16 x 1Gb RJ45, 2 x 10Gb SFP+, Network Packet Broker

SKU:

PX102S-16GT-M-DPU — 1RU network packet broker with 16× 1G RJ45 + 2× 10G SFP+, powered by the Marvell AlleyCat5Y 70Gbps (98DX2556) ASIC and PB-APP, a containerized traffic-broker application on open SONiC-based AsterNOS.

  • 16× 1G RJ45 + 2× 10G SFP+, 70 Gbps non-blocking traffic grooming & filtering in 1RU

  • PB-APP packet broker application — port roles, filtering, tunnel stripping, replication and load balancing

  • 8-tunnel decapsulation with inner 5-tuple matching (GRE, VXLAN, GTP-U, MPLS, ERSPAN, IPinIP, CFP, PPPoE)

  • L2–L4 precision ACL — across 5-tuple, VLAN, MAC, VNI, DSCP and TCP flags

  • 3K wildcard filter entries, hardware truncation down to 128 bytes

  • Optional IEEE 1588v2 PTP Class A (SMPTE 2059-2)

  • Build-in 1 PSU / 2 fans

Request Discount

3 MB

Packet Buffer

70 Gbps

Broker Throughput

3K

Wildcard Filter

PX102S-16GT-M is a 16× 1GbE RJ45 + 2× 10G SFP+ Network Packet Broker, combining the CX102S-16GT-M switch hardware with PB-APP installed as the traffic-processing software layer. Built on the Marvell Prestera 98DX2556 (AlleyCat 5Y) switch ASIC running Enterprise SONiC (AsterNOS), it delivers 70 Gbps of processing capacity in a 1U form factor — positioned for branch offices, small data centers, and edge monitoring points with a limited number of 1G/10G links to tap.

With 3K wildcard filter entries on the hardware-level packet truncation, PB-APP adds port-role assignment, rule-based filtering, tunnel stripping, and load-balanced distribution — covering both the traffic tap and the traffic-processing logic of a small-scale visibility deployment from one 1U box.

PB-APP: packet broker as a containerized application

PB-APP runs as a container on AsterNOS rather than as a separate operating system, so the switch retains its Enterprise SONiC L2/L3 stack while adding dedicated traffic-orchestration logic. Configuration, rule management, and visualization are handled through a Web UI with drag-and-drop policy workflows and real-time hit counters, alongside CLI, RESTful API, SNMP, Syslog, and Prometheus/Grafana integration for teams standardizing on existing O&M tooling.

Role-based port isolation

Each of the data ports is assigned one of four roles — Network, Service, Tool, or Hybrid — separating production traffic ingress, service-chained inline paths, and tool-facing egress on the same device. This isolation model prevents analysis traffic from being reinjected into the production path.

Deep multi-tunnel parsing

PB-APP decapsulates GRE, VXLAN, GTP-U, MPLS, ERSPAN, IPinIP, CFP, and PPPoE tunnels, then matches inner-layer 5-tuple fields for filtering and load-balancing decisions — supporting visibility into overlay and mobile-core traffic without an upstream decapsulation step.

Multi-dimensional precision ACL

Ingress and egress filtering spans L2, L3, L3V6, EX, EM, and EMV6 rule types, matched against 5-tuple, VLAN, MAC, port range, TCP flags, VNI, DSCP, and inner/outer IP fields, with any combination of fields supported per rule. Rules can be reprioritized, searched, and batch-managed from the Web UI, with hit counters tracked per rule and per policy.

Traffic replication, forwarding, and load balancing

Matched traffic can be mirrored (local SPAN, RSPAN, or ERSPAN to an L3 port), replicated to single ports, LAGs, or combined port+LAG groups, or forwarded/dropped by ACL match. Hardware truncation to 128 bytes reduces the volume sent downstream. Four LAG modes — Flexible, Static, Weight, and Standby — distribute output across tool ports, with custom hash keys, symmetric hashing, and configurable hash seeds to balance probe bandwidth.

Nanosecond timestamping

PB-APP appends packet-level nanosecond timestamps using IEEE 1588v2 PTP synchronization, giving downstream analysis tools a common time reference for performance profiling, security auditing, and fault demarcation.

Passive and inline deployment

The PX102S-16GT-M supports both passive mode, tapping SPAN/RSPAN/ERSPAN sources without sitting in the data path, and inline mode, where the packet broker sits directly between core and edge devices to chain traffic through IPS or firewall tools — reducing the optical transceiver count required for a comparable dedicated-appliance deployment.

