What are the advantages of using an Endace Card?
15.7 and prior.

Endace Card support was deprecated in DLP 15.8.


Endace Cards are recommended for those customers with traffic over 45Mb/s reaching the monitor machine.  Note that the rate at which Symantec DLP can detect in real time is significantly lower than what it can aquire from the wire.  However, not all customers demand detection in real time, and Network Monitor is able to queue traffic well ahead of how quickly detection can process it.

Additional reasons for an Endace:

  1. Burst rates may be far higher than sustained rate in typical Mbps bandwidth terms.  Bursts can exceed software capture capabilities even if the average utilization seems well within capabilities.
  2. Many customers are simply unable to filter upstream and, therefore, deliver a significant amount of "noise" in their feeds.  They may also simply prefer to control their filtering on the monitor itself rather than conditioning the feed upstream.
  3. 40-45Mbps is mentioned at times as recommended traffic, but this is essentially decomposed message data.  This does not necessarily correlate directly to stream bandwidth.
  4. Some customers simply want the assurance that they will never miss a packet.

You can obtain Endace-like performance with a NIC if the OS is Linux.  The native capture layer for Linux monitors in will provide an alternative in many circumstances.

Overall, though, if a site is willing and able to split, filter, or otherwise condition the offered load such that one or more monitors receive clean, low-rate feeds, then that is a perfectly acceptable deployment scenario.