Latest collaboration with ProfiTAP (https://www.profitap.com) allowed ITORO to promote some new features for customers that have direct link to routers and would like to avoid switches at all costs.
Most WanGuard port-mirror sensors get their copy of the traffic from a switch. A SPAN session duplicates the uplink onto a port, the sensor listens there, and that is the arrangement described in our installation notes. It assumes one thing: that there is a switch between your router and the transit link.
Plenty of networks do not have one. The router terminates the carrier link directly and there is nothing to mirror from. Buying a switch only to create a SPAN session is a real cost, a new device in the path, and one more thing that can fail at three in the morning. The alternative is a network TAP on the link itself.
What a passive optical TAP actually does
A passive fibre TAP is an optical splitter. It takes the light on each fibre and divides it: most of the power continues to the far end, a fraction is diverted to a monitor output. Nothing is buffered, nothing is switched, nothing is configured. There is no electronics in the data path, so there is no power supply to fail: if the TAP loses power the link stays up, because it never depended on that power. Profitap describes its passive fibre TAPs as requiring no power and therefore introducing no point of failure, across links from 1 to 400 Gbps, in LC, MTP and SC variants, in chassis of one to eight links.
Two consequences matter for a WanGuard deployment.
Each direction arrives on its own fibre. Traffic from the carrier and traffic towards the carrier come out on separate monitor outputs, so watching a link in both directions costs two sensor ports, not one. That maps onto the sensor sizes we deploy, specified as 2×10GE, 2×40GE and 2×100GE, and the DPDK capture engine reads both ports and reconstructs the bidirectional view. Watching inbound only halves the port count, which is what makes one multi-link chassis cover a lot of links. Decide this before ordering: the number of links a unit taps and the number of directions you can deliver to sensors are two different figures.
The split ratio comes out of your optical budget. A TAP that diverts 30 percent of the light leaves 70 percent for the live link. On a short single-mode run this is irrelevant. On a long-reach link close to the transceiver’s sensitivity limit it is not, and the remaining power at the far end has to be checked against the optics in use before a ratio is chosen. It is a five-minute calculation and a common reason a deployment needs a different ratio than the default one in the catalogue.
The reason a client chose it over a switch
In one ITORO deployment the client took exactly this route, and not for a single link. The router terminated the carrier links directly, there was no switch to mirror from, and rather than buy one for the sole purpose of SPAN sessions the client bought a Profitap F8LF8L: a passive fibre TAP for eight network links, LC connectors, 1 to 100 Gbps, with eight monitor outputs, available for single-mode 9 µm and multimode 50 µm or 62.5 µm fibre and in 50/50, 60/40 and 70/30 split ratios. One chassis therefore covers eight tapped links at once.
This deployment watches the inbound direction only: one monitor output per link, eight links from a single chassis. For DDoS detection that is a deliberate and common choice, because a volumetric attack arrives from the carrier side and the sensor needs to see what is coming in. It costs you the outbound half of the picture, so traffic ratios per host and outbound anomalies (an infected customer sending an attack) are not visible from this feed. Where both directions are required, the number of monitor outputs, and the number of sensor ports, has to be planned for twice as many feeds.
Price was not what decided it. With no switch inserted, the optical path between the router and the carrier stays intact, so the router’s own transceivers keep reporting the real condition of the link end to end: received and transmitted power in dBm, transceiver diagnostics, the rest of the fibre parameters. A switch in the middle splits that path into two segments and hides the carrier side of it from the router, which is precisely the side you want to see when the line degrades. The TAP added visibility for WanGuard without taking any away from the network team.
When a passive splitter is not enough
If several links have to be watched by fewer sensor ports, or a 1 Gbps copper link must reach a 10 Gbps sensor port, a passive splitter no longer does the job. Profitap’s Booster series aggregates up to four in-line copper links or eight out-of-band feeds into one or two SFP+ outputs at 1 or 10 Gbps; for larger fabrics there are network packet brokers (XX and X2 series) that aggregate, filter and load-balance across many monitor ports. These are active devices with their own power, management and failure modes. The argument for them is capacity and port economy, not the “no point of failure” property of a passive TAP.
What a TAP does not change
A TAP sits on the detection side only. It gives the sensor a complete, unfiltered copy of the link. It filters nothing and mitigates nothing. Mitigation still happens where it always does in a WanGuard deployment: BGP FlowSpec rules or RTBH announcements pushed to the router, or WanFilter on the sensor host. Inserting a TAP also means breaking the link once, physically, so it belongs in a maintenance window and not in the middle of an attack.
Choosing between a TAP and a mirror session is part of the wider question of how the sensor gets its traffic at all: port mirror and DPDK on one side, NetFlow, sFlow and IPFIX from the router on the other. Sizing a sensor for a tapped link follows the same rules as for a mirrored one and is covered by the standard deployment packages.
Updated September 2026. The November 2023 version of this post described the idea in general terms; this revision adds the device characteristics, their consequences, and the deployment in which a TAP replaced a switch.