48 x 25Gb SFP28, 8 x 100Gb QSFP28, Packet Broker

SKU:

PX308P-48Y-M — 1RU network packet broker with 48× 25G SFP28 + 8× 100G QSFP28, powered by the Marvell Prestera Falcon 2.0T (98CX8514) ASIC and PB-APP, a containerized traffic-broker application on open SONiC-based AsterNOS.

  • 48× 25G SFP28 +8× 100G QSFP28, 2.0 Tbps non-blocking traffic grooming & filtering in 1RU

  • PB-APP packet broker application — port roles, filtering, tunnel stripping, replication and load balancing

  • 8-tunnel decapsulation with inner 5-tuple matching (GRE, VXLAN, GTP-U, MPLS, ERSPAN, IPinIP, CFP, PPPoE)

  • L2–L4 precision ACL — across 5-tuple, VLAN, MAC, VNI, DSCP and TCP flags

  • 4.5K wildcard filter entries, hardware truncation down to 128 bytes

  • Optional IEEE 1588v2 PTP Class C (SMPTE 2059-2 / AES67)

  • Hot-swappable 1+1 PSU / 3+1 fans

Request Discount

24MB

Packet Buffer

2.0 Tbps

Broker Throughput

4.5K

Wildcard Filter

The PX308P-48Y-M is a 1U network packet broker

that delivers 48× 25G SFP28 downlink ports plus 8× 100G QSFP28 uplinks for 2.0 Tbps of processing capacity, with a wildcard filter of 4.5K and 24MB of packet buffer for non-blocking performance. Built on the Marvell Prestera Falcon ASIC and running PB-APP is a containerized packet broker application on AsterNOS that filters, replicates, and load-balances traffic without a dedicated NPB appliance. Every 100G uplink breaks out to 4×25G or 4×10G, so a single switch can fan out to a large number of downlink connections with flexible topology choices.

PB-APP: packet broker as a containerized application

PB-APP runs as a container on AsterNOS rather than as a separate operating system, so the switch retains its Enterprise SONiC L2/L3 stack while adding dedicated traffic-orchestration logic. Configuration, rule management, and visualization are handled through a Web UI with drag-and-drop policy workflows and real-time hit counters, alongside CLI, RESTful API, SNMP, Syslog, and Prometheus/Grafana integration for teams standardizing on existing O&M tooling.

Role-based port isolation

Each of the data ports is assigned one of four roles — Network, Service, Tool, or Hybrid — separating production traffic ingress, service-chained inline paths, and tool-facing egress on the same device. This isolation model prevents analysis traffic from being reinjected into the production path.

Deep multi-tunnel parsing

PB-APP decapsulates GRE, VXLAN, GTP-U, MPLS, ERSPAN, IPinIP, CFP, and PPPoE tunnels, then matches inner-layer 5-tuple fields for filtering and load-balancing decisions — supporting visibility into overlay and mobile-core traffic without an upstream decapsulation step.

Multi-dimensional precision ACL

Ingress and egress filtering spans L2, L3, L3V6, EX, EM, and EMV6 rule types, matched against 5-tuple, VLAN, MAC, port range, TCP flags, VNI, DSCP, and inner/outer IP fields, with any combination of fields supported per rule. Rules can be reprioritized, searched, and batch-managed from the Web UI, with hit counters tracked per rule and per policy.

Traffic replication, forwarding, and load balancing

Matched traffic can be mirrored (local SPAN, RSPAN, or ERSPAN to an L3 port), replicated to single ports, LAGs, or combined port+LAG groups, or forwarded/dropped by ACL match. Hardware truncation to 128 bytes reduces the volume sent downstream. Four LAG modes — Flexible, Static, Weight, and Standby — distribute output across tool ports, with custom hash keys, symmetric hashing, and configurable hash seeds to balance probe bandwidth.

Nanosecond timestamping

PB-APP appends packet-level nanosecond timestamps using IEEE 1588v2 PTP synchronization, giving downstream analysis tools a common time reference for performance profiling, security auditing, and fault demarcation.

Passive and inline deployment

The PX308P-48Y-M supports both passive mode, tapping SPAN/RSPAN/ERSPAN sources without sitting in the data path, and inline mode, where the packet broker sits directly between core and edge devices to chain traffic through IPS or firewall tools — reducing the optical transceiver count required for a comparable dedicated-appliance deployment.

Data Plane Ports (100G)8x100GbE QSFP28
Data Plane Ports (25G)48x25GbE SFP28
Switch ASICMarvell Prestera Falcon
Switching Capacity2.0Tbps
Forwarding Rate2600Mpps
Packet Buffer24MB
Control CPUPentium D1508
Flash128GB M.2 SATA
PTP ModuleOptional
Wildcard Filter4.5K
Power Module1+1 Hot-swappable
FAN Modules3+1 Hot-swappable
Input Range100-240V AC | 36-72V DC
Max Power Consumption480Watt
Rack Space1U
Management Ports1xUSB2.0, 1xConsole RJ45, 1xMGMT RJ45
AirflowFront-to-rear | Rear-to-front
Dimension (HxWxD)44x440x515mm
Op.Temperature0 - 45℃
Op. Humidity5% - 90% (non-condensing)

PB-APP Software

PB-APP is Asterfusion's Network Packet Broker application, running as a containerized service on AsterNOS — Asterfusion's enterprise SONiC distribution — directly on standard switching silicon. It brings full NPB traffic orchestration to open, disaggregated hardware: aggregation, filtering, replication, and load balancing at line rate, configured and monitored through an intuitive Web UI. PB-APP ships preloaded with a perpetual software license.

