NETWORK WATCH
APR 2026 / APCON launches ThreatGuard · SEP 2026 / The focus turns to internal security blind spots
Company / Enterprise infrastructure

APCON: Your security tools are drowning in data

A network can deliver every packet and still leave its defenders blind. APCON has built a business around deciding what security tools need to see - and getting it to them before the evidence disappears.

The bank had more traffic than its security tools could swallow. New systems and a virtual data center had increased the flow; monitoring tools were dropping packets. In APCON’s account of this unnamed financial-services customer, the organization operated in 35 countries and employed more than 50,000 people. It already owned tools intended to explain what was happening. What it needed was a better way to feed them.

The useful bits / 30 seconds
  • APCON copies and sorts network traffic before it reaches monitoring tools.
  • Its pitch is better use of existing security investments through filtering, deduplication, and shared access.
  • ThreatGuard takes it further: packet evidence, threat detection, and investigation in one workspace.

This is a peculiar predicament. A company can spend heavily on visibility and still struggle to see. The network keeps delivering data while the machinery observing it falls behind. APCON’s answer was to insert a packet broker: infrastructure that aggregates traffic, removes copies, and sends selected packets to the appropriate tools. The bank chose its IntellaView platform after evaluating throughput and scalability.

The interesting purchase, then, happens between two things the customer already understands: the network and the security appliance. APCON occupies that middle space. An evidence room needs a competent clerk.

One packet. Too many witnesses.

A network packet broker takes copies of traffic from monitoring points and distributes them to analysis tools. Multiple observation points can produce multiple copies of the same packet. Sending all those copies downstream consumes processing and storage without necessarily providing additional evidence. APCON’s tool-optimization products apply filtering, deduplication, and packet slicing to make the resulting workload more useful.

The distinctions matter. Filtering selects traffic. Deduplication removes repeated copies. Slicing keeps a selected portion of a packet. Header stripping removes encapsulation that can get in a tool’s way. These are different editorial decisions, with different consequences for the evidence an investigator receives. A neat dashboard cannot compensate for a packet that never arrived.

Anatomy of the middleman
01CollectTAPs, SPANs, virtual mirrors
02ConditionAggregate, filter, deduplicate
03DeliverSecurity + performance tools
Traffic has an itinerary. The packet broker decides which tool gets which copy. Conceptual diagram.

This also explains the buyer. APCON serves infrastructure, network operations, and security teams. It reports customers in more than 40 countries, from midsize businesses to large enterprises. Finance, healthcare, pharmaceuticals, government, and telecommunications recur in its materials. These organizations have plenty to observe, expensive tools to share, and reasons to care when evidence goes missing.

The crash cart had to go

Another customer made the problem wonderfully tangible. An anonymous aerospace manufacturer had monitoring tools in ten data centers. When trouble appeared, local staff wheeled out a diagnostic cart, plugged it in, and tried to find or reproduce the fault. APCON’s case study describes a dependence on staff availability and physical access. The monitoring process had become an errand.

The company installed IntellaFlex XR infrastructure for remotely managed visibility. APCON reports that its monitoring budget fell by approximately 50%. That is a result from the vendor’s case study, not a savings forecast for the next buyer. The practical lesson is compelling enough without gilding it: a tool can become more useful when someone improves how it connects to the network.

~50%
Reported monitoring budget reduction

One anonymous aerospace deployment, as described by APCON. A customer result, not a universal return.

A security tool’s first dependency is the evidence it can actually receive.

Fast ports, slower questions

APCON builds IntellaView as a combination of chassis, interchangeable blades, switches, and management software. Modular hardware lets customers select capacity and functions for their installation. Its February 2024 announcement included a 32-port 400G EdgeSwitch, a 28-port multi-function blade, and a 16-port 400G blade. The audience includes organizations preparing networks for AI and high-performance computing workloads.

APCON IntellaView packet broker chassis in several rack sizes
Plenty of ports, very little small talk. IntellaView’s chassis family puts the traffic-sorting machinery in the rack.

The speed printed on a port deserves a follow-up question: what can the system process with the required functions enabled? APCON’s current HyperEngine documentation describes up to 400G total throughput across as many as four concurrent service engines. Application filtering, traffic shaping, and pattern matching bring their own configuration considerations. Procurement should follow the workload through the machine, rather than stop at the socket.

