Skip to content
OBSERVE. ANALYZE. ACT.
Support Login

NPB / Network Packet Brokering

Deliver the traffic your tools need.

Bring monitoring feeds together, select relevant traffic, and distribute it across security, monitoring, and capture systems. 01Layer connects aggregation, filtering, replication, and load balancing in one service design and operating environment.

NPB collects physical and virtual monitoring feeds and uses aggregation, filtering, replication, and load balancing to deliver traffic to selected tools.
View delivery model at full size

Connect the observation points

Consolidate traffic from multiple inputs into the service paths that need it.

Focus each tool

Select relevant traffic and define what each destination receives.

Expand delivery capacity

Distribute streams across output groups and add parallel tool or capture branches.

Traffic selection and distribution

Build the delivery path around the tools.

NPB functions determine which sources feed a service, what traffic continues, and how it reaches the destinations. Connect the required components in NextIO, then configure the rules and output relationships.

Aggregate

Bring multiple feeds together

Combine ingress sources into one stream for shared filtering, processing, capture, or tool delivery. Place common downstream functions after the aggregation point.

Aggregation workflow

Filter

Select the relevant traffic

Match traffic using the fields supported by the target platform and associate rules with forwarding or drop actions. Apply selection before shared processing or at an output.

Filter component reference

Replicate

Feed parallel destinations

Create multiple copies of a stream so separate monitoring, security, or capture paths can receive the same source traffic. Define the required branches and replication settings.

Replication workflow

Load balance

Share traffic across a tool group

Distribute traffic across multiple outputs using the selected symmetric hash method. Configure the participating ports and check the receiving capacity of each tool.

Load Balancer reference

Mirror

Create an observation feed

The FlowDirector SPAN component copies selected ingress or egress traffic to a destination. Its settings include optional ERSPAN transport, VLAN handling, and truncation.

SPAN component reference

Map

Manage multiple service paths

FlowMagic Multiplexer and Traffic Matrix components define input-to-output relationships. Configure mappings and, where used, the associated active and standby HA settings.

Traffic Matrix reference

Need traffic preparation as well? Add Advanced NPB functions for deduplication, burst shaping, detunneling, or client-address restoration before downstream delivery.

Copies and shared capacity

Choose what each destination receives.

Replication and load balancing serve different delivery needs. Use the appropriate pattern for independent tools, a group of equivalent receivers, or both.

Replication: a copy for each branch

Send the same selected stream to multiple destinations. For example, a security inspection path and a capture path can each receive the traffic they need from one replication point.

  • Each connected branch receives a copy of the upstream stream.
  • Branches can have their own filtering or processing stages.
  • Account for the traffic volume on every output path.

Load balancing: a share for each member

Distribute a stream across receivers that share the monitoring workload. The selected symmetric hash method provides flow-affine selection so both directions of a flow remain together.

  • Each member receives the traffic assigned by the selection method.
  • Choose hash fields that fit the traffic and analysis requirements.
  • Review distribution and receiver capacity under representative load.

Combine both with FlowDirector LB Groups. Replicate traffic to multiple groups, then load balance within each group. This supports separate tool groups that each need visibility of the selected stream.

A visible service definition

Connect sources, rules, and outputs in NextIO.

The Diagram Editor keeps the traffic path and component settings together in a saved .nio design. The documented example connects an input-port group to a load balancer and multiple output paths.

NextIO Diagram Editor showing an input-port group feeding a load balancer in the LB to Ports example service.
The agg-lb-example.nio design from the editor guide. View full-size screenshot.
  1. Select sources and destinations

    Choose the input and output components for the product family, then connect the ports, groups, or service endpoints.

  2. Define selection and distribution

    Add filter rules, replication branches, load-balancing methods, or matrix mappings. Changing component output counts can change the available connectors.

  3. Verify the design

    Save and Verify after editing properties or wiring. Use Start for a stopped service or Apply to update a running service with the saved design.

  4. Check the receiving tools

    Confirm traffic selection, flow distribution, and volume at the destinations before expanding the service.

Match the delivery and processing needs

A service capability across the portfolio.

NPB describes the traffic-handling functions. Choose a deployment for the port capacity, processing, and downstream services you need. Each product can stand on its own; combine platforms when the requirements call for it.

FlowDirector traffic fabric

Use the dedicated lossless fabric for traffic delivery, with documented filtering, aggregation, replication, load balancing, LB Groups, egress filtering, and SPAN functions.

Explore FlowDirector

Service Node processing

Add software-defined traffic services and scale processing separately from the fabric. Select the Service Node model and functions for the intended delivery and preparation workload.

Explore Service Node

FlowMagic service paths

Combine NPB functions with capture, metadata, and analysis services. The FlowMagic palette includes Multiplexer, Traffic Matrix, Filter, Aggregator, Replicator, and Load Balancer.

Explore FlowMagic

The component palette, settings, and capacity depend on the product and release. The FlowDirector and FlowMagic references document the family-specific controls.

Keep the delivery path accountable

Follow the traffic from design to destination.

NextIO Services connects the saved design with runtime state, traffic, counters, logs, and workflow-backed actions. Use these views to confirm the intended service behavior and investigate exceptions.

What to verify in an NPB service
AreaOperating check
Selection rulesReview the configured rule actions and available counters. FlowDirector Filter starts with Pass All; Port Egress Filter starts with Drop All, so configure each for its intended purpose.
Output relationshipsConfirm replication branches, load-balancing members, and matrix mappings match the receivers that should see the traffic.
Traffic and capacityReview ingress and egress throughput, errors, and drops over the relevant time window; confirm the assigned load at the receiving tools.
Changes and failuresSave and Verify before runtime changes. Saving alone does not update a running service. Inspect Activity Monitor workflow traces if Start or Apply fails.

Connect your visibility requirements.

Work with our team to map your observation points, tool groups, and traffic volumes to the right delivery architecture.

Request Architecture Review