n2disk™

100 Gbit network traffic recorder with on-the-fly indexing
n2disk™ is a network traffic recorder application capable of capturing full-sized network packets up to 100 Gbit from a live network interface, and write them into files without any packet loss. n2disk™ has been designed to write files into disks for very long periods. When n2disk™ reaches the maximum configured data retention (disk space), it will start recycling the files from the oldest one.
n2disk™ uses the industry standard PCAP file format to dump packets into files so the resulting output can be easily integrated with existing third party or even open-source analysis tools (e.g. Wireshark).
NetFlow technologies are more manageable and require less disk space to be stored, but in some cases, like DPI analysis, troubleshooting, or controlled traffic replay, it is not useful.
n2disk™ can be effectively used to perform numerous activities, among these:
- Off-line network packets analysis by feeding a specialized tools like IDSs
- Reconstruct particular communication flows or network activities
- Reproduce the previous captured traffic on a different network interface

at a glance
Key Features
- Industry standard PCAP file format (regular and nanoseconds)
- Line rate 64-byte packet to disk recording with no packet loss
- PF_RING Zero-Copy (ZC) support for Intel and NVIDIA/Mellanox adapters
- Native support for Napatech and Silicom (Fiberblaze) FPGA with segment mode
- Full 100 Gbit line-rate 64-byte packets to disk with no packet loss on adequate hardware
- Optimized BPF and Layer-7 filters support, shunting and slicing
- Multi-cores support to fully leverage on modern CPU architectures
- Direct-IO disk access and NVMe RAID emulation to obtain maximum disk-write throughput
- On-the-fly indexing of pcap data, to quickly retrieve interesting packets in a specified time interval using BPF-like filters
- PCAP and index compression (optionally enabled) to optimize I/O throughput and disk space

Ideal for Every Environment
Use Cases
Troubleshooting
n2disk enables continuous packet capture with zero packet loss, providing a reliable record of all network activity. When issues arise (such as service disruptions, dropped connections, or abnormal latency) engineers can quickly rewind network traffic and pinpoint root causes with full-packet visibility.
Network Forensics
In security-sensitive environments, having a searchable, time-stamped archive of packet data is critical. n2disk supports long-term retention and indexed search capabilities, making it an ideal solution for forensic investigations, regulatory audits, and lawful interception scenarios.
HFT Optimization
In ultra-low latency environments like High-Frequency Trading, every microsecond matters. n2disk, when used with PF_RING and hardware timestamping, allows precise capture and analysis of packet timing and jitter. This helps trading firms validate performance, troubleshoot delays, and optimize infrastructure for maximum speed and accuracy.
Specifications
Tech Specs
- Linux
- FreeBSD (libpcap capture)
- Web GUI available for configuration and traffic extraction through ntopng or on nBox appliances
- HTTP-based RESTful API for traffic extraction through ntopng
- CLI tool for traffic extraction
1 Gbit | 10 Gbit | 100 Gbit | |
Disk | 1 HDD | 8 HDD / 4 SSD | 8 NVMe |
Processor | 1 core | 4 cores 3 Ghz | 12 cores 3 Ghz |
Memory | 1 GB | 8 GB | 32* GB |
Table reports minimum requirements.
Increase the number of disks to achieve the desired data retention.
* RAM configuration should meet the optimal number of memory modules according to the memory channels supported by the CPU.
models
Choose Your Model
Did you already install the software?
Select the model. Different models unlock different features and capacity. Check the comparison table.
1 Gbit
- Packet capture to disk in PCAP format
- On-the-fly indexing and timeline
- Native PF_RING support
- Single threaded packet processing
- L7 filtering not included (optional)
- Up to 1 Gbps
5 Gbit
- Packet capture to disk in PCAP format
- On-the-fly indexing and timeline
- Native PF_RING support
- Single threaded packet processing
- PF_RING FT included (L7 filtering)
- Up to 5 Gbps
10/100 Gbit
- Packet capture to disk in PCAP format
- On-the-fly indexing and timeline
- Native PF_RING support
- Multithreaded packet processing
- PF_RING FT included (L7 filtering)
- Up to 100 Gbps