Skip to content
← Products

Capture every packet. Miss nothing.

An FPGA-based packet capture, storage and replay appliance. Inline tap or out-of-band (tap / SPAN): it writes 100% of your 10G / 25G traffic straight to PCAP, at line rate, onto up to 32 TB of NVMe.

NanoCap40G16T front panel
Mode
Inline tap
Links
10/25G ×4
Captured
100%
Dropped
0
The problem

Sound familiar?

SPAN / mirror drops packets

Mirror ports oversubscribe and drop packets. You lose exactly the moments that matter.

You can't miss a packet

For security investigations and compliance, sampling or gaps simply aren't acceptable.

Big capture rigs are heavy

Rack-mount capture rigs are costly, and they can't travel to the problem.

Microbursts stay invisible

Counters and SNMP miss microsecond bursts, so the root cause stays hidden.

What is NanoCap?

A lossless capture appliance you can carry to the problem

The same hardware works as an inline tap or out-of-band. An FPGA turns every packet into PCAP at line rate and writes it to NVMe: the certainty of dedicated gear, in a size you can carry.

Lossless

100% capture. No oversubscription, no sampling loss.

FPGA line-rate

L2 to L4 filtering and capture in hardware, never bottlenecked by the CPU.

Portable

A 1.8 kg, palm-sized box, for the data center and the field alike.

Deployment modes

Two modes, one box.

The same hardware runs as an inline tap or out-of-band, chosen to fit each site.

Inline tap (active)

In the data path

NanoCap sits directly in the data path between two devices. Traffic across a port pair (for example P1 to P2) passes straight through, while a copy of every packet, both directions, is mirrored to the FPGA capture engine and written to NVMe. Forwarding the live link means no mirror oversubscription and no sampling loss.

Out-of-band (tap / SPAN)

Zero impact on the link

NanoCap connects to an existing network tap or a switch SPAN / mirror port and captures the copied traffic passively. It is not in the data path, so it has no effect on the monitored link, the preferred mode wherever the link must stay up regardless of the capture unit.

Technical note: Inline mode is fail-closed. As an active inline device with no passive bypass relay, a paired set of ports forwards traffic only while the unit is powered; if power is lost, that link goes down. Use inline on links where a brief outage is tolerable, or add an external bypass switch. Out-of-band mode has no such dependency.
Key features

From capture to analysis to replay.

100% capture to PCAP

Optionally encrypted, written to NVMe in RAID0 or RAID5.

Line-rate L2 to L4 filtering

MAC (masking), VLAN (range), IPv4 / IPv6 (masking), TCP / UDP / SCTP ports (range).

Hardware PCAP replay

Replay at line rate; read-back and export to user-defined PCAP file sizes.

Live PCAP stream

Stream to a local or remote analytics tool for real-time analysis.

Microburst detection

Real-time detection, configurable down to 10 µs.

NetFlow & metadata option

1:1 line-rate output into your existing analytics and visibility stack.

Lossless by design

From counter-based guessing to complete capture.

100%
Capture rate
10 µs
Microburst resolution
32 TB
NVMe storage

Filter L2 to L4 in the FPGA and record just the traffic you need, at line rate, then hand a complete, gap-free original straight to analysis.

Inside

Purpose-built: FPGA + NVMe.

A Xilinx Kintex UltraScale+ FPGA, an AMD Ryzen Embedded V3000, up to 96 GB of RAM, and a PCIe-switched NVMe array (RAID0 / RAID5), all in one compact chassis.

Capture ports SFP / SFP+ / SFP28
FPGA capture engine
NVMe array RAID0 / RAID5
CPU AMD Ryzen Embedded V3000
Mgmt / export 1G / 10G

System architecture (illustrative)

  • Line-rate processing in the FPGA capture engine
  • PCIe switch + NVMe array (up to 32 TB)
  • Operate and automate via GUI / CLI / REST API
Specifications

At a glance

Links
4 × SFP28 (10G / 25G) / 100G (QSFP28) on the roadmap
Management / export
1G / 10G
Timestamping
GPS (within 20 ns RMS accuracy) or NTP
Storage
Up to 32 TB NVMe (RAID0 / RAID5)
FPGA
Xilinx Kintex UltraScale+
CPU
AMD Ryzen Embedded V3000
System RAM
Up to 96 GB
Power supply
12 V DC, 15 A
Dimensions
8″ (W) × 7.5″ (D) × 1.75″ (H)
Weight
4 lb (1.8 kg)
Operating system
Linux
Interfaces
GUI / CLI / REST API
Model lineup

A model to fit the job.

ModelPortsData rateMax. storage
NanoCap20G8T 4 × 10G 20 G 8 TB
NanoCap20G16T 4 × 10G 20 G 16 TB
NanoCap40G16T 4 × 10G 40 G 16 TB
NanoCap40G32T 4 × 10G 40 G 32 TB
NanoCap50G16T 4 × 25G 50 G 16 TB
NanoCap50G32T 4 × 25G 50 G 32 TB
NanoCap100G32T roadmap 1 × QSFP28 100 G 32 TB

All models except 100G use the same four-port SFP28 hardware, the 10G models fitted with 10G optics and the 50G model with 25G, differentiated by data rate (aggregate) and storage. Each forms two independent inline tap pairs (2×2); capture is lossless up to the model's rated data rate, and traffic beyond it is dropped. The 100G model (QSFP28) is planned by end of 2026.

Where it fits

From the data center to the field.

Always-on capture in the DC & edge

Record critical links at 100% and rewind to analyze anytime.

On-site troubleshooting

Carry the box to the problem; isolate latency, retransmits, and anomalous flows.

Security & forensics

Preserve a gap-free original and extract evidence; encrypted storage available.

Compliance capture-to-disk

Retain a complete traffic record on up to 32 TB of NVMe.

Microburst & latency analysis

Surface microsecond bursts at 10 µs resolution and pinpoint congestion counters can't see.

FAQ

Frequently asked questions

Inline tap vs. out-of-band, what is the difference?
Inline sits in the data path, forwarding traffic while copying every packet to disk (no mirror oversubscription). Out-of-band taps an existing TAP or SPAN / mirror port passively, with no effect on the monitored link. The same hardware supports both.
Is capture really lossless?
Yes. Within each model's rated data rate (aggregate), the FPGA captures at line rate and writes 100% of traffic to PCAP on NVMe, with no sampling and no mirror-oversubscription loss. All models share the same four-port hardware, rated at 20G / 40G / 50G (or 100G on the 100G model); traffic beyond the rating is dropped.
Can captures be encrypted?
Yes. PCAP can be stored optionally encrypted, on storage configured as RAID0 or RAID5.
Do you support 100G?
Current models support 10G / 25G. 100G (QSFP28, NanoCap100G32T) is planned by end of 2026, contact us about availability and timing.
Can I use my existing analysis tools?
Yes. It records standard PCAP, so your existing tools (e.g. Wireshark) work as-is. A live PCAP stream feeds local or remote analytics in real time, and NetFlow output is available as an option.

Bring lossless capture to your network.

Inline or out-of-band, with the FPGA-based NanoCap.