A network packet broker is a device that sits between the network and the tools that monitor it. It takes copies of traffic from taps and mirror ports, then aggregates, filters, replicates and forwards them to wherever they need to go. It does not analyse the traffic itself; its job is to make sure each tool receives exactly the traffic it needs and nothing else.
The problem it solves
A large network has more places worth watching than any tool has inputs. Tapping twenty links and feeding four tools means eighty connections if done directly, most of which carry traffic the receiving tool has no use for.
A broker collapses that. Traffic from many taps arrives on its ingress ports, and each monitoring tool gets one egress feed carrying the subset it cares about. Adding a tool becomes a configuration change rather than a cabling project, which matters in environments where touching the production path requires a maintenance window.
What it actually does to the traffic
Four operations cover most deployments. Aggregation combines several links into one stream. Filtering drops traffic a tool does not need, by VLAN, address, port or protocol. Replication sends the same traffic to several tools at once. And load balancing spreads a stream that is too fast for one tool across several, keeping related flows together so each tool sees whole conversations.
Better brokers also tag each packet with the port it arrived on and timestamp it on ingress. Both matter downstream: without port tagging an aggregated stream loses track of where anything came from, and without accurate timestamps the analysis inherits whatever delay the broker added.
Packet broker, tap and capture appliance
These three are often confused because they sit next to each other. A tap copies traffic off a link without disturbing it. A broker decides where those copies go. A capture appliance records and analyses what it receives. They are a chain, not alternatives, and most environments of any size run all three.
Where deduplication becomes a problem
Brokers commonly offer deduplication, removing the extra copies that appear when the same packet is tapped at several points. For most monitoring tools that is helpful. For forensic work it can be the opposite, because seeing the same packet at three points along a path is how you establish where it was delayed or lost.
That is why Corvil Network Capture supports capturing multiple copies from aggregation taps without deduplicating them, and consumes the port tagging and timestamping that leading broker vendors provide. The broker and the capture layer do different jobs; the capture layer works best when the broker has not already discarded the evidence.