/
16 x 1Gb RJ45, 2 x 10Gb SFP+, Network Packet Broker
3 MB
Packet Buffer
70 Gbps
Broker Throughput
3K
Wildcard Filter
PX102S-16GT-M is a 16× 1GbE RJ45 + 2× 10G SFP+ Network Packet Broker, combining the CX102S-16GT-M switch hardware with PB-APP installed as the traffic-processing software layer. Built on the Marvell Prestera 98DX2556 (AlleyCat 5Y) switch ASIC running Enterprise SONiC (AsterNOS), it delivers 70 Gbps of processing capacity in a 1U form factor — positioned for branch offices, small data centers, and edge monitoring points with a limited number of 1G/10G links to tap.
With 3K wildcard filter entries on the hardware-level packet truncation, PB-APP adds port-role assignment, rule-based filtering, tunnel stripping, and load-balanced distribution — covering both the traffic tap and the traffic-processing logic of a small-scale visibility deployment from one 1U box.
PB-APP: packet broker as a containerized application
PB-APP runs as a container on AsterNOS rather than as a separate operating system, so the switch retains its Enterprise SONiC L2/L3 stack while adding dedicated traffic-orchestration logic. Configuration, rule management, and visualization are handled through a Web UI with drag-and-drop policy workflows and real-time hit counters, alongside CLI, RESTful API, SNMP, Syslog, and Prometheus/Grafana integration for teams standardizing on existing O&M tooling.
Role-based port isolation
Each of the data ports is assigned one of four roles — Network, Service, Tool, or Hybrid — separating production traffic ingress, service-chained inline paths, and tool-facing egress on the same device. This isolation model prevents analysis traffic from being reinjected into the production path.
Deep multi-tunnel parsing
PB-APP decapsulates GRE, VXLAN, GTP-U, MPLS, ERSPAN, IPinIP, CFP, and PPPoE tunnels, then matches inner-layer 5-tuple fields for filtering and load-balancing decisions — supporting visibility into overlay and mobile-core traffic without an upstream decapsulation step.
Multi-dimensional precision ACL
Ingress and egress filtering spans L2, L3, L3V6, EX, EM, and EMV6 rule types, matched against 5-tuple, VLAN, MAC, port range, TCP flags, VNI, DSCP, and inner/outer IP fields, with any combination of fields supported per rule. Rules can be reprioritized, searched, and batch-managed from the Web UI, with hit counters tracked per rule and per policy.
Traffic replication, forwarding, and load balancing
Matched traffic can be mirrored (local SPAN, RSPAN, or ERSPAN to an L3 port), replicated to single ports, LAGs, or combined port+LAG groups, or forwarded/dropped by ACL match. Hardware truncation to 128 bytes reduces the volume sent downstream. Four LAG modes — Flexible, Static, Weight, and Standby — distribute output across tool ports, with custom hash keys, symmetric hashing, and configurable hash seeds to balance probe bandwidth.
Nanosecond timestamping
PB-APP appends packet-level nanosecond timestamps using IEEE 1588v2 PTP synchronization, giving downstream analysis tools a common time reference for performance profiling, security auditing, and fault demarcation.
Passive and inline deployment
The PX102S-16GT-M supports both passive mode, tapping SPAN/RSPAN/ERSPAN sources without sitting in the data path, and inline mode, where the packet broker sits directly between core and edge devices to chain traffic through IPS or firewall tools — reducing the optical transceiver count required for a comparable dedicated-appliance deployment.
PB-APP Software
PB-APP is Asterfusion's Network Packet Broker application, running as a containerized service on AsterNOS — Asterfusion's enterprise SONiC distribution — directly on standard switching silicon. It brings full NPB traffic orchestration to open, disaggregated hardware: aggregation, filtering, replication, and load balancing at line rate, configured and monitored through an intuitive Web UI. PB-APP ships preloaded with a perpetual software license.
Interface Features
Header Stripping & Hash Capabilities
Traffic Filtering & Matching (Ingress/Egress)
Forward Policy & Load Balancing
Rule & Policy Management
Mgmt & Monitoring
Marvell® Prestera® 98DX25xx (98DX2556 and family)
The 98DX25xx is a family of low-power Ethernet switches for cost-sensitive enterprise/SMB access and cloud edge, supporting 1/2.5GbE network access ports with 10GbE uplink and stacking. Built as an upgrade to the Prestera 98DX33xx/32xx/22xx/23xx family, the devices offer enlarged table scales, an enhanced multilayer feature set, improved security, and higher CPU subsystem performance, with an optimized RBOM design suited for unmanaged, cloud-managed, and full L2/L3-managed access platforms.
Architecture & performance
Multi-rate 1G/2.5G/5G/10G/22G port support via QSGMII Switch-PHY interface, carrying multiple 10M/100M/1G Ethernet ports over a single SerDes lane
10G uplink and stacking ports
Integrated Arm® Cortex dual-core CPU with additional Arm co-processors offloading real-time applications from the host CPU, and high-capacity DDR3/DDR4 support
Single clock input and unified power rails for optimized RBOM; advanced process node delivering more than 20% power savings over the prior generation
Timing & synchronization
SyncE frequency synchronization
Security — SecureIQ
SecureIQ: secure boot and secured storage
SCT / NST control and management plane protection; reactive DDoS mitigation
Telemetry & intelligence
Entry-level cloud edge telemetry for network visibility, actionable analytics, and troubleshooting
| Network packet broker family datasheet | Network Packet Broker Datasheet (PDF) |
| Quick start guide for AsterNOS CLI | AsterNOS Documentation |
CERTIFICATE |
|
|
|
|
|
|
SCOPE | Quality management system | Environmental management | Occupational health and safety | Information security management | US radio frequency compliance | EU health, safety and environmental compliance |