This site requires JavaScript. Please try again.
Networks are complex. Your network performance management shouldn’t be!
TurboCap is a Gigabit Ethernet packet capture and injection solution with advanced features such as simultaneous full-rate capture and injection, multi-port traffic aggregation and a configurable pass-thru mode. Wireshark, the leading network protocol analyzer, supports packet capture using TurboCap interfaces and off-line analysis of TurboCap capture files. A native TurboCap API and a winpcap/libpcap API are available for writing/porting custom Gigabit Ethernet applications. TurboCap includes a PCI Express, dual-port or quad-port gigabit NIC, the TurboCap optimized driver, and a user-level API. TurboCap is available for Microsoft Windows® (XP and Vista) and Fedora® 10.
TurboCap Key Features
Full-Rate Capture: Full-rate Gigabit Ethernet packet capture is most needed when networks are exhibiting poor performance. There could be many reasons for this, including a network attack. These are the times when it is essential to capture traffic from the network without dropping any packets. TurboCap supports full-rate Gigabit capture for even the most challenging smallest packet sizes (64 bytes).
Aggregation of Traffic Sources: Capturing traffic in timestamp order from two different sources (e.g., a full-duplex link) is a common and important network analysis requirement. This is referred to as “aggregation”, and provides a means to measure packet delays between multiple sources, such as the ingress and egress of a switch or router. TurboCap supports full-rate traffic aggregation of the traffic received on pairs of ports of the same board. This is presented to the user as a virtual port called a board aggregating port (BAP).
TurboCap also supports aggregation of all of the ports on all of the TurboCap boards installed on the system. Specifically, with a single 4-port TurboCap board, the user can capture from each of the individual ports, from two, 2-port aggregation ports (ports 0 and 1 and ports 2 and 3), or an aggregation port corresponding to all four ports.

Pass-Thru Mode: Often, the preferred way to capture traffic is to tap into your network. TurboCap can emulate a network tap by being configured to inject the traffic received from one port to the other port on the same board. When the board is in pass-thru mode, the injection is done simultaneously for pairs of ports of the same board and, consequently, TurboCap can act as a Network Tap.

Application Performance: The TurboCap card and optimized driver are capable of capturing full-rate Gigabit Ethernet traffic and delivering this data to an application. The overall application performance is often determined by a number of additional factors such as the application’s computational tasks, disk write speed, CPU speed, and main memory size. TurboCap is integrated with winPcap/libpcap and, consequently, supports applications such as Wireshark, Windump/tcpdump and Ntop.
Full-rate Traffic Injection: For stress testing the network, TurboCap offers full-rate, simultaneous Gigabit Ethernet traffic injection. The TurboCap API is available for developing a wide range of traffic injection applications for vulnerability testing as well. Packets ranging in size from 64 bytes to 9234 bytes (jumbo frames) are transmitted in the order they are sent to the driver with minimal delay.
Timestamps: TurboCap offers a range of timestamp modes which trade timestamp accuracy for CPU utilization. The user has the option of choosing the timestamp mode that best suits the need, from highly accurate timestamps to no timestamp generation.
| Model | TurboCap 2 | TurboCap 4 |
|---|---|---|
| GbE Line-Rate Capture | Yes | Yes |
| Wireshark Integration | Yes | Yes |
| Full-Rate Traffic Injection | Yes | Yes |
| Open API for Development | Yes | Yes |
| Port Aggregation | pairwise and all ports from all the boards |
pairwise and all ports from all the boards |
| Number of Ports | 2 ports | 4 ports |
| Host Interface | PCIe 4-lane | PCIe 8-lane |
| System Requirements | |
|---|---|
| Operating System | Microsoft Windows or Linux Fedora 10 |
| CPU | Pentium-D(dual core) processor or multiple CPUs (SMP), 2.8GHz or greater |
| Memory | 2 GB RAM |
| Disk | Full-rate dump-to-disk requires disk arrays that have sufficient capacity and speed to keep up with full-rate Gigabit Ethernet. Disk capacity and speed to keep up with full-rate Gigabit Ethernet. Disk capacity and speed can be achieved using highly parallel disk arrays. |
| PCIe | Either x4 or x8 PCI Express slots depending on the TurboCap board |
The TurboCap driver Software License Agreement is a single-seat license. If you wish to purchase TurboCap online, click here. A TurboCap purchase is subject to these standard terms and conditions of sale and license.
The latest TurboCap Windows and Linux drivers are available on the Riverbed Support Site. TurboCap NICs are not shipped with the drivers.
Learn More:
Other Related Content:
Sharkfest '12
Wireshark Developers & User Event
Dates, agendas, and retrospectives
Learn More
Riverbed. WAN optimization for your network: Application acceleration, WAN bandwidth optimization, and IT consolidation
Riverbed Technology delivers performance for the globally connected enterprise. With Riverbed, enterprises can successfully and intelligently implement strategic initiatives such as virtualization, consolidation, cloud computing, and disaster recovery without fear of compromising performance. By giving enterprises the platform they need to understand, optimize and consolidate their IT, Riverbed helps enterprises to build a fast, fluid and dynamic IT architecture that aligns the business needs of the organization. Additional information about Riverbed (NASDAQ: RVBD) is available at www.riverbed.com.