Gigamon, Keysight, and NETSCOUT also offer packet-broker and visibility products. Deduplication and load balancing are established market capabilities. APCON’s case rests on its particular mix of modular hardware, management software, traffic processing, and integration with existing tools. A sensible comparison asks which configuration handles the actual traffic, with the actual services running, under the actual purchasing terms.

The conversation inside the server

Virtualization adds a quieter problem. Two virtual machines can exchange traffic inside infrastructure that a physical monitoring point does not observe. APCON announced a virtual-monitoring strategy in 2015, extending its existing visibility architecture toward those conversations. IntellaTap-VM now provides mechanisms for mirroring and filtering virtual traffic and forwarding it to analysis tools.

There is setup behind the promise. In the documented VM monitoring option, customers deploy a compatible virtual machine and use their own virtual-network tools to mirror the traffic of interest. APCON’s management software does not create that VM for them. The useful principle is to choose a capture point where the conversation actually occurs, then establish a route to the tool that needs it.

Managing the resulting fabric is another job. IntellaView Enterprise, launched in March 2024, offers centralized control of up to 200 switches. Connections, alerts, maintenance, and virtual traffic controls become accessible through a shared management system. The benefit is easy to picture: fewer individual devices to visit whenever a configuration or operational task changes.

From carrying evidence to examining it

Richard Rauch founded APCON in 1993 with computer connectivity products in mind. Over time, the company expanded through switching, visibility, packet processing, and capture. Its recent security software follows the same traffic deeper into an investigation. ThreatGuard’s launch announcement was published on April 1, 2026.

ThreatGuard combines live and recorded traffic analysis, intrusion detection, packet evidence, and session metadata. A connection graph shows relationships among hosts and sessions; AI-assisted investigation and mobile notifications add ways to examine and follow events. The product is available as standalone software on customer-provided hardware or integrated with APCON’s IntellaStore IV appliance.

IntellaStore IV combines traffic conditioning, capture, storage, and compute. APCON specifies monitoring ports up to 100G and internal storage up to 32TB. Its included 60-day ThreatGuard trial gives customers a route to testing the combined system. The appliance and the broader 400G switching portfolio serve different roles; their specifications should not be casually exchanged.

The budget belongs to the whole route

APCON sells enterprise hardware, software licenses, and support, through direct sales and a channel program for resellers and systems integrators. Buyers request a quote for their configuration. ThreatGuard is licensed annually; IntellaView Enterprise also has an annual-license tier. The cost calculation includes the hardware, selected software, support, installation, and the tools receiving the traffic.

A named example shows why integrations matter. An APCON and Splunk solution brief describes the State of Arizona using APCON infrastructure to capture, filter, and aggregate traffic, with Splunk Enterprise providing dashboards, alerts, and reporting. Collecting and understanding are separate expenses that have to cooperate. Improving one side can increase the value of the other.

APCON’s work is grounded in physical engineering as well as software. Its published materials describe in-house design, manufacturing, testing, training, and servicing. Its careers page emphasizes integrity, passion, and commitment, with professional development and promotion from within. Those are the employer’s stated values; the manufacturing floor supplies a more concrete image of the business.

Equipment on APCON’s manufacturing floor in Wilsonville, Oregon
The cloud still has a factory somewhere. APCON’s Wilsonville manufacturing floor is one place the packet’s journey becomes hardware.
Two people inspecting a server rack with a laptop
Two sets of eyes, one rack of questions. A server-room photograph used on APCON’s careers page.

Start with the feed

The lesson readers can borrow is a purchasing sequence. Map the traffic that matters. Identify where it can be copied. Measure normal load and bursts. Decide which packets each tool needs, then test the proposed processing chain with those requirements enabled. APCON’s deduplication case study explicitly warns that processing pools can become oversubscribed and that the order of services matters.

The approach depends on access to the traffic and enough capacity throughout the route. Filtering away needed evidence, missing a virtual capture point, or overloading a processing stage defeats the purpose. Packet visibility also needs people and procedures that can investigate what it reveals. A broker supplies a useful feed; the response still has to happen.

APCON’s September 2026 writing turns attention toward internal activity that perimeter monitoring may miss. That gives its move into investigation a coherent rationale. Before an organization buys another pair of electronic eyes, it should inspect what those eyes are being shown. Sometimes the next useful security purchase is the machinery that gets the evidence into view.