PacketHawk Inline-Bypass Switch & TAP

Highly Available Security Service Chaining

Bypass Network TAP

Inline-Bypass Switching & Network Visibility for Data Center Edge

Assured Continuous Traffic Flow and Complete Inspection Coverage
North–South Visibility I Fail-Safe Bypass I Security Tool Cascading

PacketHawk 10-100G Inline-Bypass Network TAP

PacketHawk is a high-performance inline-bypass switch and network TAP designed to deliver continuous north–south traffic visibility while ensuring uninterrupted operation of inline security and monitoring tools. Supporting 10G, 40G, and 100Gbps environments, PacketHawk sits transparently between production links and inline devices such as IPS, WAF, DDoS, and SSL/TLS platforms—eliminating single points of failure and preserving business continuity. Through intelligent heartbeat monitoring and link-loss detection, PacketHawk automatically bypasses failed or degraded tools in real time, keeping traffic flowing while maintaining service integrity.

Built with a modular, carrier-grade architecture, PacketHawk enables flexible security service chaining, high-availability designs, and load-balanced deployments. Network teams can insert, remove, or upgrade inline devices without downtime, making it ideal for always-on enterprise data centers, telecom environments, and service provider networks. PacketHawk supports multiple operational modes—including inline, bypass, TAP breakout, and TAP aggregation—allowing a single platform to protect inline tools while simultaneously feeding monitoring and analytics systems. Advanced Layer 2–4 filtering further optimizes traffic steering, ensuring critical flows receive inspection while reducing unnecessary load on security appliances.

Designed for operational resilience, PacketHawk combines redundant power, hot-swappable modules, and automated failover with comprehensive management capabilities via web UI, CLI, SNMP, and Syslog. Whether deployed for perimeter security, hybrid visibility, or complex multi-tool service chains, PacketHawk delivers deterministic performance, rapid failover, and complete traffic control—providing the foundation for highly available security architectures and always-on network visibility at scale.

PacketHawk Bypass Network TAP

CONTINUITY

Maintain uninterrupted north–south traffic when inline tools fail or require maintenance. Heartbeat monitoring and link-loss detection trigger automatic bypass, preserving uptime and eliminating single points of failure.

PacketHawk Bypass Network TAP

SERVICE CHAINING

Insert, chain, load-balance, or remove inline security devices without disrupting production traffic. Support active/active and active/standby deployments for flexible multi-tool architectures and deterministic traffic handling.

VISIBILITY

Deliver full traffic access through TAP, breakout, and aggregation modes alongside inline bypass protection. Layer 2–4 filtering steers only relevant flows to tools, preserving performance while ensuring complete north–south visibility.

  • Assure highest availability for security service chaining and inline security devices at the network edge for up to 100Gbps north-south traffic
  • Add or remove security devices for strenthening the security stack, or for maintenance, without any network downtime, guaranteeing business continuity
  • Provision complete north-south network visibility through breakout and aggregated mirroring along with bypass switching
  • Connect network and inline devices for versatile speed of 10, 25, 40, and 100Gbps with up to 2 inline devices per module
  • Use advanced filtering along with multiple operational modes for full control: cascade, high-availability, load balancing, bypass, and visibility modes along with controlled failover conditions
  • High-speed edge connectivity with 10G, 40G, and 100G network, device/tool, and TAP ports in 1RU
  • Line-rate processing and failover of network traffic with up to 100Gbps non-blocking throughput per module, with support for jumbo frames
  • Support for 2 inline security devices on a single network segment
  • Heartbeat packets for network and inline ports health check, speed and duplex monitoring, and fast failover with ICMP, IPX, UDP, TCP (special feature), and firewall support
  • Versatile operation with Service-Chain, High-Availability, Load Balance, Bypass, and Visibility (TAP) modes
  • Visibility TAP mode (Breakout, Aggregation): Net A, Net B traffic any-to-any mapping
  • Flexible operations with 6 bypass modes: Auto, Semi-Auto, Force-Inline, Force-Bypass, Tap-Separate, and Tap-Aggregate
  • Redundant bypass behavior in the event of a bypass TAP/switch failure with Active Bypass or Passive Bypass
  • Supports Mirror mode: mapping of inline-1 to inline-2, inline-2 to inline-1 port traffic
  • Link Loss Detection (LLD) in the event of a network connection failure
  • Link-Drop operation: Inline device failure or network link failure
  • Filtering by inline port IP, port (include or exclude)
  • Traffic auto-refresh statistics per-port: Byte/bps/pps, Uni/Multi/Broadcast packet, packet size, utilization%, Runt/Jumbo packet, CRC error, drop count
  • Versatile management options (CLI, SSH, SNMP v2/v3, NTP, Web UI, NETCONF, and REST API) with logging through Syslog and SNMP traps
  • RADIUS, TACACS+, and LDAP
  • Support for ACL (Access Control List) policies for the management port
  • Digital Diagnostics Monitoring (DDM)
  • Configuration export/import option
  • Hot-swappable redundant power supplies & fan modules
PACKETHAWK CHASSIS
SKU Description
 NX-PH-BS-CH Chassis for up to 2 modules
PACKETHAWK MODULES
SKUDescriptionModules
 NX-PH-BS-M10S1/10 Gigabit Multimode Bypass TAP I/F module (SR)
View

 NX-PH-BS-M10L
1/10 Gigabit Singlemode Bypass TAP I/F module (LR)
View
 NX-PH-BS-M40S40 Gigabit Multimode Bypass TAP I/F module (SR4)
View

 NX-PH-BS-M40L
40 Gigabit Singlemode Bypass TAP I/F module (LR4)
View
 NX-PH-BS-M100S40/100 Gigabit Multimode Bypass TAP I/F module (SR4)
View
 NX-PH-BS-M100L40/100 Gigabit Singlemode Bypass TAP I/F module (LR4)
View
PacketHawk

FEATURED RESOURCES

Network Visibility for Our Customers

infographic network-tap

Infographic

Why You Need a Network Tap

White Paper

White Paper

Network Tap vs SPAN/Mirror Port

Packet Capture Appliance

Product Brochure

A Complete Guide to Products

Deployment

SERVICE & SUPPORT

Unparalleled Multi-Level Service & Support for Peace of Mind

All NEOXPacketHawk Bypass Switches come with NEOX SILVER Support and can be upgraded to GOLD Support for advanced replacement in case of a hardware failure.