Selection & Interfaces

Chapter 5 — Core product lineup, selection criteria, interface specifications, and integration capabilities

5.1 Core Product Lineup

The NTA/AD product ecosystem consists of three primary hardware platforms — the NTA-2000 Series Sensor, the NTA-5000 Series Analytics Platform, and the PCAP-Store 100T storage appliance — plus a software-only deployment option for virtualized and cloud environments. Each platform is optimized for a specific role in the overall architecture, and they are designed to work together as an integrated system. The photograph below shows the three hardware platforms in their standard rack-mount form factors.

NTA/AD Core Product Lineup
Figure 5.1: NTA/AD core product lineup — NTA-2000 Series Sensor (1U, 10 Gbps), NTA-5000 Series Platform (2U, 100 Gbps), and PCAP-Store 100T storage appliance (4U, 100 TB).

5.1.1 Core Product Feature Comparison

The table below provides a comprehensive feature comparison across all four deployment options, covering hardware specifications, telemetry capabilities, detection features, and integration interfaces. This table is the primary reference for solution package selection.

Feature / Specification NTA-2000 Sensor NTA-5000 Platform PCAP-Store 100T Virtual/Cloud Edition
Hardware Specifications
Form Factor 1U Rack-mount 2U Rack-mount 4U Rack-mount VM / Container
Monitoring Throughput Up to 10 Gbps Up to 100 Gbps N/A (storage only) Up to 10 Gbps (vCPU-dependent)
Monitoring Ports 4x 10GbE + 2x SFP+ 8x 10GbE + 4x 100GbE QSFP28 2x 10GbE (data) Virtual NIC (any speed)
Management Ports 2x 1GbE + Console + IPMI 2x 1GbE + Console + IPMI 2x 1GbE + Console + IPMI Virtual management interface
Internal Storage 2x 960GB SSD (OS + metadata) 4x 1.92TB SSD (hot) + 12x 8TB HDD 24x 8TB HDD (RAID 6) Configurable (external storage)
RAM 64 GB DDR4 ECC 256 GB DDR4 ECC 32 GB DDR4 ECC 32–256 GB (configurable)
CPU 2x Intel Xeon Silver 4314 2x Intel Xeon Gold 6330 1x Intel Xeon Silver 4310 8–64 vCPUs
Power Supply Dual 550W redundant Dual 1200W redundant Dual 800W redundant N/A
Telemetry Capabilities
NetFlow v5/v9/IPFIX ✓ Collector ✓ Collector + Exporter — N/A ✓ Collector
sFlow ✓ Collector ✓ Collector — N/A ✓ Collector
Full Packet Capture (PCAP) ✓ Up to 10 Gbps ✓ Up to 40 Gbps ✓ Storage backend Optional (storage-dependent)
DNS Log Collection ✓ Passive + Syslog ✓ Passive + Syslog + API — N/A ✓ Syslog + API
TLS Fingerprinting (JA3/JA4) — N/A
Cloud VPC Flow Logs — Not applicable ✓ AWS/Azure/GCP — N/A ✓ Native cloud API
Detection Capabilities
Behavioral Baseline / ML Anomaly Detection Optional (requires platform) ✓ Built-in ML engine — N/A ✓ Cloud ML inference
Signature-based Detection (IDS rules) ✓ Suricata-compatible ✓ Suricata + custom — N/A ✓ Suricata-compatible
Threat Intelligence Integration ✓ STIX/TAXII ✓ STIX/TAXII + commercial feeds — N/A ✓ STIX/TAXII
Encrypted Traffic Analysis (ETA) Basic (JA3 only) ✓ Full ETA with ML — N/A Basic (JA3/JA4)
Integration Interfaces
SIEM Integration ✓ CEF/LEEF/JSON syslog ✓ CEF/LEEF/JSON/REST API — N/A ✓ CEF/LEEF/JSON syslog
SOAR Integration Via platform ✓ REST API webhooks — N/A ✓ REST API webhooks
REST API ✓ HTTPS 443 ✓ HTTPS 443 (full) ✓ HTTPS 443 (storage mgmt) ✓ HTTPS 443

Legend: ✓ = Supported  |  Optional = Available as add-on  |  — = Not applicable

5.2 Interface Logic and Integration Architecture

The interface logic diagram below provides a comprehensive view of all data ingestion interfaces, management interfaces, integration outputs, and storage interfaces supported by the NTA/AD Analytics Platform. This diagram serves as the definitive reference for integration planning, firewall rule configuration, and API development.

NTA/AD Analytics Platform Interface Logic Diagram
Figure 5.2: NTA/AD Analytics Platform interface logic diagram showing all data ingestion, management, integration output, and storage interfaces with protocol specifications and port numbers.

5.2.1 Data Ingestion Interface Specifications

The following table details the technical specifications for each data ingestion interface, including the protocol, transport, port, authentication method, and maximum ingestion rate. These specifications must be used when configuring network devices to export telemetry and when sizing network bandwidth for telemetry transport.

Interface Protocol Transport Port Auth Max Rate
NetFlow v5 NetFlow v5 UDP 2055 Source IP allowlist 500K flows/sec
NetFlow v9 NetFlow v9 UDP 2055 Source IP allowlist 500K flows/sec
IPFIX IPFIX (RFC 7011) UDP / TCP / SCTP 4739 Source IP allowlist 1M flows/sec
sFlow sFlow v5 UDP 6343 Source IP allowlist 200K samples/sec
PCAP (TAP) Raw Ethernet frames Physical (monitoring port) N/A Physical access control 10–100 Gbps per port
DNS Syslog Syslog (RFC 5424) UDP / TCP / TLS 514 / 6514 TLS mutual auth (optional) 100K events/sec
Cloud VPC Flow Logs REST API (cloud-native) HTTPS 443 Cloud IAM / API key API rate limit dependent

5.3 Selection Criteria and Sizing Guidelines

Selecting the appropriate product configuration requires evaluating four primary dimensions: peak monitoring throughput, required telemetry types, PCAP storage capacity, and analytics processing requirements. The sizing methodology starts with traffic measurement at each observation point, then applies a growth factor for future capacity, and finally maps the resulting requirements to the appropriate product platform.

Requirement < 1 Gbps 1–10 Gbps 10–40 Gbps > 40 Gbps
Recommended Sensor Virtual Edition or NTA-2000 NTA-2000 Series NTA-5000 Series NTA-5000 Cluster
Flow Storage (90 days) ~500 GB ~2 TB ~8 TB ~30 TB+
PCAP Storage (7 days) ~5 TB ~50 TB ~200 TB Not recommended (selective PCAP only)
Analytics Nodes 1 (virtual or physical) 1x NTA-5000 1x NTA-5000 + storage NTA-5000 cluster (2–4 nodes)