24 x 25Gb SFP28, 2 x 100Gb QSFP28, Packet Broker

SKU:

PX202P-24Y-M — 1RU network packet broker with 24× 25G SFP28 + 2× 100G QSFP28, powered by the Marvell Aldrin3 800Gbps (98DX7332) ASIC and PB-APP, a containerized traffic-broker application on open SONiC-based AsterNOS.

  • 48× 25G SFP28 + 2× 100G QSFP28, 800 Gbps non-blocking traffic grooming & filtering in 1RU

  • PB-APP packet broker application — port roles, filtering, tunnel stripping, replication and load balancing

  • 8-tunnel decapsulation with inner 5-tuple matching (GRE, VXLAN, GTP-U, MPLS, ERSPAN, IPinIP, CFP, PPPoE)

  • L2–L4 precision ACL — across 5-tuple, VLAN, MAC, VNI, DSCP and TCP flags

  • 13K wildcard filter entries, hardware truncation down to 128 bytes

  • Optional IEEE 1588v2 PTP Class C (SMPTE 2059-2 / AES67)

  • Hot-swappable 1+1 PSU / 2+1 fans

Request Discount

8 MB

Packet Buffer

800Gbps

Broker Throughput

13K

Wildcard Filter

The PX202P-24Y-M is a 1U network packet broker

that delivers 24× 25G SFP28 ports plus 2× 100G QSFP28 (40G QSFP+ compatible) uplinks for 800 Gbps of processing capacity, with a forwarding rate of 810 Mpps and 8MB of packet buffer. Built on the Marvell Aldrin3 ASIC and running PB-APP, Enterprise SONiC (AsterNOS), Its 100G uplink ports support interface splitting via breakout cables; each 100G port breaks out to 4×25G or 4×10G, so a single packet broker can fan out to a large number of downlink connections with flexible topology choices.

PB-APP: packet broker as a containerized application

PB-APP runs as a container on AsterNOS rather than as a separate operating system, so the switch retains its Enterprise SONiC L2/L3 stack while adding dedicated traffic-orchestration logic. Configuration, rule management, and visualization are handled through a Web UI with drag-and-drop policy workflows and real-time hit counters, alongside CLI, RESTful API, SNMP, Syslog, and Prometheus/Grafana integration for teams standardizing on existing O&M tooling.

Role-based port isolation

Each of the data ports is assigned one of four roles — Network, Service, Tool, or Hybrid — separating production traffic ingress, service-chained inline paths, and tool-facing egress on the same device. This isolation model prevents analysis traffic from being reinjected into the production path.

Deep multi-tunnel parsing

PB-APP decapsulates GRE, VXLAN, GTP-U, MPLS, ERSPAN, IPinIP, CFP, and PPPoE tunnels, then matches inner-layer 5-tuple fields for filtering and load-balancing decisions — supporting visibility into overlay and mobile-core traffic without an upstream decapsulation step.

Multi-dimensional precision ACL

Ingress and egress filtering spans L2, L3, L3V6, EX, EM, and EMV6 rule types, matched against 5-tuple, VLAN, MAC, port range, TCP flags, VNI, DSCP, and inner/outer IP fields, with any combination of fields supported per rule. Rules can be reprioritized, searched, and batch-managed from the Web UI, with hit counters tracked per rule and per policy.

Traffic replication, forwarding, and load balancing

Matched traffic can be mirrored (local SPAN, RSPAN, or ERSPAN to an L3 port), replicated to single ports, LAGs, or combined port+LAG groups, or forwarded/dropped by ACL match. Hardware truncation to 128 bytes reduces the volume sent downstream. Four LAG modes — Flexible, Static, Weight, and Standby — distribute output across tool ports, with custom hash keys, symmetric hashing, and configurable hash seeds to balance probe bandwidth.

Nanosecond timestamping

PB-APP appends packet-level nanosecond timestamps using IEEE 1588v2 PTP synchronization, giving downstream analysis tools a common time reference for performance profiling, security auditing, and fault demarcation.

Passive and inline deployment

The PX202P-24Y-M supports both passive mode, tapping SPAN/RSPAN/ERSPAN sources without sitting in the data path, and inline mode, where the packet broker sits directly between core and edge devices to chain traffic through IPS or firewall tools — reducing the optical transceiver count required for a comparable dedicated-appliance deployment.

Data Plane Ports (100G)2x100GbE QSFP28
Data Plane Ports (25G)24x25GbE SFP28
Switch ASICMarvell Aldrin3
Switching Capacity800Gbps
Forwarding Rate810Mpps
Packet Buffer8MB
Control CPUMarvell CN9130
Flash32GB eMMC
PTP ModuleOptional
Wildcard Filter13K
Power Modules1+1 Hot-swappable
FAN Modules2+1 Hot-swappable
Max Power Consumption168Watt
Input Range100- 240V AC | 36-72V DC
Rack Space1RU
AirflowFront-to-rear
Dimension (HxWxD)44x440x470mm
Management Ports1xUSB2.0, 1xConsole RJ45, 1xMGMT RJ45
Op.Temperature0 - 45℃ (32 to 113°F)
Op. Humidity5% - 90% (non-condensing)

PB-APP Software

PB-APP is Asterfusion's Network Packet Broker application, running as a containerized service on AsterNOS — Asterfusion's enterprise SONiC distribution — directly on standard switching silicon. It brings full NPB traffic orchestration to open, disaggregated hardware: aggregation, filtering, replication, and load balancing at line rate, configured and monitored through an intuitive Web UI. PB-APP ships preloaded with a perpetual software license.

