Security Challenges
Increasing convergence of IT and OT environments has expanded the attack surface and introduced new security risks for critical infrastructure. Older and inherently vulnerable Industrial Control Systems (ICS) that were previously ‘air gapped’ or isolated are becoming increasingly exposed to threats as IT and OT converge. Additionally, as the number of industrial IoT devices has risen dramatically over the past several years, the overall level of visibility for security teams into these assets has decreased, creating easy entry points for attackers.
OT security teams continue to suffer from a growing skills shortage, tight budgets, and are understaffed compared to the IT security teams. Furthermore, as United States and European regulations on OT/ICS tighten, critical infrastructures must find a way to improve their OT security posture with an easy to deploy solution providing visibility across all Purdue Levels.
Key Solution Benefits
• Increased visibility across OT, IT, and IioT to Purdue level 1 where there is lacking existing switching infrastructure.
• Protocol and technology agnostic.
• Illuminates points of IT/OT convergence.
• Reduces risk of misconfigured switch ports.
• Guarantees unidirectional traffic flow with data diode protection.
•Reduce complexity of deployment in distributed networks.
• TAPS do not have an IP or MAC address so are not hackable from a network standpoint.
• Zero hardware subscription fees from Garland Technology.
Garland EdgeLens Solution
Garland’s EdgeLens series is an advanced bypass TAP with built-in packet broker functionality that centralizes network traffic, making network tools more efficient by sharing network traffic with monitoring and security tools. EdgeLens provides visibility for a hybrid configuration of an active, inline network device and out-of-band tools, such as LiveAction. EdgeLens provides identical network traffic streams through the active inline device and to the capture engine of LiveAction LiveWire or LiveCapture. The benefits of both devices seeing the same traffic are:
• Correlated data for real-time monitoring and root cause analysis using network packets.
• Historical look back and playback of the network traffic.
• Validating and updating network policy changes and spotting anomalies.
• Network data recording for compliance and security forensics.
• Root cause analysis for application and network related problems.
TAP -> TOOL
Network TAP Benefits
- Provide complete packet visibility with full-duplex copies of network traffic.
- Ensure no dropped packets while passing physical errors and support jumbo frames without delay or altering the data.
- Support speeds from 10/100M, 1G, 10G, 40G, 100G, and 400G are available in single-mode and multi-mode fiber or copper ethernet.
- Available in Tap ‘Breakout,’ aggregation, regeneration, bypass, and advanced filtering.
- Passive or failsafe – Does not affect the network.
- No IP address or MAC address, and cannot be hacked.
CHALLENGES
Increasing Data Rates

Maximising Visibility

Protecting Core Infrastructure

Comprehensive Toolsets

Architecture
Solution Overview
Garland Technology provides a comprehensive portfolio of Network test access point (TAP) and packet broker solutions. When deployed together in a TAP to Agg solution, Garland Technology delivers enhanced East - West visibility into customer networks, at speeds ranging from 1G to 400G. Network TAP and SPAN/Mirror feeds are aggregated together and depending on the requirements of the customer, advanced filtering, packet slicing, and deduplication is applied, before being forwarded on to Telesoft’s advanced Network Detection & Response (NDR) appliance, the Alert Probe, for comprehensive network monitoring and threat detection.
By combining Garland’s high-performance packet broker with Telesoft’s Alert Probe, this joint solution empowers security teams to accurately identify threats and quickly mitigate risks introduced by the ever-evolving threat landscape. Organizations can secure their most critical information, assets, and infrastructure with complete network visibility, advanced analytics, and actionable intelligence.
- Full PDF Solution Brief
- Key Benefits
- About Telesoft
High Rate Performance
Garland and Telesoft have partnered to provide a best-in-class packet broker and NDR solution, capable of processing and analyzing multi-100Gbps networks in real-time.
Comprehensive Threat Detection
Telesoft’s Alert Probe utilizes a number of comprehensive detection techniques and integrated 3rd party threat intelligence to provide real-time alerting for rapid security response.
Accelerated Threat Hunting
IPFIX records generated by Telesoft’s Alert Probe enable network security teams to quickly analyze forensic network data and proactively threat hunt for indicators of compromise.
Traffic Optimisation
Garland’s advanced packet filtering capability can ensure that only unknown/untrusted traffic is forwarded to the Alert Probe, optimising data processing and threat detection.
Unsampled Visibility
By combining Garland’s high-rate packet broker and Telesoft’s Alert Probe, organizations gain complete network visibility across networks at speeds up to 400Gbps, ensuring no threats go undetected.
Integrated Solution
By forwarding NDR threat alerts and unsampled IPFIX records to a unified SIEM platform, security teams gain complete, correlated analysis and intelligence to protect the network.
Telesoft Technologies is a UK-based global provider of comprehensive cyber security and government infrastructure solutions and services. Telesoft develop, manufacture, and support cutting-edge systems and applications to protect core network infrastructure and keep organizations secure. Telesoft prides itself on innovatively creating solutions that improve your existing security posture and prevent cyber-attacks. Gain full network visibility with the world’s highest density enriched probes and sensors.
Discover more at: www.telesoft-technologies.com
- How It Works
- Bypass TAP Benefits
- Full PDF Solution Brief
- How It Works
- How It Works
- How It Works
Bypass manages the availability of inline tools, preventing a single point of failure in the network by “bypassing” the device in the event it fails or needs to be updated. Reducing network downtime. Bypass is unique to the other TAP modes, as it is an inline use case not out-of-band.
• Keep up with Federal security mandates
• Expedited problem resolution
• Ability to pilot or deploy need security tools
• No maintenance windows
• Simple configuration ensures a quick set-up
• Zero subscription fees so O&M expenses don’t increase
■SOLUTION EDGESAFETM BYPASS TAP
• Install a Garland Technology Bypass TAP between Cisco Firepower and the network
• Bypass TAP manages the availability of Firepower at any time without having to take down the network
• Bypass TAP continuously checks the health of Firepower with heartbeat packets and the Bypass TAP will bypass Firepower to keep the network up-and-running in the event Firepower becomes unavailable
PROBLEM 1 PORT FAILURE | ||
■WITHOUT TAP • The network |
![]()
|
■WITH TAP • Uptime • Tool is bypassed while it is being updated |
PROBLEM 1 PORT FAILURE | ||
■WITHOUT TAP • The network |
![]()
|
■WITH TAP • Uptime • Tool is bypassed while it is being replaced |