Capture appliances
Select a portable, rack-mounted, or virtual packet-capture profile.
Capuris Capture Appliances retain packet-level evidence for troubleshooting, security investigations, and long-running network visibility. The physical range increases capture bandwidth with appliance size. Choose the smallest profile that accommodates measured peak traffic, retention, interface, and resilience requirements with operational headroom.
Deployment profiles
| Model | Format | Published capture profile | Typical use |
|---|---|---|---|
| Capture P1 | Portable | Up to 10 Gbps | Field work, evaluations, and targeted investigations |
| Capture R1 | 1U rack | Up to 40 Gbps | Branch, campus, and data-center capture |
| Capture R2 | 2U rack | Up to 100 Gbps | High-volume capture with greater local retention |
| Capture Virtual | Virtual appliance | Host-dependent | Labs, cloud networks, and software-defined environments |
The published profile is the maximum supported aggregate capture rate for the model, not a per-port guarantee. Final performance depends on the adapter, packet-size distribution, storage layout, filtering, compression, and host design. Treat link rate as an upper bound, not a sizing measurement.
Interface and storage options
Supported physical configurations cover 1, 10, 25, 40, and 100 GbE, with interface speed increasing alongside the model's capture profile.
| Model | Supported interface speeds | Planning limit for capture ports |
|---|---|---|
| Capture P1 | 1 or 10 GbE | Up to two capture ports |
| Capture R1 | 1, 10, 25, or 40 GbE | Up to four at 1/10 GbE or two at 25/40 GbE |
| Capture R2 | 1, 10, 25, 40, or 100 GbE | Up to four at 1/10 GbE or two at higher rate |
Portable P1 systems support RAID 0 or RAID 1 options. R1 and R2 configurations support model-dependent RAID 0 or RAID 10, with R2 providing the largest local-retention profile. Confirm current SKUs, usable capacity, interface combinations, and storage protection with Capuris before purchase or publication.
Capabilities shared across the family
- Sustained recording to local storage with hardware-assisted timestamps.
- Capture filters, packet slicing, file rotation, and standard PCAP output.
- NTP, PTP, and 1PPS time-synchronization options on supported hardware.
- Historical packet search, trace comparison, export, and traffic replay.
- Browser administration through Capuris Control and automation through the Control API.
- Relationship analysis and reporting through Capuris Insight.
Size a deployment
Collect at least one representative traffic sample before selecting hardware. Match the measured peak plus headroom to the lowest published profile that can support it: P1 through 10 Gbps, R1 through 40 Gbps, or R2 through 100 Gbps. Also record:
- sustained and peak throughput at each observation point;
- average packet size and burst behavior;
- interface speed, media, breakout, and transceiver type;
- required hours or days of retention;
- whether full packets, sliced packets, or filtered traffic must be stored;
- redundancy, RAID, rack, power, and remote-management requirements;
- expected search, export, backup, and mirror activity.
Estimate raw retention as average captured bytes per second multiplied by the retention period. Then include headroom for bursts, indexing, filesystem overhead, and operational exports. Compression may reduce storage use, but the result depends on the traffic and should be measured rather than assumed.
Validate the selected system
- Confirm the bill of materials, interface count, optics, storage protection, power, and rack depth.
- Connect BMC and management networks separately from monitored traffic where the design requires it.
- Establish approved time synchronization before collecting incident evidence.
- Verify link state and packet ingress on every capture port.
- Record known traffic at the expected load, search for it, and export a readable PCAP.
- Test retention, backup, restore, and alerting before declaring the system operational.
For installation details, continue with Deployment and quick start.