Selection & Interfaces
5.1 Core Product Lineup
The NTA/AD product ecosystem consists of three primary hardware platforms — the NTA-2000 Series Sensor, the NTA-5000 Series Analytics Platform, and the PCAP-Store 100T storage appliance — plus a software-only deployment option for virtualized and cloud environments. Each platform is optimized for a specific role in the overall architecture, and they are designed to work together as an integrated system. The photograph below shows the three hardware platforms in their standard rack-mount form factors.
5.1.1 Core Product Feature Comparison
The table below provides a comprehensive feature comparison across all four deployment options, covering hardware specifications, telemetry capabilities, detection features, and integration interfaces. This table is the primary reference for solution package selection.
| Feature / Specification | NTA-2000 Sensor | NTA-5000 Platform | PCAP-Store 100T | Virtual/Cloud Edition |
|---|---|---|---|---|
| Hardware Specifications | ||||
| Form Factor | 1U Rack-mount | 2U Rack-mount | 4U Rack-mount | VM / Container |
| Monitoring Throughput | Up to 10 Gbps | Up to 100 Gbps | N/A (storage only) | Up to 10 Gbps (vCPU-dependent) |
| Monitoring Ports | 4x 10GbE + 2x SFP+ | 8x 10GbE + 4x 100GbE QSFP28 | 2x 10GbE (data) | Virtual NIC (any speed) |
| Management Ports | 2x 1GbE + Console + IPMI | 2x 1GbE + Console + IPMI | 2x 1GbE + Console + IPMI | Virtual management interface |
| Internal Storage | 2x 960GB SSD (OS + metadata) | 4x 1.92TB SSD (hot) + 12x 8TB HDD | 24x 8TB HDD (RAID 6) | Configurable (external storage) |
| RAM | 64 GB DDR4 ECC | 256 GB DDR4 ECC | 32 GB DDR4 ECC | 32–256 GB (configurable) |
| CPU | 2x Intel Xeon Silver 4314 | 2x Intel Xeon Gold 6330 | 1x Intel Xeon Silver 4310 | 8–64 vCPUs |
| Power Supply | Dual 550W redundant | Dual 1200W redundant | Dual 800W redundant | N/A |
| Telemetry Capabilities | ||||
| NetFlow v5/v9/IPFIX | ✓ Collector | ✓ Collector + Exporter | — N/A | ✓ Collector |
| sFlow | ✓ Collector | ✓ Collector | — N/A | ✓ Collector |
| Full Packet Capture (PCAP) | ✓ Up to 10 Gbps | ✓ Up to 40 Gbps | ✓ Storage backend | Optional (storage-dependent) |
| DNS Log Collection | ✓ Passive + Syslog | ✓ Passive + Syslog + API | — N/A | ✓ Syslog + API |
| TLS Fingerprinting (JA3/JA4) | ✓ | ✓ | — N/A | ✓ |
| Cloud VPC Flow Logs | — Not applicable | ✓ AWS/Azure/GCP | — N/A | ✓ Native cloud API |
| Detection Capabilities | ||||
| Behavioral Baseline / ML Anomaly Detection | Optional (requires platform) | ✓ Built-in ML engine | — N/A | ✓ Cloud ML inference |
| Signature-based Detection (IDS rules) | ✓ Suricata-compatible | ✓ Suricata + custom | — N/A | ✓ Suricata-compatible |
| Threat Intelligence Integration | ✓ STIX/TAXII | ✓ STIX/TAXII + commercial feeds | — N/A | ✓ STIX/TAXII |
| Encrypted Traffic Analysis (ETA) | Basic (JA3 only) | ✓ Full ETA with ML | — N/A | Basic (JA3/JA4) |
| Integration Interfaces | ||||
| SIEM Integration | ✓ CEF/LEEF/JSON syslog | ✓ CEF/LEEF/JSON/REST API | — N/A | ✓ CEF/LEEF/JSON syslog |
| SOAR Integration | Via platform | ✓ REST API webhooks | — N/A | ✓ REST API webhooks |
| REST API | ✓ HTTPS 443 | ✓ HTTPS 443 (full) | ✓ HTTPS 443 (storage mgmt) | ✓ HTTPS 443 |
Legend: ✓ = Supported | Optional = Available as add-on | — = Not applicable
5.2 Interface Logic and Integration Architecture
The interface logic diagram below provides a comprehensive view of all data ingestion interfaces, management interfaces, integration outputs, and storage interfaces supported by the NTA/AD Analytics Platform. This diagram serves as the definitive reference for integration planning, firewall rule configuration, and API development.
5.2.1 Data Ingestion Interface Specifications
The following table details the technical specifications for each data ingestion interface, including the protocol, transport, port, authentication method, and maximum ingestion rate. These specifications must be used when configuring network devices to export telemetry and when sizing network bandwidth for telemetry transport.
| Interface | Protocol | Transport | Port | Auth | Max Rate |
|---|---|---|---|---|---|
| NetFlow v5 | NetFlow v5 | UDP | 2055 | Source IP allowlist | 500K flows/sec |
| NetFlow v9 | NetFlow v9 | UDP | 2055 | Source IP allowlist | 500K flows/sec |
| IPFIX | IPFIX (RFC 7011) | UDP / TCP / SCTP | 4739 | Source IP allowlist | 1M flows/sec |
| sFlow | sFlow v5 | UDP | 6343 | Source IP allowlist | 200K samples/sec |
| PCAP (TAP) | Raw Ethernet frames | Physical (monitoring port) | N/A | Physical access control | 10–100 Gbps per port |
| DNS Syslog | Syslog (RFC 5424) | UDP / TCP / TLS | 514 / 6514 | TLS mutual auth (optional) | 100K events/sec |
| Cloud VPC Flow Logs | REST API (cloud-native) | HTTPS | 443 | Cloud IAM / API key | API rate limit dependent |
5.3 Selection Criteria and Sizing Guidelines
Selecting the appropriate product configuration requires evaluating four primary dimensions: peak monitoring throughput, required telemetry types, PCAP storage capacity, and analytics processing requirements. The sizing methodology starts with traffic measurement at each observation point, then applies a growth factor for future capacity, and finally maps the resulting requirements to the appropriate product platform.
| Requirement | < 1 Gbps | 1–10 Gbps | 10–40 Gbps | > 40 Gbps |
|---|---|---|---|---|
| Recommended Sensor | Virtual Edition or NTA-2000 | NTA-2000 Series | NTA-5000 Series | NTA-5000 Cluster |
| Flow Storage (90 days) | ~500 GB | ~2 TB | ~8 TB | ~30 TB+ |
| PCAP Storage (7 days) | ~5 TB | ~50 TB | ~200 TB | Not recommended (selective PCAP only) |
| Analytics Nodes | 1 (virtual or physical) | 1x NTA-5000 | 1x NTA-5000 + storage | NTA-5000 cluster (2–4 nodes) |