RT3616-4P4S
Data Center Multi-WAN Router Based on Marvell OCTEON 10 CN103 Chip, SONiC, and VPP
The above modules can be mixed and matched, custom combinations are available. Please send us emails for more detailed information!
-
Preloaded AsterNOS-VPP
-
2 x 8 x 2.5GHz ARM64 Neoverse N2 Core;
-
16GB pluggable DDR5 SO-DIMM, up to 48G;
-
2x2x100GE QSFP28, 2x2x10GE SFP+, optional 2x2x2.5GE RJ45;
-
True inline crypto engine;
-
Optional M.2 SSD up to 4TB; Optional 5G/LTE extensible module;
-
Optional PTP module with 20ns accuracy and BC support;
-
200Gbps intelligent data processing for routing, firewall, IPSec, and SSL/TLS;
-
<200 Watt with FULL configuration and workload.
8 Core ARM 64-bit Neoverse N2 Open Data Center Edge Router Powered by Marvell OCTEON 10 CN103 Chip, SONiC, and VPP
The RT3616 open smart gateway/router delivers high performance and reliability at the edge. Powered by two Marvell OCTEON 10 CN103XX DPUs with 8-core ARM 64-bit Neoverse N2 processors, it supports 2 x 220G throughput with flexible programmable ports. Two CN103XX DPU chips have embedded encryption/decryption engines that have a processing capacity of 200 Gbps. This open smart gateway/router can be configured for dual-node high availability or active-standby operation, ensuring uninterrupted service, enhancing reliability.
Preloaded with AsterNOS-VPP, Asterfusion’s enterprise SONiC routing OS, the platform delivers an out-of-the-box open router requiring no software adaptation. By combining SONiC control plane reliability with DPDK-accelerated VPP forwarding, it supports full Internet BGP scale, OSPFv2/v3, and MP-BGP. Features like 256-way ECMP, Policy-Based Routing, Multi-VRF, and EVPN-VXLAN enable intelligent traffic steering, resilient multi-path load balancing, and secure overlay segmentation.
Application Scenarios
The open enterprise router leverages a hardware-software disaggregated architecture, combining an Enterprise SONiC control plane with a hardware-optimized data plane. This architecture suits diverse application scenarios and flexible deployments.
Cloud Edge
High-performance Cloud edge routing with EVPN-VXLAN and L3 VPN capability.
BNG/BRAS Networking
Subscriber management, PPPoE access termination, and traffic shaping.
Security Gateway
Secure edge connectivity with IPsec/WireGuard VPN
Cloud Edge Gateway: AsterNOS-VPP
- The Cloud Edge Gateway enables edge routing scenarios for effective egress traffic management and scalable cloud federation.
- Supporting protocols such as BGP and VXLAN to manage complex traffic for edge gateways.
- Hardware-optimized vector packet technology and DPDK accelerate data plane forwarding.
- Enables exact traffic control across apps with comprehensive QoS policies.
ISP BNG/BRAS Networking
- RT3616: High-Performance BNG/BRAS for Carrier-Grade Networks
- Granular Session Management: Full IPoE/PPPoE access with integrated AAA & dynamic billing.
- Multi-dimensional H-QoS: User/Service-based scheduling for IPTV, VoIP, and Data.
Intelligent Security Gateway: SONiC-VPP + Wireguard
- AsterNOS-VPP with WireGuard, along with NAT (Network Address Translation) and ACL (Access Control List) functionalities, can serve as a security gateway.
- Hardware-accelerated VPN with encryption/decryption engine supports up to 100Gbps throughput.
Operating System
AsterNOS-VPP
AsterNOS-VPP bridges SONiC’s robust management control plane with VPP’s vector-based packet processing architecture. Replacing standard SAI with a VPP-integrated translation layer (libsaivpp), it executes L3 routing, firewall, VPN, and NAT at line rate across both hardware and virtual platforms.
To maximize forwarding efficiency, the OS leverages an optimized DPDK framework tightly integrated with Marvell hardware crypto and offload engines. It extends core routing capability through a rich suite of VPP plugins, including QUIC, SRv6, NAT64, LACP, LLDP, and SRTP, enabling granular service expansion without compromising throughput.
Rich Software Features
Domain & Location-Based Traffic Control
Domain & Location-Based Traffic Control
Enterprise Edge Security with SPI & uRPF
Enterprise Edge Security with SPI & uRPF
Wire-speed Encryption and Decryption – IPsec and WireGuard VPN
Wire-speed Encryption and Decryption – IPsec and WireGuard VPN
Point-to-Point Layer 2 Encryption – MACSec
Point-to-Point Layer 2 Encryption – MACSec
Cloud Edge Router with PTP Support(Optional)
Modern Network Monitoring & Visualization
Unified Visualization, Management & O&M with OpenWiFi Network Controller
Specification
|
Hardware Panel
System Architecture
FAQs
Both the RT3608 and RT3616 share the same 1U rack-mountable height (440 x 44 x 470 mm). However, while the RT3608 utilizes a single Marvell CN103 DPU (8-core ARM64 @ 2.5GHz) to deliver 100Gbps forwarding and encryption capacity, the RT3616 doubles its hardware capability by integrating two Marvell CN103 DPUs (totaling 16 ARM64 cores @ 2.5GHz). This dual-DPU design effectively doubles the system’s performance to 2 x 100Gbps routing capacity, 2 x 100Gbps IPsec hardware encryption/decryption, and 2 x 220Gbps switching capacity without consuming additional rack space in your data center or WAN hub.
To handle its high-density processing power—with a maximum power consumption of 200W under full configuration and workload—the RT3616 is equipped with robust hardware redundancy. It features a 2+1 redundant fan module setup along with 1+1 redundant hot-swappable power supplies (100~240VAC). On the software layer running AsterNOS-VPP, it supports high-availability features including MC-LAG, VRRP, VRRP Sync Group, BFD, and SLA Link Monitoring to guarantee sub-second failover and continuous operation.
The RT3616 includes 2 x 16GB DDR5 memory by default (expandable up to 2 x 48GB), allowing it to support up to 4 Million IPv4/IPv6 host and prefix routes and up to 256k dynamic ARP/ND neighbors. For WAN edge and broadband access deployments, the RT3616 provides:
-
Enterprise WAN Edge: EVPN-VXLAN virtualization, 256-way ECMP/UCMP, GeoSite/GeoIP policy-based routing, and hardware-accelerated IPsec (2k tunnels) and WireGuard (10k tunnels).
-
Service Provider Broadband Access (BNG): PPPoE subscriber termination, Hierarchical QoS (HQoS), CGNAT, MAP-E/MAP-T, and centralized RADIUS AAA integration for large-scale subscriber policy enforcement.
The RT3616 supports flexible management via the Klish CLI as well as open programmable APIs—including REST API, gNMI, and NETCONF—making it easy to integrate into standard orchestration and DevOps tools. For real-time monitoring, AsterNOS-VPP includes a native AsterNOS Prometheus Exporter container that streams hardware health and network interface metrics directly to a Prometheus server, enabling visual performance tracking on standard Grafana dashboards. Deep traffic inspection is also supported via NetFlow and IPFIX protocols.



