|
Memory
VSS monitoring Aggregation Taps are the only aggregation taps designed to be independent of Switch technology and therefore are not limited in memory. Switch chips built into the design of other vendor aggregation taps typically have either no memory or approx 2MB per channel. This means packets are almost instantly dropped the moment utilization on the network exceeds 50% on either link.
As VSS monitoring uses FPGA and not switches in its designs, each product capacity to aggregate large traffic bursts does not have this memory limitation. Instead VSS monitoring Aggregation Taps provide up to 64MB (512Mb) of memory to ensure the highest rate of packet capture and monitoring throughput for all heavily utilized and critical networks.
Preservation of Packet Order
VSS monitoring guarantees the preservation
of original packet order during the aggregation process.
This ensures that any IDS or Analyzer receives the aggregated
traffic in the same order as the packets occur on the
network. Not receiving the traffic in correct order
makes it very difficult to recreate the session and/or
detect for anomalies during a security analysis.
While other vendor Taps simply aggregate data in FIFO
order as packets are received from the network the limitations
of their technology induce a failure as packets of unequal
length are received on different streams. Consider an
example where a Tap has 2 inputs and 1 aggregated output.
On input 1 the tap receives a large packet (1000 Bytes).
On Input 2 several smaller packets are received (64
Bytes). The switch chips used by other tap vendors FIFO
the input streams based on the packets being received
in whole. In this case we can see that all packets on
input 2 are passed on to the monitoring stream before
input 1, despite the packet on input 1 occurring on
the network first. Hence non VSS monitoring devices
cannot always preserve the original packet order.
In contrast VSS monitoring does not employ ff the shelf?switches
but instead uses FPGA for the aggregation process and
thereby time stamps the incoming packet on each input
in real time. The monitoring stream is thus made up
of the inputs based upon their entry time-stamp which
of course is removed before exiting the tap in real
time.
This therefore preserves the true order and sequence
of network traffic making the data interpretation process
seamless for the user. This differentiating factor between
VSS monitoring and other brands is a major feature users
appreciate during analysis.
Multiple Monitoring Ports
VSS monitoring Aggregation Taps
are the only Taps available that combine aggregation
and non aggregation ports on a single device. As the
aggregation process can sometimes drop packets during
peak flow rates VSS monitoring series of Aggregation
Taps (that include the products: V1.3CCE-A, V1.3CCE-IS,
V6.3CCE-AS, V12.3CCE-AS) ensure that no packets need
be lost.
In having both Aggregation and non aggregation monitoring
ports the user can use the Tap for both maximum and
non-maximum bandwidth utilization monitoring. In this
way the Tap is suitable for monitoring at all levels
of network utilization.
|