<img src="https://secure.leadforensics.com/97241.png" style="display:none;">

Network TAPs for rail and transport networks

Network Critical provides network TAPs for rail and transport networks, built for operators running safety-critical control, signalling and passenger systems across stations, depots, control centres and remote sites.

Network teams at these organisations run Network Critical visibility

  • Vodafone Logo
  • HSBC Logo
  • bp logo
  • Airbus Logo
  • Darktrace Logo

Zero-impact monitoring for safety-critical rail and transport operations

Rail and transport operators run converged networks where signalling, SCADA, CCTV, ticketing and passenger information systems share infrastructure spread across stations, depots and remote sites. Monitoring that traffic is essential for security and service assurance, but any device that can disrupt a live link is a safety risk, not just an availability risk. Network TAPs for rail and transport networks solve this at the access layer. They copy every packet, including errors, to your monitoring and security tools while live traffic passes untouched, and fail-safe designs keep links running even if power is lost. The BP case study shows the same zero-impact approach monitoring IT and OT systems across distributed refinery sites.

Key challenges facing rail and transport operators

Fail-safe requirements on critical links
Any active device in the path of control or signalling traffic is a safety risk, and a failed monitoring appliance must never take a link down. Network Critical's Passive Fiber Optical TAPs use no power and no active electronics, so live traffic keeps flowing whatever happens to the TAP.
Space and power limits at remote sites
Lineside cabinets, substations and small station equipment rooms rarely have spare rack space, power or cooling for more appliances. Network Critical's SmartNA-XL combines TAP and packet broker functions in a single 1RU chassis, cutting the footprint and cabling that separate devices would need.
Change windows measured in months
Engineering access and change approvals are scarce, so a monitoring deployment that needs repeated site visits or reconfiguration is hard to justify. Network Critical's Drag-n-Vu lets administrators change filters and tool mappings from a single interface, without touching the live link again.
Monitoring the IT and OT boundary
Ticketing, passenger Wi-Fi and corporate IT increasingly connect to operational systems, widening the attack surface for ransomware. Network Critical's OT network monitoring approach uses one-way passive TAPs that copy traffic out to security tools without creating a path back into the operational network.

Why rail and transport teams come to Network Critical

We need visibility across our operational networks without risking any service disruption.

Our IEC 62443 programme requires segmentation monitoring between IT and OT zones.

A ransomware attack on a peer operator has put OT visibility on our board agenda.

We are digitising control systems and need complete visibility of the new traffic.

Our remote sites lack the power and space for more active monitoring appliances.

Our SPAN sessions drop packets and our security tools are missing what matters.

Key capabilities for rail and transport networks

Fail-safe, zero-impact capture

Network Critical's Passive Fiber Optical TAPs need no power and no configuration, passing full-duplex traffic, including errors, to your tools. Fail-safe copper TAP modules need no batteries and keep links running through a power loss. 

Multi-link aggregation and filtering

Network Critical's SmartNA-XL aggregates, filters and load balances traffic from copper and fibre links at speeds up to 40Gbps. Filtering out irrelevant traffic and aggregating under-utilised links reduces the number of tools you need to protect every link. 

Simple, centralised management

 Network Critical's Drag-n-Vu gives a single pane of glass across your visibility platform, with drag and drop filters, one-click rollback and an open API. Network administrators, not specialist engineers, can make changes, reducing downtime during maintenance windows. 

Zero trust protection for critical systems

 Network Critical's INVIKTUS adds a zero trust layer in front of critical servers. With no IP or MAC address it stays invisible to intruders, runs at full line rate, and its Lock and Leave policies need minimal maintenance. 

Best network TAP solution for rail and transport networks

SmartNA-XL: hybrid TAP and packet broker for distributed transport networks

  • Modular 1RU chassis with five slots, including a rear slot for stacking units
  • Up to twenty 1/10Gbps SFP/SFP+ ports, plus 40Gbps QSFP module options
  • Non-blocking backplane carrying traffic from 10Mbps to 40Gbps
  • Passive fibre, Fastfail copper and bypass TAP modules, so traffic flows even if power fails
  • PacketPro packet slicing, header stripping and payload masking
  • IP, GRE, NVGRE and VXLAN encapsulation for point-to-point tunnelling to central tools
  • Dual hot-swappable power supplies, AC (100V to 240V) or DC (-42V to -63V)
  • Managed through Drag-n-Vu, with SSH, HTTPS, SNMP v1/v2c/v3, RADIUS and TACACS+
SmartNA-PortPlus on blue background
person typing on futuristic laptop

When SmartNA-XL is the right fit

  • You need to monitor a mix of copper and fibre links at 1G to 40G from one compact chassis.
  • You must keep control and signalling traffic flowing even if a monitoring appliance or power supply fails.
  • You want to protect many station, depot and control centre links with fewer security tools.
  • You need fail-safe access plus filtering and aggregation, adding Passive Fiber Optical TAPs on links where power is unavailable.

Case studies: network TAPs proven in safety-critical and distributed networks

The State of Maryland Department of IT uses the Network Critical SmartNA-XL to monitor its unified communications network through a migration from TDM voice to IP. Five modular slots support passive, active and bypass TAP modules, giving visibility across all network layers that protects service levels and supports regulatory compliance. 

