R

One Answer:

1

I can recommend the NetShark appliances (hardware as well as virtual) from Riverbed.

answered 25 Feb '16, 01:35

Uli's gravatar image

Uli
9031515
accept rate: 29%