DocsGet started

Capture appliances

Select a portable, rack-mounted, or virtual packet-capture profile.

Capuris Capture Appliances retain packet-level evidence for troubleshooting, security investigations, and long-running network visibility. The physical range increases capture bandwidth with appliance size. Choose the smallest profile that accommodates measured peak traffic, retention, interface, and resilience requirements with operational headroom.

Deployment profiles

ModelFormatPublished capture profileTypical use
Capture P1PortableUp to 10 GbpsField work, evaluations, and targeted investigations
Capture R11U rackUp to 40 GbpsBranch, campus, and data-center capture
Capture R22U rackUp to 100 GbpsHigh-volume capture with greater local retention
Capture VirtualVirtual applianceHost-dependentLabs, cloud networks, and software-defined environments

The published profile is the maximum supported aggregate capture rate for the model, not a per-port guarantee. Final performance depends on the adapter, packet-size distribution, storage layout, filtering, compression, and host design. Treat link rate as an upper bound, not a sizing measurement.

Interface and storage options

Supported physical configurations cover 1, 10, 25, 40, and 100 GbE, with interface speed increasing alongside the model's capture profile.

ModelSupported interface speedsPlanning limit for capture ports
Capture P11 or 10 GbEUp to two capture ports
Capture R11, 10, 25, or 40 GbEUp to four at 1/10 GbE or two at 25/40 GbE
Capture R21, 10, 25, 40, or 100 GbEUp to four at 1/10 GbE or two at higher rate

Portable P1 systems support RAID 0 or RAID 1 options. R1 and R2 configurations support model-dependent RAID 0 or RAID 10, with R2 providing the largest local-retention profile. Confirm current SKUs, usable capacity, interface combinations, and storage protection with Capuris before purchase or publication.

Capabilities shared across the family

  • Sustained recording to local storage with hardware-assisted timestamps.
  • Capture filters, packet slicing, file rotation, and standard PCAP output.
  • NTP, PTP, and 1PPS time-synchronization options on supported hardware.
  • Historical packet search, trace comparison, export, and traffic replay.
  • Browser administration through Capuris Control and automation through the Control API.
  • Relationship analysis and reporting through Capuris Insight.

Size a deployment

Collect at least one representative traffic sample before selecting hardware. Match the measured peak plus headroom to the lowest published profile that can support it: P1 through 10 Gbps, R1 through 40 Gbps, or R2 through 100 Gbps. Also record:

  • sustained and peak throughput at each observation point;
  • average packet size and burst behavior;
  • interface speed, media, breakout, and transceiver type;
  • required hours or days of retention;
  • whether full packets, sliced packets, or filtered traffic must be stored;
  • redundancy, RAID, rack, power, and remote-management requirements;
  • expected search, export, backup, and mirror activity.

Estimate raw retention as average captured bytes per second multiplied by the retention period. Then include headroom for bursts, indexing, filesystem overhead, and operational exports. Compression may reduce storage use, but the result depends on the traffic and should be measured rather than assumed.

Validate the selected system

  1. Confirm the bill of materials, interface count, optics, storage protection, power, and rack depth.
  2. Connect BMC and management networks separately from monitored traffic where the design requires it.
  3. Establish approved time synchronization before collecting incident evidence.
  4. Verify link state and packet ingress on every capture port.
  5. Record known traffic at the expected load, search for it, and export a readable PCAP.
  6. Test retention, backup, restore, and alerting before declaring the system operational.

For installation details, continue with Deployment and quick start.