Case Study for Network Packet Brokers – Improving Alibaba Data Center Network Visibility
written by Asterfuison
Table of Contents
Customer Background
Alibaba, as a global leading multinational technology company, is headquartered in China. Its business has expanded from its early focus on e-commerce to a broad range of areas, including domestic and international retail, local consumer services, logistics, cloud computing, and digital media. This expansion has created a comprehensive ecosystem that connects merchants, consumers, brands, and service providers.
Today, Alibaba is no longer limited to e-commerce. It has evolved into a platform-based enterprise spanning commerce, cloud, and digital services. With continuous global expansion and technology investment, Alibaba operates across multiple regions worldwide and continues to increase investment in cloud data centers and AI infrastructure.
However, with rapid business growth, its underlying network infrastructure faces increasingly demanding requirements. In addition to high-performance data transmission, the network must ensure stable visibility, data security, and compliance management. In complex multi-data-center interconnection scenarios, Alibaba requires advanced traffic collection, replication, distribution, filtering, and analysis capabilities to support the deployment of critical security and monitoring tools and provide unified operational assurance across distributed environments.
Based on these requirements, Alibaba selected our next-generation Network Packet Broker (NPB) solution and products powered by SONiC.
Why Choose Asterfusion
SONiC-Based Network Packet Broker 2.0 Era
The transition from P4-based solutions marks the beginning of the SONiC-based NPB 2.0 era. Built on the industry-proven SONiC open-source architecture and commercial switching ASICs, Asterfusion simplifies feature implementation complexity while providing a wide range of advanced capabilities.
With a modular container-based control plane architecture, failures or maintenance activities of individual modules are isolated within their respective containers. This design improves overall system reliability and ensures stable operation.
Flexible Port Options and Scalable Port Density
Asterfusion provides a complete portfolio of port speeds from 1G to 800G, offering flexible port configurations and bandwidth combinations to meet different deployment requirements. Based on the customer’s specific business needs, this project deployed devices equipped with 48 × 10G SFP+ ports and 6 × 100G QSFP28 ports.
Standard Open APIs and Automated Operations
Asterfusion supports standard interfaces, including SSH, WebUI, RESTful API, and NETCONF, along with Prometheus/Grafana-based monitoring and visualization. These capabilities enable seamless integration with existing automated operations and monitoring platforms (NetOps) used by large-scale internet enterprises, reducing operational complexity and improving management efficiency.
Over 10 Years of Industry Experience and Technical Support
With more than 10 years of experience in the NPB field, Asterfusion has accumulated extensive expertise and technical capabilities through continuous development and innovation. Based on previous successful collaboration, both parties have established long-term trust and cooperation. This proven customization capability and strong technical support provide the foundation for customers to select and rely on Asterfusion.
Network Deployment Architecture
In this project, considering the requirements of cross-data-center deployment scenarios and compliance management, the customer deployed 20 high-performance Network Packet Broker platforms — CX206P-48S-M. Based on this architecture, the customer built a highly resilient and software-defined network visibility infrastructure.

1. Distributed Standalone Deployment and Topology Planning
This project includes 20 CX206P-48S-M devices deployed in a standalone mode, where each device independently handles efficient traffic ingress and egress processing. The deployment covers core network locations across multiple regions:
- Headquarters data centers: Four core data center sites, with one device deployed in each site.
- Business node data centers: One device deployed in each of the remaining 16 critical business node sites.
The CX206P-48S-M provides a combination of 10G and 100G interfaces to support different network traffic scenarios:
- 48 × 10G ports: Used for flexible connections to service switches, traffic mirroring sources, and medium- to low-speed analysis devices.
- 6 × 100G high-speed ports: Used for high-capacity uplinks or connections to high-speed analysis clusters, providing high-performance non-blocking forwarding capabilities.
Through this distributed Network Packet Broker architecture, the customer achieved local traffic collection, centralized processing, and intelligent distribution across multiple data centers. This approach avoids traffic aggregation bottlenecks caused by traditional centralized deployments and improves overall network visibility and security analysis efficiency.
