Skip to main content

RT3616-4P4S

Data Center Multi-WAN Router Based on Marvell OCTEON 10 CN103 Chip, SONiC, and VPP

The above modules can be mixed and matched, custom combinations are available. Please send us emails for more detailed information!
  • Preloaded AsterNOS-VPP
  • 2 x 8 x 2.5GHz ARM64 Neoverse N2 Core;
  • 16GB pluggable DDR5 SO-DIMM, up to 48G;
  • 2x2x100GE QSFP28, 2x2x10GE SFP+, optional 2x2x2.5GE RJ45;
  • True inline crypto engine;
  • Optional M.2 SSD up to 4TB; Optional 5G/LTE extensible module;
  • Optional PTP module with 20ns accuracy and BC support;
  • 200Gbps intelligent data processing for routing, firewall, IPSec, and SSL/TLS;
  • <200 Watt with FULL configuration and workload.

8 Core ARM 64-bit Neoverse N2 Open Data Center Edge Router Powered by Marvell OCTEON 10 CN103 Chip, SONiC, and VPP

The RT3616 open smart gateway/router delivers high performance and reliability at the edge. Powered by two Marvell OCTEON 10 CN103XX DPUs with 8-core ARM 64-bit Neoverse N2 processors, it supports 2 x 220G throughput with flexible programmable ports. Two CN103XX DPU chips have embedded encryption/decryption engines that have a processing capacity of 200 Gbps. This open smart gateway/router can be configured for dual-node high availability or active-standby operation, ensuring uninterrupted service, enhancing reliability.

Preloaded with AsterNOS-VPP, Asterfusion’s enterprise SONiC routing OS, the platform delivers an out-of-the-box open router requiring no software adaptation. By combining SONiC control plane reliability with DPDK-accelerated VPP forwarding, it supports full Internet BGP scale, OSPFv2/v3, and MP-BGP. Features like 256-way ECMP, Policy-Based Routing, Multi-VRF, and EVPN-VXLAN enable intelligent traffic steering, resilient multi-path load balancing, and secure overlay segmentation.

Application Scenarios


The open enterprise router leverages a hardware-software disaggregated architecture, combining an Enterprise SONiC control plane with a hardware-optimized data plane. This architecture suits diverse application scenarios and flexible deployments.

Cloud Edge

High-performance Cloud edge routing with EVPN-VXLAN and L3 VPN capability.

BNG/BRAS Networking

Subscriber management, PPPoE access termination, and traffic shaping.

Security Gateway

Secure edge connectivity with IPsec/WireGuard VPN

scenarios-data-center-multi-WAN-router

Cloud Edge Gateway: AsterNOS-VPP

  • The Cloud Edge Gateway enables edge routing scenarios for effective egress traffic management and scalable cloud federation.
  • Supporting protocols such as BGP and VXLAN to manage complex traffic for edge gateways.
  • Hardware-optimized vector packet technology and DPDK accelerate data plane forwarding.
  • Enables exact traffic control across apps with comprehensive QoS policies.
ISP BNG-BRAS Networking

ISP BNG/BRAS Networking

  • RT3616: High-Performance BNG/BRAS for Carrier-Grade Networks
  • Granular Session Management: Full IPoE/PPPoE access with integrated AAA & dynamic billing.
  • Multi-dimensional H-QoS: User/Service-based scheduling for IPTV, VoIP, and Data.
scenarios-vpn-gateway

Intelligent Security Gateway: SONiC-VPP + Wireguard

  • AsterNOS-VPP with WireGuard, along with NAT (Network Address Translation) and ACL (Access Control List) functionalities, can serve as a security gateway.
  • Hardware-accelerated VPN with encryption/decryption engine supports up to 100Gbps throughput.

Operating System


AsterNOS-VPP

AsterNOS-VPP bridges SONiC’s robust management control plane with VPP’s vector-based packet processing architecture. Replacing standard SAI with a VPP-integrated translation layer (libsaivpp), it executes L3 routing, firewall, VPN, and NAT at line rate across both hardware and virtual platforms.

To maximize forwarding efficiency, the OS leverages an optimized DPDK framework tightly integrated with Marvell hardware crypto and offload engines. It extends core routing capability through a rich suite of VPP plugins, including QUIC, SRv6, NAT64, LACP, LLDP, and SRTP, enabling granular service expansion without compromising throughput.

AsterNOS-VPP NOS Architecture on Open Edge Router

Rich Software Features


Domain & Location-Based Traffic Control

Leverages GeoIP and GeoSite ACLs to enforce location-aware access policies and domain-based traffic steering. The platform enables automated routing and filtering by dynamically mapping traffic to geographic regions or specific internet services.
Geosite-GeoIP-on data center edge router

Enterprise Edge Security with SPI & uRPF

Integrates Stateful Packet Inspection (SPI) with Unicast Reverse Path Forwarding (uRPF) to protect edge networks. This combined architecture enforces session-aware traffic filtering while validating source IP integrity to prevent IP spoofing and unauthorized access.
SPI-URPF on data center edge router

Wire-speed Encryption and Decryption – IPsec and WireGuard VPN

Features IPsec and WireGuard VPN offloaded to the Marvell OCTEON 10 DPU inline crypto engine, delivering wire-speed encryption and secure enterprise connectivity without taxing CPU performance.
IPSec-on data center edge router

Point-to-Point Layer 2 Encryption – MACSec

Supports MACsec (Media Access Control Security), providing layer 2 encryption for secure, high-speed connectivity across your campus or enterprise network.
ai-ml-hpc

Cloud Edge Router with PTP Support(Optional)

