SDN-controlled network packet broker fabric for scalable network visibility and security monitoring using merchant-silicon switches
Arista DANZ Monitoring Fabric (DMF) is a network packet broker (NPB) platform that uses an SDN-controlled fabric of merchant-silicon switches (from Arista, Dell, and Accton) to replicate, filter, aggregate, and distribute network traffic to security monitoring tools, intrusion detection systems, and network analytics platforms without tapping the production network directly. The SDN control plane is provided by a high-availability pair of DMF controllers, which manage the full switch fabric through a centralised policy model: operators define what traffic to capture (by VLAN, IP prefix, protocol, or port), where to send it (which monitoring tool ports), and how to transform it (stripping headers, de-duplicating packets), and the controllers push those policies to the underlying merchant-silicon switches as flow table entries. The NPB function runs in the switching silicon at line rate, with no packet processing overhead on the controller and no additional latency introduced to the production network being monitored.
The controller can be deployed as a virtual machine on KVM or VMware ESXi hypervisors (minimum 8 vCPU, 32 GB RAM, 400 GB storage), or as a dedicated 1U hardware appliance (DCA-DM-C660) with an Intel Xeon Silver dual-socket 12-core processor, 64 GB RAM, 8 TB SATA storage, and 2×10 GbE connectivity, rated to 115,000 hours MTBCF. A separate Service Node appliance (DCA-DM-SNR660) handles packet processing for analytics functions (deduplication, header stripping, load balancing to tool clusters) with a 24-core single-socket Xeon processor, 128 GB RDIMM, 960 GB SSD, and 4×25 GbE + 2×1 GbE network interfaces. Multi-tenancy support allows separate IT teams (security operations, network operations, application monitoring) to access their own filtered view of the monitoring fabric through a single physical infrastructure, rather than requiring separate NPB deployments per team.
The DMF controller pair manages the full packet broker switching fabric through an SDN control plane, translating operator-defined traffic policies into switch flow table entries that execute at line rate in the merchant-silicon ASICs of the underlying switches. This SDN architecture separates the policy definition (what traffic, to which tools, with which transformations) from the hardware that enforces it, meaning that the DMF fabric can be scaled by adding more merchant-silicon switches without changing the policy model or the management interface; policies scale with the fabric automatically rather than requiring reconfiguration when new switch ports are added to the monitoring infrastructure.
Multiple IT teams, including security operations, network operations, application performance monitoring, and compliance auditing, share a single DMF fabric deployment while each team sees only the traffic segments authorised for their role. This eliminates the infrastructure duplication that arises when each team deploys its own separate taps, NPBs, and tool connections across the same production network, reducing both capital cost and the number of physical taps on production links. The multi-tenant model also provides audit separation: a security team's packet capture configuration is not visible to the network operations team, and each team's tool connections receive only the filtered traffic they are entitled to see.
The DMF controller is available as a VM appliance on KVM or VMware ESXi for organisations that prefer to host control-plane infrastructure on existing server estates, or as a dedicated 1U hardware appliance (DCA-DM-C660) with an Intel Xeon Silver dual-socket processor and 8 TB of local storage for event logs, packet captures, and flow records. The Service Node (DCA-DM-SNR660) provides dedicated packet processing capacity for DMF's analytics functions, running on a single-socket 24-core Xeon with 4×25 GbE interfaces, separating packet processing load from the controller's policy management functions so that high-volume packet capture does not degrade policy enforcement latency in the fabric.
DMF combines three functions that are typically provided by separate products in traditional visibility architectures: the network packet broker (traffic filtering and distribution to tools), an analytics layer (flow metadata, traffic statistics, anomaly detection), and packet capture (full packet recording for forensic analysis and incident response). Consolidating these functions under a single SDN-controlled platform means that a security analyst investigating an incident can simultaneously see the real-time flow analytics, initiate a packet capture of the relevant traffic segment, and redirect that traffic to an additional tool for further analysis, all from a single management interface, without requiring separate teams to coordinate changes to separate systems.
Full specifications for Arista DANZ Monitoring Fabric
Download product documentation and resources
Explore other configurations and models that might suit your needs.
Recommended#Arista-CLOUD-TEST
Recommended#Arista-CLOUDVISION-CUE
Recommended#Arista-MULTI-DIRECTOR
Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.
We're here to help with any questions