The popular notion about span and tap is to tap where you can and span where you must. Both measures have usecases dependent on your environment. However, for total visibility it is advisable to use a tap.
Yes. Niagara provides SSL/TLS decryption platform that supports multiple version of SSL and TLS, including the latest TLS1.3. SSL/TLS flows are dynamically detected from the traffic flow, and detection is not just limited to standard ports such as 443.
Yes. Niagara's open system architecture allows 3rd party vendors or end users to integrate virtualized applications such as Accedian, Darktrace, Qwilt, Fireeye, Splunk, Palo Alto, Fortinet, forcepoint, A10 etc.