Interface Features
1G/10G, 25G, 40G, 100G, 400G, 800G Ethernet & Management Ports
Flexible Breakout Modes
Port Control: Startup/Shutdown, Startup Delay, FEC, Loopback
Port Types: Service, Network, Tool & Hybrid, with Input/Output Multiplexing
Port Real-time Statistics, Threshold Alarms & Optical Module Info
Header Stripping & Hash Capabilities
Tunnel Stripping: CFP, ERSPAN, GRE, GTP, IPinIP, PPPoE, MPLS, VXLAN
Global Hash: Src/Dst IP, MAC, Port, or Combined
Custom Hash: Src/Dst IP/MAC/Port, Symmetric L2/L3/L4 Hash
Traffic Filtering & Matching (Ingress/Egress)
L2/L3/L3V6 Rule Filtering (VLAN, MAC, IP, Port, Protocol, DSCP, ICMP-Type, Frag)
Advanced Matching: EX Rules, EM/EMV6 Combo Rules, Port Range Matching
Inner Layer Matching (Post Tunnel Stripping / In MPLS Tunnels)
Flexible Rule Actions (VLAN Add/Modify/Delete, Timestamping, Dst MAC Rewrite)
Forward Policy & Load Balancing
SPAN, RSPAN & ERSPAN Traffic Mirroring with 128-byte Truncation
Multi-port/LAG Traffic Replication & Forwarding (with ACL Support)
Load Balancing Modes: Flexible, Static, Weight, Standby (Preemption/Rate-First)
Dynamic Hash Seed Configuration & Fixed LB Members
Rule & Policy Management
Multi-Criteria Rule Search & Range Selection
Priority Adjustment (Highest, Lowest, Policy-Based)
Policy Copying, Re-editing & Color Labeling
Real-time Rule & Policy Hit Counters (Packets/Bytes, Flush & Clean)
Mgmt & Monitoring
Access & Control: Console, SSH, Telnet, CLI, RESTful API, Web UI, RADIUS, TACACS+, Local AAA
Time Sync & File Transfer: PTP, NTP, FTP, TFTP
Online Update & Online Capture
System Monitoring: Millisecond-level Traffic, CPU, Memory, Temperature, Fan & Power Status
DevOps & Exporters: Ansible, LLDP, SNMP, Syslog, Prometheus Exporter

Marvell® Prestera® Falcon 2.0T–12.8T (Prestera 98CX85xx family)

The CX-N-V2 data center switch family is built on Marvell’s 9th-generation, 16nm Prestera Falcon packet processors, scaling from 2.0 Tbps leaf platforms through 3.2 Tbps spine/leaf designs to 12.8 Tbps high-radix spine switches within the same merchant-silicon architecture. Falcon pairs large shared L2/L3 forwarding and LPM tables with a globally shared, dynamic-threshold packet buffer for superior microburst absorption under heavy east-west load. Exposing the standard SAI and TAM APIs, it is what lets open SONiC-based AsterNOS run consistently across the entire CX-N-V2 line — with no proprietary forwarding stack and no feature licensing.

Architecture & performance

  • 9th-generation, 16nm Marvell Prestera Falcon — 2.0 Tbps to 12.8 Tbps wire-speed switching across the 98CX85xx family

  • Large shared tables: 128K MAC, 288K IPv4 / 144K IPv6 prefixes, high-scale multi-tenant L2/L3

  • Globally shared packet buffer with dynamic thresholds for microburst (µBurst) absorption

  • Cut-through switching and dynamic load balancing (DLB) across the fabric

Virtualization & overlays

  • eBridge unified virtualization architecture with hardware-based interface/domain virtualization

  • Programmable header editor: hardware-accelerated VXLAN, VXLAN-GPE, Geneve and NSH

  • MPLS and IPv6 segment routing for flexible transport

RDMA, telemetry & openness

  • RoCEv2-aware congestion management for lossless RDMA storage and AI/ML traffic

  • In-band network telemetry built into the data path — sFlow, IPFIX, remote port analysis

  • Open Switch Abstraction Interface (SAI) + Telemetry & Monitoring (TAM) APIs — merchant-silicon foundation for SONiC/AsterNOS

Network packet broker family datasheet Network Packet Broker Datasheet (PDF)
Quick start guide for AsterNOS CLI AsterNOS Documentation

The dual 1+1 hot-swappable power supplies ensure continuous operation by allowing replacement without system shutdown.

Equipped with 3+1 hot-swappable fan modules, the system delivers reliable cooling performance to maintain stability and efficiency under demanding workloads.

CERTIFICATEISO 9001ISO 9001ISO 14001ISO 14001ISO 45001ISO 45001ISO 27001ISO 27001FCCFCCCECE
SCOPEQuality management systemEnvironmental managementOccupational health and safetyInformation security managementUS radio frequency complianceEU health, safety and environmental compliance