Skip to content

Two common methods to copy traffic to your monitoring or security tools is a Span port or network tap. Span can be convenient for quick troubleshooting, remote locations or when you do not have access to the physical infrastructure. The risk of using a span port is that

  • It can be over subscribed, and the lowest priority when it comes to forwarding all the packets to the intended device.
  • Using a SPAN port is processor-intensive and can have a negative performance on the switch itself.

To avoid this we can use a network TAP which is a simple device that connects directly to the cabling infrastructure to split or copy packets for monitoring purposes such as security or packet capture devices.

So where do I deploy a tap? A quick answer to this is anywhere you need 100% of the data all the time from L1 to L7. The above diagram is also a useful reference guide.

Thank you to ProfiTap for the article.

Related Posts

Understanding & Operationalizing Bill C-8 as a Critical Infrastructure Operator

Understanding & Operationalizing Bill C-8 as a Critical Infrastructure Operator

On June 15, 2026, Bill C-8, An Act Respecting Cyber Security, received Royal Assent. After years of consultation, a false…
Data Diodes in ICS Environments: Why One-Way Visibility Is Becoming Non-Negotiable

Data Diodes in ICS Environments: Why One-Way Visibility Is Becoming Non-Negotiable

“You cannot secure what you cannot see.”  It’s a mantra we come back to often, because it’s true. Your security…
Vendor Spotlight: Unlocking Enterprise Infrastructure Visibility with Garland Technology

Vendor Spotlight: Unlocking Enterprise Infrastructure Visibility with Garland Technology

Achieving comprehensive visibility across complex physical, virtual, and cloud infrastructure remains a persistent challenge for modern IT teams. Security and…
Vendor Spotlight: Unlocking Network Visibility with Profitap

Vendor Spotlight: Unlocking Network Visibility with Profitap

If your security tools are only as good as the data they receive, then visibility isn’t a nice-to-have — it’s…
The Hidden Foundation of Network Security: Why Precision Time Matters in a Zero Trust World

The Hidden Foundation of Network Security: Why Precision Time Matters in a Zero Trust World

Zero Trust Architecture has fundamentally changed how organizations think about network security. Identity must be continuously verified. Every access request…