Phantom vTap

Software solution that supports all leading hypervisors

Phantom Virtualization Tap

Free 30-Day Trial

CRN Head Turning Product

Network World How Product Interop 2012

Free 30-Day Trial

The Phantom vTap™ is a software solution that supports all leading hypervisors (VMware vSphere, Microsoft Hyper-V, Citrix XenServer) to provide customers with 100% visibility of their virtual traffic.

Virtual Taps – Phantom Monitoring Solution

Security and Performance Monitoring tools in the market today are not capable of providing a comprehensive, raw view of traffic traversing virtual switches.  This is because they cannot monitor the internal networking layer within the hypervisor.  The Phantom vTap deploys a module that resides in the hypervisor kernel, passively monitoring all the inter-VM traffic and capturing only traffic of interest – enabling the customer to forward the packets to any end-point tool of choice, physical or virtual, and local or remote.

With integration on the hypervisor kernel level, Phantom vTap is an out-of-band monitoring solution that does not affect the production traffic flow and does not require any services or agents to be installed on the virtual machine or application layer, eliminating the need for sacrificing any virtual resources such as vCPU, vRAM, and storage.  The Phantom vTap is vSwitch agnostic supporting the vSS, vDS and third party virtual switches (ie Cisco Nexus 1000v, IBM 5000v).

The Phantom vTap can mirror all traffic within the virtual switch, apply smart TapFlow™ filtering, and send only traffic of interest to any monitoring tools of choice. Virtual traffic is bridged to the physical wire in an GRE encapsulated tunnel that can be terminated by a Net Optics xFilter™ or any other capable end-point termination tool of your choosing. The Phantom vTap is an all in one solution providing a unified centralized management in a single pane glass. Get total access and control with your security and performance monitoring needs with an easy to use web UI.

Phantom InventoryThe Virtual Monitoring Challenge

Enterprises have been utilizing Tap solutions for network traffic access for many years. Traffic capture, analysis, replay, and logging are now part of every well-managed network environment. In recent years, the significant shift to virtualization—with penetration exceeding 50%—is yielding great benefits in efficiency. However, today’s virtualization-based deployments create challenges for network security, compliance, and performance monitoring. This is because Inter-VM traffic is optimized to speed up connections and minimize network utilization. This imposes invisibility on physical tools unable to extend easily into the new environments. Costly new virtualization-specific tools plus training can affect the economic benefits and cost-savings of virtualizing. Currently, many tools suffer from limited throughput, hypervisor incompatibility, and excessive resource utilization.

Next generation data centers use virtualization technology to deploy private/public cloud environments on a single physical server, or across a clustered group of servers. Traditional Taps cannot see the traffic between the VMs that reside on the same hypervisor (east to west traffic), nor can they “follow” VMs as they get migrated from one host to another.

Visibility is further reduced by the complexity of blade servers: with each blade running multiple VMs on a hypervisor. Traffic running on blades servers share a common backplane, presenting a network blind spot, as the physical network and its attached tools unable to see traffic from the internal network packets.

Watch the Video:

Phantom Deployment

Supported Version
Hypervisor Support

  • VMware vSphere ESXi Server 5.0/5.1
  • Microsoft Hyper-V 2012
  • Citrix XenServer 5.6

Network Connectivity

  • Phantom Manager VM must be accessible via HTTP to access Web UI
  • TCP port 80, 443, and 5989 (and/or custom vCenter port) must be open between Phantom Manager VM and VMware vCenter    

Resource Requirements
Disk Storage

  • Thin provision 3.1 GB
  • Thick provision 60 GB


  • 1 vCPU


  • 1 GB minimum
  • 2 GB recommended

Web Browser
Google Chrome, Firefox

Key Features
  • 100 percent visibility of east to west, inter-VM and blade server mid-plane traffic
  • Kernel level solution, enables full access to network packets passing between VMs on hypervisor stack
  • TapFlow™ multi-layer L2-L4 filtering engine
  • Supports best of breed hypervisors – VMware vSphere, Microsoft Hyper-V, Citrix XenServer
  • vSwitch agnostic – supports vSS (virtual standard switch), vDS (virtual distributed switch), and third party virtual switches  (Cisco Nexus 1000v)
  • Tool agnostic -  send traffic to any existing end-point appliance
  • VM-level monitoring - Follows UUID of VM for 100% visibility throughout migration
  • vMotion and DRS supported


  • Enables proactive monitoring and security of virtual datacenters
  • Maximize user experiences by increasing troubleshooting capabilities
  • Meet SLA’s and compliance requirements (SOX, PCI, HIPPA)
  • Visibility and verification helps resolve root causes to reduce meantime to resolution
  • Increase ROI and Lower TCO of existing Security and Performance Monitoring tools
  • No services or agents installed on the VM level allowing you to retain 100% system resources

Control multiple Phantom vTaps  with centralized management VM (included software component)



- PT-1vTAP-1YR

Phantom Virtualization Tap, 1 Phantom Manager + 1 Monitor, One Year License