Data Plane Ports (10G)2x10GbE SFP+
Data Plane Ports (1G)16x1GbE RJ45
Switch ASICMarvell Allleycat 5Y
Switching Capacity70Gbps
Packet Buffer3MB
Control CPUCortex-A55
Control Plane Memory4GB DDR4/32GB eMMC
Wildcard Filter (ACL) Entries3K
PTP ModuleOptional
Management Ports1xRJ45 serial console, 1xUSB2.0
Power Module1 Built-in
FAN Modules2 Built-in
Max Power Consumption21Watt
Input Range100- 240V AC
Rack Space1RU
AirflowFront to Rear
Dimension (HxWxD)44x215x310mm
Weight2.2KG
Op.Temperature0 - 45℃ (32 to 113°F)
Op. Humidity5% - 90% (non-condensing)

PB-APP Software

PB-APP is Asterfusion's Network Packet Broker application, running as a containerized service on AsterNOS — Asterfusion's enterprise SONiC distribution — directly on standard switching silicon. It brings full NPB traffic orchestration to open, disaggregated hardware: aggregation, filtering, replication, and load balancing at line rate, configured and monitored through an intuitive Web UI. PB-APP ships preloaded with a perpetual software license.

Interface Features
1G/10G, 25G, 40G, 100G, 400G, 800G Ethernet & Management Ports
Flexible Breakout Modes
Port Control: Startup/Shutdown, Startup Delay, FEC, Loopback
Port Types: Service, Network, Tool & Hybrid, with Input/Output Multiplexing
Port Real-time Statistics, Threshold Alarms & Optical Module Info
Header Stripping & Hash Capabilities
Tunnel Stripping: CFP, ERSPAN, GRE, GTP, IPinIP, PPPoE, MPLS, VXLAN
Global Hash: Src/Dst IP, MAC, Port, or Combined
Custom Hash: Src/Dst IP/MAC/Port, Symmetric L2/L3/L4 Hash
Traffic Filtering & Matching (Ingress/Egress)
L2/L3/L3V6 Rule Filtering (VLAN, MAC, IP, Port, Protocol, DSCP, ICMP-Type, Frag)
Advanced Matching: EX Rules, EM/EMV6 Combo Rules, Port Range Matching
Inner Layer Matching (Post Tunnel Stripping / In MPLS Tunnels)
Flexible Rule Actions (VLAN Add/Modify/Delete, Timestamping, Dst MAC Rewrite)
Forward Policy & Load Balancing
SPAN, RSPAN & ERSPAN Traffic Mirroring with 128-byte Truncation
Multi-port/LAG Traffic Replication & Forwarding (with ACL Support)
Load Balancing Modes: Flexible, Static, Weight, Standby (Preemption/Rate-First)
Dynamic Hash Seed Configuration & Fixed LB Members
Rule & Policy Management
Multi-Criteria Rule Search & Range Selection
Priority Adjustment (Highest, Lowest, Policy-Based)
Policy Copying, Re-editing & Color Labeling
Real-time Rule & Policy Hit Counters (Packets/Bytes, Flush & Clean)
Mgmt & Monitoring
Access & Control: Console, SSH, Telnet, CLI, RESTful API, Web UI, RADIUS, TACACS+, Local AAA
Time Sync & File Transfer: PTP, NTP, FTP, TFTP
Online Update & Online Capture
System Monitoring: Millisecond-level Traffic, CPU, Memory, Temperature, Fan & Power Status
DevOps & Exporters: Ansible, LLDP, SNMP, Syslog, Prometheus Exporter

Marvell® Prestera® 98DX25xx (98DX2556 and family)

The 98DX25xx is a family of low-power Ethernet switches for cost-sensitive enterprise/SMB access and cloud edge, supporting 1/2.5GbE network access ports with 10GbE uplink and stacking. Built as an upgrade to the Prestera 98DX33xx/32xx/22xx/23xx family, the devices offer enlarged table scales, an enhanced multilayer feature set, improved security, and higher CPU subsystem performance, with an optimized RBOM design suited for unmanaged, cloud-managed, and full L2/L3-managed access platforms.

Architecture & performance

  • Multi-rate 1G/2.5G/5G/10G/22G port support via QSGMII Switch-PHY interface, carrying multiple 10M/100M/1G Ethernet ports over a single SerDes lane

  • 10G uplink and stacking ports

  • Integrated Arm® Cortex dual-core CPU with additional Arm co-processors offloading real-time applications from the host CPU, and high-capacity DDR3/DDR4 support

  • Single clock input and unified power rails for optimized RBOM; advanced process node delivering more than 20% power savings over the prior generation

Timing & synchronization

  • SyncE frequency synchronization

Security — SecureIQ

  • SecureIQ: secure boot and secured storage

  • SCT / NST control and management plane protection; reactive DDoS mitigation

Telemetry & intelligence

  • Entry-level cloud edge telemetry for network visibility, actionable analytics, and troubleshooting

Network packet broker family datasheet Network Packet Broker Datasheet (PDF)
Quick start guide for AsterNOS CLI AsterNOS Documentation

CERTIFICATE

ISO 9001ISO 9001

ISO 14001ISO 14001

ISO 45001ISO 45001

ISO 27001ISO 27001

FCCFCC

CECE

SCOPE

Quality management system

Environmental management

Occupational health and safety

Information security management

US radio frequency compliance

EU health, safety and environmental compliance