Offers hardware and software support for IEEE 1588 PTPv2, delivering sub-microsecond precision. The platform accommodates key industry profiles, including IEEE 1588v2, G.8275.1, G.8275.2, SMPTE 2059-2, and AES67. It operates flexibly across clock roles, such as Boundary Clock (BC) and Ordinary Clock (OC).
PTP Networking with Open Edge Router

Modern Network Monitoring & Visualization

AsterNOS-VPP supports Node Exporter to send CPU, traffic, packet loss, latency, and RoCE congestion metrics to Prometheus.
Paired with Grafana, it enables real-time, visual insight into network performance.
prometheus-paired-with-grafana

Unified Visualization, Management & O&M with OpenWiFi Network Controller

Integrated with Asterfusion Controller, our Enterprise SONiC edge router enables unified monitoring, ZTP, and automated deployment. It delivers centralized control, real-time visualization, and simplified management across campus WAN edge networks.
Unified Management for Edge Router by OpenWiFi Controller

Specification


Network interface
10GE (SFP+)4 ports2.5GE (RJ45)Option4 ports
100GE (QSFP28)4 portsAntenna(Option)8
5G/LTE (Option)4 SIM cards, M.2 B key
Misc. interface
USB2 x USB3.0Console2 x Console RJ45
MGMT2 x MGMT RJ45
Computing
DPU 2 x Marvell OCTEON 10 CN103
8 Core ARM64 N2 @ 2.5 GHz
Flash2 x 64GB eMMC
Cache capacityL2 8MB, L3 16MBMemory16GB DDR5, maximum 48GB
NVME SSD (Option)2x M.2 NVME (up to 4TB, M.2 M key)
Network performance
L2/L3 Switching capacity2 x 220GbpsRouting capacity2 x 100Gbps
Ingress/Egress ACL Entries2k tables/1000k rulesEncryption and Decryption capacity2 x 100Gbps
PTP/SyncE accuracy20nsPTP/SyncE holdover time> 8hours
Electrical characteristics
Fan2 + 1Power Module1 + 1
Maximum power consumption200W (FULL configuration and workload)Input voltage100~240VAC
Mechanical
Operating temperature0 – 45℃Dimensions (W x H x D mm)440 x 44 x 470
Relative humidity5% - 95% (non-condensing)Height1U

Hardware Panel

Rear view showing redundant power supply and cooling system of Asterfusion ET3616-4P4S network security hardware.

System Architecture

ET3616-System-Architecture

FAQs

How does the RT3616 achieve double the performance of the RT3608 while maintaining a compact 1U form factor?

Both the RT3608 and RT3616 share the same 1U rack-mountable height (440 x 44 x 470 mm). However, while the RT3608 utilizes a single Marvell CN103 DPU (8-core ARM64 @ 2.5GHz) to deliver 100Gbps forwarding and encryption capacity, the RT3616 doubles its hardware capability by integrating two Marvell CN103 DPUs (totaling 16 ARM64 cores @ 2.5GHz). This dual-DPU design effectively doubles the system’s performance to 2 x 100Gbps routing capacity, 2 x 100Gbps IPsec hardware encryption/decryption, and 2 x 220Gbps switching capacity without consuming additional rack space in your data center or WAN hub.

What interface options and hardware expansion capacity does the RT3616 provide?
Powered by its dual-DPU architecture, the RT3616 doubles the network interface density of the RT3608. It features up to 4 x 100GE QSFP28 ports and 4 x 10GE SFP+ ports (structured as 2 x [2 x 100GE + 2 x 10GE]). Additionally, the RT3616 supports flexible hardware expansion, including 2 x M.2 NVMe SSD slots (up to 4TB per SSD), dual 5G/LTE SIM card modules via M.2 B key, management interfaces (2 x USB 3.0, 2 x Console RJ45, and 2 x MGMT GE RJ45), and optional high-precision PTP modules.
How does the RT3616 ensure maximum system resilience and thermal stability under full workloads?

To handle its high-density processing power—with a maximum power consumption of 200W under full configuration and workload—the RT3616 is equipped with robust hardware redundancy. It features a 2+1 redundant fan module setup along with 1+1 redundant hot-swappable power supplies (100~240VAC). On the software layer running AsterNOS-VPP, it supports high-availability features including MC-LAG, VRRP, VRRP Sync Group, BFD, and SLA Link Monitoring to guarantee sub-second failover and continuous operation.

What routing scale and multi-tenant capabilities does the RT3616 support for Enterprise WAN Edge and Broadband Access (BNG)?

The RT3616 includes 2 x 16GB DDR5 memory by default (expandable up to 2 x 48GB), allowing it to support up to 4 Million IPv4/IPv6 host and prefix routes and up to 256k dynamic ARP/ND neighbors. For WAN edge and broadband access deployments, the RT3616 provides:

  • Enterprise WAN Edge: EVPN-VXLAN virtualization, 256-way ECMP/UCMP, GeoSite/GeoIP policy-based routing, and hardware-accelerated IPsec (2k tunnels) and WireGuard (10k tunnels).

  • Service Provider Broadband Access (BNG): PPPoE subscriber termination, Hierarchical QoS (HQoS), CGNAT, MAP-E/MAP-T, and centralized RADIUS AAA integration for large-scale subscriber policy enforcement.

How can network administrators automate management and monitor telemetry on the RT3616?

The RT3616 supports flexible management via the Klish CLI as well as open programmable APIs—including REST API, gNMI, and NETCONF—making it easy to integrate into standard orchestration and DevOps tools. For real-time monitoring, AsterNOS-VPP includes a native AsterNOS Prometheus Exporter container that streams hardware health and network interface metrics directly to a Prometheus server, enabling visual performance tracking on standard Grafana dashboards. Deep traffic inspection is also supported via NetFlow and IPFIX protocols.