Skip to content
OBSERVE. ANALYZE. ACT.
Support Login

Advanced NPB / Traffic preparation

Make traffic ready for deeper analysis.

Remove repeated observations, smooth bursts, expose inner traffic, and restore client-address context. Advanced NPB prepares the traffic your monitoring, security, and capture systems receive—with configurable services operated through 01Layer.

Four independent Advanced NPB functions address repeated traffic, short bursts, tunnel feeds, and forwarded client headers. Choose the functions required by the service.
View preparation functions at full size

Reduce redundant work

Remove duplicate observations before they consume tool bandwidth, storage, or analysis resources.

Match receiver needs

Shape burst delivery and remove encapsulation where downstream tools need the inner traffic.

Recover useful context

Use available forwarded-client headers to restore source-address context for analysis.

Choose the preparation the traffic needs

Four functions. Different operational problems.

NPB selects and distributes traffic. Advanced NPB adds processing that prepares it for the next stage. Use a single function or combine the required stages in a NextIO service; the traffic and receiving tools determine the design.

Deduplication

Keep overlapping feeds from multiplying the work

Identify repeated observations using a configured fingerprint and time window. Forward the unique stream and inspect duplicate classifications when needed.

Explore duplicate handling

Microburst Shaper

Control how bursts reach the receiver

Buffer and pace traffic using configured bit-rate and packet-rate limits. Match the service settings to the burst profile and the receiving system.

Explore burst controls

Detunnel

Expose the traffic inside the transport

Remove configured tunnel headers so downstream filtering, capture, or analysis can work with the inner traffic. Use staged processing where multiple layers need removal.

Explore tunnel handling

True IP

Restore client-address context

Use configured HTTP ports and forwarded-client header names to recover source-address context carried through a proxy or translated path.

Explore True IP

Overlapping observation points

Recognize repeated traffic with an explicit matching policy.

The same traffic can arrive through multiple TAP, SPAN, ERSPAN, or mirrored feeds. Deduplication compares configured fingerprints within a bounded time window, so repeated observations can be removed before replication, capture, or tool delivery.

Comparison window
Configure a window from 100 microseconds to 1 second. The documented default is 100 milliseconds; choose the interval for the expected arrival-time difference between observation points.
Fingerprint content
Use selected L2 fields, VLAN context, parsed IP and transport headers, and a configurable amount of payload. Set fallback lengths for unknown EtherTypes or IP protocols.
Expected transit changes
Configure L2, IPv4, and IPv6 ignore fields to account for legitimate differences between observation points. Match the exclusions to the actual traffic path.
State capacity
Size the fingerprint database for the unique-traffic rate and comparison window. Review occupancy, database-full events, malformed traffic, and resource errors.
Unique and duplicate outputs
The primary output carries unique traffic. A connected second output can carry duplicates for inspection; otherwise duplicate traffic is discarded.
Deduplication properties showing time window, fingerprint database size, unique-traffic action, fingerprint method, ignore fields, and payload length.
Deduplication properties from the component manual. View full size.

Receiver-aware delivery

Manage the burst as well as the average rate.

Short bursts can place different demands on a receiver than the average traffic rate suggests. The Microburst Shaper smooths traffic using a configured buffer and maximum egress rates.

Buffer size
Allocate the buffer in megabytes for the expected burst profile.
Maximum bit rate
Set the egress bandwidth limit in megabits per second.
Maximum packet rate
Set the maximum transmit rate in packets per second, accounting for the receiver's processing limits as well as link speed.
Receiver and compute settings
Review receiver PCIe optimization and the compute resources allocated to the component.

Size the buffer and egress limits together, then validate them with representative bursts. Sustained offered traffic still needs to fit the available downstream capacity.

Microburst Shaper reference
Microburst Shaper properties showing buffer size, maximum transmit bit rate and packet rate, receiver PCIe optimization, and compute allocation.
Microburst Shaper settings. Values shown are configuration examples, not platform capacity ratings.

Encapsulation and client identity

Give the next stage the context it expects.

Tunnel transport and proxy paths can change what a monitoring tool sees. Configure the relevant preparation function for the source environment and the form of traffic required downstream.

Detunnel: expose the inner traffic

Remove encapsulation before tools inspect, filter, or capture the original traffic. The Detunnel component exposes operation selection, VxLAN and GTP port settings, configurable header removal, and ERSPAN-related settings.

  • Select the tunnel operation required by the incoming feed.
  • Use consecutive stages when multiple encapsulation layers need removal.
  • Replicate at the appropriate point if both intermediate and fully stripped views are needed.
Detunneling workflow Detunnel component settings

True IP: use forwarded client information

Restore source-address context from client information retained in configured HTTP headers. The reference exposes HTTP ports and header names such as X-Forwarded-For, True-Client-IP, and NS-Client-IP.

  • Set the HTTP ports used by the application path.
  • Match the configured header names to those supplied by the proxy.
  • Review the resulting address context against a representative source trace before applying the service broadly.
True IP component settings

Extend the preparation path when needed.

Related 01Layer workflows include content-based selection and additional header stripping or truncation. Choose these stages according to what the receiving tool or capture workflow needs.

Preparation as a service

Place each function where it adds value.

NextIO lets you connect preparation functions with NPB selection and delivery, capture, metadata, and analysis. The order and branches should reflect the source traffic and what each destination needs.

Save the design, run Verify, then use Start or Apply as appropriate. Review service traffic, logs, counters, and workflow output after the change.

Explore NextIO service design
  1. Identify the traffic condition

    Confirm where overlapping observations, bursts, encapsulation, or proxy headers enter the service.

  2. Select the required stages

    Use only the functions needed for the destination. Decide whether raw, intermediate, unique, or duplicate traffic needs a separate branch.

  3. Configure matching and resources

    Set fingerprint fields and windows, buffer and rate limits, tunnel operations, or HTTP header names for the actual traffic profile.

  4. Validate the prepared output

    Replay or generate representative traffic, inspect the results, and check component errors and receiving-tool behavior before increasing load.

Example preparation patterns
Operational needService approach
Overlapping mirrored feedsConverge the observation feeds into Deduplication, then send the unique stream to capture or NPB distribution. Use the duplicate branch during classification checks.
Remote encapsulated trafficApply the required detunneling stages, then filter or capture the exposed traffic. Retain an intermediate branch if another tool requires that view.
A burst-sensitive receiverPlace Microburst Shaper on the selected delivery path and configure its buffer and egress limits for the destination.
Proxy-facing analysisConfigure True IP for the available forwarded-client headers, then inspect the restored address context in the downstream analysis path.

Scale the processing you need

Add preparation where it fits your architecture.

Advanced NPB is a capability group, not a requirement to deploy a separate appliance. Use supported processing within a FlowMagic service, or use a Service Node when the architecture calls for processing capacity that scales separately from the traffic fabric.

FlowMagic processing services

The FlowMagic NextIO reference documents Deduplication, Microburst Shaper, Detunnel, and True IP. Combine the required functions with NPB, capture, metadata, or analysis in the supported service environment.

Explore FlowMagic

Service Node processing capacity

Service Nodes provide software-defined services that can extend the FlowDirector fabric. The FSN-400 specification includes deduplication, tunnel processing, header transformation, and microburst control; select the model and configuration for your workload.

Review FSN-400 capabilities

Available functions and operating capacity depend on the platform and release. Match processing resources to the traffic mix and the functions enabled together.

Prepare the right traffic for the next decision.

Work with our team to map your traffic conditions, tool requirements, and processing capacity to an Advanced NPB service.

Request Architecture Review