NAT / PAT
Hide the internal network behind a translated address. High-port PAT for many-to-one, or 1:1 when you need it. Standard gateway behavior — on purpose.
TAPGW sits between your internal network and everything untrusted. It NATs. It filters by port and protocol. And it copies every packet to one or many IDS sensors over VXLAN.
Replace a firewall, a TAP, and a packet broker with one simple gateway.
How it works
The path is the explanation. Inside to TAPGW to the internet. Traffic is translated, filtered, and copied to your sensors on the way through — three jobs that used to live on three boxes.
Internal hosts reach the untrusted network through TAPGW. Source addresses are translated with NAT/PAT. Return traffic lands back where it belongs.
Port and protocol rules decide what is forwarded and what is blocked. Simple. Predictable. No policy novel required to ship a change.
Every packet that hits TAPGW is copied, encapsulated in VXLAN, and sent to one or many IDS sensors. Your existing detection stack just works.
Capabilities
Hide the internal network behind a translated address. High-port PAT for many-to-one, or 1:1 when you need it. Standard gateway behavior — on purpose.
Allow or deny by port and protocol. Blocked sessions never leave the box. Sensors can still see the attempt, so security is not blind to what you refused.
A full-fidelity copy of traffic, taken at the gateway as packets pass through. Forwarded or blocked, the copy still goes out over VXLAN.
Copies are routable overlay. Send them to a sensor on the same rack, or to many sensors across the environment. Add a collector without touching the forwarding path.
Suricata, Zeek, NDR — TAPGW does not replace them. It delivers a VXLAN copy they can listen to, so detection stays on the stack you already run.
Fewer devices in the critical path. Fewer things to patch, rack, and explain. Simple enough to operate. Serious enough to trust with the edge.
Two rooms, one story
For network teams
For security teams
Architecture
Traffic flows through TAPGW as a gateway. A copy of that traffic is encapsulated in VXLAN and delivered to whatever sensors you already operate. Nothing about your IDS has to change except where it listens.
Secvara
TAPGW is part of Secvara’s simple software solutions — networking technology that a room of executives can understand in one sitting, and a network team can actually run.
hello@tapgw.com