Read more

Airbus deployed Network Critical network TAPs across its aircraft test rigs, capturing steering, braking, landing and avionics test data with zero impact on the network. Failsafe TAP technology gave the safety assurance testing required, helping Airbus complete its first flight test objectives on schedule.

Read more
bp logo

 

 Continuous monitoring is critical to digitization and automation of our many monitoring systems. Being able to monitor remote sites from a single location keeps our systems up to date without having a large staff running around in trucks." 

 —   Senior Project Manager, Refining Operations, BP 

 

Why SPAN ports fail for rail and transport networks

SPAN drops packets when incidents happen

SPAN is oversubscribed by design, so it drops packets during traffic spikes and anomalies, exactly when forensic evidence matters most. No alarm fires, so your tools report a partial picture. Network TAPs copy every packet, including errors, at line rate. 

SPAN loads the switches that run operations

SPAN competes with the switching workload for shared resources, and most switches support only 2 to 4 concurrent sessions. On control networks, that puts monitoring load on devices you need stable. Passive Fiber Optical TAPs add no load and need no power. 

SPAN cannot scale across distributed sites

Every station and depot switch needs its own carefully configured SPAN session, and misconfiguration is easy and silent. Multiply that across a route and coverage gaps become inevitable. The SmartNA-XL aggregates many links into fewer tool ports, configured from one interface. 

Why choose Network Critical for rail and transport network TAPs

Network Critical gives rail and transport operators enterprise-grade visibility without enterprise pricing or complexity. Fail-safe Passive Fiber Optical TAPs and the hybrid SmartNA-XL deliver complete, zero-impact capture, with perpetual licensing, transparent pricing and a three-year cost of ownership typically 40 to 60% lower than enterprise visibility platforms.

Drag-n-Vu lets administrators configure filters and tool mappings quickly, so changes fit inside short maintenance windows. Our TAPs are proven where safety and continuity matter, from multi-building refineries in the BP case study to aircraft test rigs in the aviation case study and public networks in the State of Maryland case study.

With over 20 years' experience, UK manufacturing, a US office and 24/7 support, Network Critical is built for the long deployment cycles of critical infrastructure.

 

Frequently asked questions about network TAPs for rail and transport networks

  • A network TAP is a hardware device that copies all traffic on a link to monitoring and security tools without affecting the live network. Network TAPs for rail and transport networks give operators complete visibility of control and passenger systems with no risk to service. Read more in what is a network TAP. 

  • A network TAP captures every packet at line rate, while SPAN ports mirror traffic using switch resources and drop packets under load. TAPs also capture errors and add no load to operational switches. Our guide to network TAPs vs SPAN explains the differences in detail. 

  •  When SPAN drops packets, your security and performance tools analyse an incomplete picture, and nothing alerts you to the gap. Intrusions, faults and anomalies can go unseen at the moment evidence matters most. Learn what is network packet capture and why complete capture is essential. 
  • A passive network TAP cannot disrupt live traffic, because it splits the optical signal and uses no power or active electronics. Live traffic passes at full speed while a complete copy goes to your tools. Network Critical's passive fiber TAPs ship preconfigured and need no ongoing maintenance. 

  •  The SmartNA-XL hybrid TAP and packet broker suits most rail and transport networks. It combines fail-safe copper, fibre and bypass TAP modules with aggregation and filtering in one 1RU chassis. Explore the SmartNA-XL for full specifications. 

  • Passive fibre TAPs need no power, so they keep working through power glitches at remote sites and add nothing to the power budget. Up to 16 TAPs fit in 1RU, saving space in cramped equipment rooms. See Network Critical's range of optical network taps. 
  •  SmartNA-XL works with all major monitoring tools, including protocol analysers, probes and intrusion detection systems. It filters, aggregates and load balances traffic so each tool receives only the data it needs. Find out more about OT network monitoring with Network Critical. 

  •  Network TAPs support NIS2 and IEC 62443 programmes by providing the continuous, non-intrusive visibility that segmentation monitoring and incident detection depend on. They let you monitor across zones without bridging them. Learn how Network Critical supports OT cybersecurity in critical infrastructure. 
  •  Bypass TAPs send heartbeat signals to inline security tools and automatically reroute traffic if a tool stops responding. Your network keeps running during tool failures or maintenance. Network Critical's bypass taps use the SmartNA-XL modular chassis with dual hot-swappable power supplies. 
  •  Yes. INVIKTUS places a zero trust layer in front of critical servers, giving each authorised user one permitted path while the rest of the network stays invisible. It has no IP or MAC address, so attackers cannot see it. Explore INVIKTUS for zero trust protection. 

  •  Airbus, BP and the State of Maryland all rely on Network Critical TAPs where zero network impact is essential. Airbus used failsafe network TAPs across aircraft test rigs to complete its first flight test objectives on schedule. Read the aviation case study for details. 
  •  Network Critical typically costs less to own than enterprise visibility platforms, with perpetual licensing, transparent pricing and no subscriptions. Aggregation also cuts tool spend: Bourne Leisure protects eight 1Gbps links with a single 10Gbps security tool. See the leisure case study for the full deployment.