Interface Features
1G/10G, 25G, 40G, 100G, 400G, 800G Ethernet & Management Ports
Flexible Breakout Modes
Port Control: Startup/Shutdown, Startup Delay, FEC, Loopback
Port Types: Service, Network, Tool & Hybrid, with Input/Output Multiplexing
Port Real-time Statistics, Threshold Alarms & Optical Module Info
Header Stripping & Hash Capabilities
Tunnel Stripping: CFP, ERSPAN, GRE, GTP, IPinIP, PPPoE, MPLS, VXLAN
Global Hash: Src/Dst IP, MAC, Port, or Combined
Custom Hash: Src/Dst IP/MAC/Port, Symmetric L2/L3/L4 Hash
Traffic Filtering & Matching (Ingress/Egress)
L2/L3/L3V6 Rule Filtering (VLAN, MAC, IP, Port, Protocol, DSCP, ICMP-Type, Frag)
Advanced Matching: EX Rules, EM/EMV6 Combo Rules, Port Range Matching
Inner Layer Matching (Post Tunnel Stripping / In MPLS Tunnels)
Flexible Rule Actions (VLAN Add/Modify/Delete, Timestamping, Dst MAC Rewrite)
Forward Policy & Load Balancing
SPAN, RSPAN & ERSPAN Traffic Mirroring with 128-byte Truncation
Multi-port/LAG Traffic Replication & Forwarding (with ACL Support)
Load Balancing Modes: Flexible, Static, Weight, Standby (Preemption/Rate-First)
Dynamic Hash Seed Configuration & Fixed LB Members
Rule & Policy Management
Multi-Criteria Rule Search & Range Selection
Priority Adjustment (Highest, Lowest, Policy-Based)
Policy Copying, Re-editing & Color Labeling
Real-time Rule & Policy Hit Counters (Packets/Bytes, Flush & Clean)
Mgmt & Monitoring
Access & Control: Console, SSH, Telnet, CLI, RESTful API, Web UI, RADIUS, TACACS+, Local AAA
Time Sync & File Transfer: PTP, NTP, FTP, TFTP
Online Update & Online Capture
System Monitoring: Millisecond-level Traffic, CPU, Memory, Temperature, Fan & Power Status
DevOps & Exporters: Ansible, LLDP, SNMP, Syslog, Prometheus Exporter

Marvell® Prestera® 98DX73xx

(98DX7332 and family)

The 98DX73xx is a family of carrier-optimized, low-power multilayer Ethernet switches scaling from 200 Gbps to 1.6 Tbps, with port speeds from 1G to 400G. Purpose-built for 5G radio access and carrier edge networks, the devices integrate MACsec, high-precision timing, TSN, eCPRI-awareness, and an embedded Arm® CPU cluster — enabling fronthaul aggregation, cell site gateways, MEC, and edge DCI in a single compact platform.

Architecture & performance

  • Multi-rate 1/2.5/5/10/25/40/50/100/200/400G Ethernet ports support across the family

  • Integrated Arm®-based multi-core CPU cluster for embedded application and service offload

  • Programmable ingress/egress pipelines with dedicated packet buffer and traffic manager

  • Supports 400G-ZR pluggable coherent optical modules for edge DCI connectivity

Timing & synchronization

  • PTP IEEE 1588v1/v2, ITU-T G.8273.2 Class C compliant for nanosecond-scale time accuracy

  • SyncE per ITU-T G.8261/G.8264 frequency recommendations

  • IEEE 802.1CM-2018 Profile B TSN and 802.1Qbu frame preemption for deterministic packet delay control

  • Security — SecureIQ & MACsec

Security — SecureIQ & MACsec

  • Line-rate IEEE 802.1AE MACsec GCM-AES-128/256 and GCM-AES-XPN-128/256 on all network-facing ports

  • SecureIQ: secure boot, secured storage, programmable security sensors, and micro-segmentation to security groups

  • SCT / NST control and management plane protection; DDoS mitigation and encrypted traffic analytics

Telemetry, intelligence & programmability

  • TrackIQ: line-rate flow-aware telemetry, per-packet latency measurement, elephant/mice flow detection, anomaly detection

  • NetIQ: programmable processing engines with eCPRI and GTP awareness for in-network compute and auto-healing

  • Overlay support: VXLAN, VXLAN-GPE, Geneve, IP-GRE, EVPN, SRv6, MPLS-SR

  • Hardware OAM: IEEE 802.1ag, ITU-T Y.1731, MPLS OAM, ITU-T G.8113.1

Ordering information

Part NumberPort ConfigurationBandwidth
98DX73088 × 25G200 Gbps
98DX73128 × 25G + 1 × 100G-R4300 Gbps
98DX732020 × 25G500 Gbps
98DX732424 × 25G / 6 × 100G-R4600 Gbps
98DX733232 × 25G / 8 × 100G-R4800 Gbps
98DX732120 × 50G1 Tbps
98DX732524 × 50G / 6 × 200G / 3 × 400G1.2 Tbps
98DX733532 × 50G / 8 × 200G / 4 × 400G1.6 Tbps
Network packet broker family datasheet Network Packet Broker Datasheet (PDF)
Quick start guide for AsterNOS CLI AsterNOS Documentation

The dual 1+1 hot-swappable power supplies ensure continuous operation by allowing replacement without system shutdown.

Equipped with 2+1 hot-swappable fan modules, the system delivers reliable cooling performance to maintain stability and efficiency under demanding workloads.

CERTIFICATEISO 9001ISO 9001ISO 14001ISO 14001ISO 45001ISO 45001ISO 27001ISO 27001FCCFCCCECE
SCOPEQuality management systemEnvironmental managementOccupational health and safetyInformation security managementUS radio frequency complianceEU health, safety and environmental compliance