Capture every packet. Miss nothing.
An FPGA-based packet capture, storage and replay appliance. Inline tap or out-of-band (tap / SPAN): it writes 100% of your 10G / 25G traffic straight to PCAP, at line rate, onto up to 32 TB of NVMe.
Sound familiar?
SPAN / mirror drops packets
Mirror ports oversubscribe and drop packets. You lose exactly the moments that matter.
You can't miss a packet
For security investigations and compliance, sampling or gaps simply aren't acceptable.
Big capture rigs are heavy
Rack-mount capture rigs are costly, and they can't travel to the problem.
Microbursts stay invisible
Counters and SNMP miss microsecond bursts, so the root cause stays hidden.
A lossless capture appliance you can carry to the problem
The same hardware works as an inline tap or out-of-band. An FPGA turns every packet into PCAP at line rate and writes it to NVMe: the certainty of dedicated gear, in a size you can carry.
Lossless
100% capture. No oversubscription, no sampling loss.
FPGA line-rate
L2 to L4 filtering and capture in hardware, never bottlenecked by the CPU.
Portable
A 1.8 kg, palm-sized box, for the data center and the field alike.
Two modes, one box.
The same hardware runs as an inline tap or out-of-band, chosen to fit each site.
In the data path
NanoCap sits directly in the data path between two devices. Traffic across a port pair (for example P1 to P2) passes straight through, while a copy of every packet, both directions, is mirrored to the FPGA capture engine and written to NVMe. Forwarding the live link means no mirror oversubscription and no sampling loss.
Zero impact on the link
NanoCap connects to an existing network tap or a switch SPAN / mirror port and captures the copied traffic passively. It is not in the data path, so it has no effect on the monitored link, the preferred mode wherever the link must stay up regardless of the capture unit.
One 4-port unit, two links at once.
Every NanoCap uses the same four-port hardware and acts as two independent inline tap pairs (2×2): P1 + P2 carry link 1 and P3 + P4 carry link 2, full bidirectional visibility on both links at once, lossless up to the model's rated data rate (aggregate).
- Two links, tapped independently
- Full bidirectional capture, simultaneously
- Lossless up to the model's rated aggregate rate
10G/25G ×4 = two independent tap pairs (2×2)
From capture to analysis to replay.
100% capture to PCAP
Optionally encrypted, written to NVMe in RAID0 or RAID5.
Line-rate L2 to L4 filtering
MAC (masking), VLAN (range), IPv4 / IPv6 (masking), TCP / UDP / SCTP ports (range).
Hardware PCAP replay
Replay at line rate; read-back and export to user-defined PCAP file sizes.
Live PCAP stream
Stream to a local or remote analytics tool for real-time analysis.
Microburst detection
Real-time detection, configurable down to 10 µs.
NetFlow & metadata option
1:1 line-rate output into your existing analytics and visibility stack.
From counter-based guessing to complete capture.
Filter L2 to L4 in the FPGA and record just the traffic you need, at line rate, then hand a complete, gap-free original straight to analysis.
Purpose-built: FPGA + NVMe.
A Xilinx Kintex UltraScale+ FPGA, an AMD Ryzen Embedded V3000, up to 96 GB of RAM, and a PCIe-switched NVMe array (RAID0 / RAID5), all in one compact chassis.
System architecture (illustrative)
- Line-rate processing in the FPGA capture engine
- PCIe switch + NVMe array (up to 32 TB)
- Operate and automate via GUI / CLI / REST API
At a glance
A model to fit the job.
| Model | Ports | Data rate | Max. storage |
|---|---|---|---|
| NanoCap20G8T | 4 × 10G | 20 G | 8 TB |
| NanoCap20G16T | 4 × 10G | 20 G | 16 TB |
| NanoCap40G16T | 4 × 10G | 40 G | 16 TB |
| NanoCap40G32T | 4 × 10G | 40 G | 32 TB |
| NanoCap50G16T | 4 × 25G | 50 G | 16 TB |
| NanoCap50G32T | 4 × 25G | 50 G | 32 TB |
| NanoCap100G32T roadmap | 1 × QSFP28 | 100 G | 32 TB |
All models except 100G use the same four-port SFP28 hardware, the 10G models fitted with 10G optics and the 50G model with 25G, differentiated by data rate (aggregate) and storage. Each forms two independent inline tap pairs (2×2); capture is lossless up to the model's rated data rate, and traffic beyond it is dropped. The 100G model (QSFP28) is planned by end of 2026.
From the data center to the field.
Always-on capture in the DC & edge
Record critical links at 100% and rewind to analyze anytime.
On-site troubleshooting
Carry the box to the problem; isolate latency, retransmits, and anomalous flows.
Security & forensics
Preserve a gap-free original and extract evidence; encrypted storage available.
Compliance capture-to-disk
Retain a complete traffic record on up to 32 TB of NVMe.
Microburst & latency analysis
Surface microsecond bursts at 10 µs resolution and pinpoint congestion counters can't see.
Frequently asked questions
Inline tap vs. out-of-band, what is the difference?
Is capture really lossless?
Can captures be encrypted?
Do you support 100G?
Can I use my existing analysis tools?
Bring lossless capture to your network.
Inline or out-of-band, with the FPGA-based NanoCap.