2. Integration with Security Ecosystem
As the traffic collection solution supporting QAX Tianyan threat detection and analysis platform, including the Tianyan Analysis Platform and Tianyan Probes, CX206P-48S-M plays a critical role as the traffic delivery layer within the security architecture.
Mirrored traffic from service switches in Alibaba’s data center sites is connected to the physical ports of CX206P-48S-M through 10G/100G links. After advanced traffic filtering and scheduling, high-value traffic is delivered to QAX security appliances, enabling full-traffic real-time auditing and supporting security compliance requirements.
3. Core Feature Implementation
During production operation, CX206P-48S-M leverages its integrated hardware and software capabilities to enable four key functions in this deployment:
- Traffic Aggregation: Mirrored traffic from service network switches (SPAN/RSPAN) is connected to CX206P-48S-M through 10G/100G links for 100% traffic collection and lossless aggregation. This enables stable transmission and processing of more than 600G traffic.
- Deep Traffic Filtering: Based on hardware-level ACL rules customized on the SONiC platform, CX206P-48S-M performs Layer 2–Layer 4 traffic filtering on incoming packets. Unnecessary background traffic, such as large file transfers and routine backup traffic, is removed, while high-value security and business analysis traffic is forwarded to downstream tools. Based on specific business scenarios, the customer successfully filtered out 10%–40% of low-value background traffic. This reduced the need for security probe expansion and licensing costs while preventing packet loss caused by CPU overload on security appliances.
- Traffic Replication: The solution supports one-to-many traffic replication, allowing the same critical traffic stream to be duplicated and distributed to multiple downstream analysis and monitoring tools. This meets requirements for multi-dimensional security analysis.
- Load Balancing: By using chip-level Equal-Cost Multipath (ECMP) mechanisms, traffic is intelligently distributed to backend security analysis clusters based on source/destination IP addresses, flow information, and other hashing criteria. This prevents packet loss caused by temporary congestion on individual analysis devices.
Deployment Results & Customer Feedback
1. Deployment Results
Through this large-scale distributed standalone deployment, 20 CX206P-48S-M devices work together to build a full-stack network visibility infrastructure covering multiple data centers across different regions.
The deployment eliminates traffic visibility silos in cross-domain environments and enables precise delivery of filtered and optimized high-value traffic to the backend QAX security analysis clusters. This fully meets enterprise requirements for security compliance, real-time auditing, and rapid fault isolation during periods of rapid business growth.
2. Customer Feedback and Evaluation
After successful delivery and stable operation of the system, the customer highly recognized the network visibility solution, especially the improvements in software interaction and overall user experience:
- Smooth and User-Friendly Web UI: Compared with the complex and less intuitive interfaces commonly found in traditional networking solutions, Asterfusion’s Web UI provides a more responsive and intuitive user experience. The customer commented that: “More than 10 years of industry experience truly makes a difference. The initial dashboard is clear at a glance, with key metrics and functions easily accessible, significantly reducing the operational complexity for daily maintenance.”

- Ease of Use Enabled by SONiC Architecture: SONiC improves network operational flexibility by breaking network functions into standardized and modular components. Based on Linux, Redis, containers, and SAI, SONiC abstracts hardware differences at the underlying layer, simplifying deployment, integration, upgrades, and automation. This architecture provides a more efficient operational experience for frontline operations and security teams, reducing operational complexity while improving management efficiency.
Summary
Facing challenges from multi-data-center interconnection, rapid business expansion, and increasingly strict security and compliance requirements, Alibaba selected Asterfusion’s next-generation Network Packet Broker solution based on the SONiC architecture. The deployment successfully built a full-stack network visibility infrastructure covering multiple data centers.
Through the distributed deployment and centralized management of 20 CX206P-48S-M devices, the project enabled efficient traffic aggregation, filtering, replication, and load distribution. It effectively established end-to-end traffic collection capabilities across different domains and significantly improved security auditing and fault isolation efficiency.
Leveraging the SONiC open architecture, standardized interface framework, and flexible automation capabilities, the Asterfusion solution not only met the customer’s requirements for high performance, reliability, and scalability but also gained strong recognition in deployment simplicity, integration flexibility, and operational efficiency. It has become a key infrastructure capability supporting Alibaba’s next-generation security visibility architecture.