Skip to main content

RT3608-2P2S

Data Center Edge Router Based on Marvell OCTEON 10 CN103 Chip, SONiC, and VPP

The above modules can be mixed and matched, custom combinations are available. Please send us emails for more detailed information!
  • Preloaded AsterNOS-VPP
  • 8 x 2.5GHz ARM64 Neoverse N2 Core;
  • 16GB pluggable DDR5 SO-DIMM, up to 48G;
  • 2 x 100GE QSFP28, 2x10GE SFP+
  • True inline crypto engine;
  • Optional M.2 SSD up to 4TB; Optional 5G/LTE extensible module;
  • Optional PTP module with 20ns accuracy and BC support;
  • 100Gbps intelligent data processing for routing, firewall, IPSec, and SSL/TLS;
  • <100 Watt with FULL configuration and workload.

8 Core ARM 64-bit Neoverse N2 Open Data Center Edge Router Powered by Marvell OCTEON 10 CN103 Chip, SONiC, and VPP

The RT3608 is a 1U compact, open intelligent gateway designed specifically for large-scale enterprise edge, carrier, and data center environments. It supports up to one Marvell OCTEON 10 CN103XX DPU, each integrating an 8-core ARM Neoverse N2 processor, programmable Ethernet ports with a bidirectional throughput of 220 Gbps, and an embedded encryption/decryption engine with a processing capacity of 100 Gbps.

Preloaded with AsterNOS-VPP, Asterfusion’s enterprise SONiC routing OS, the platform delivers an out-of-the-box open router requiring no software adaptation. By combining SONiC control plane reliability with DPDK-accelerated VPP forwarding, it supports full Internet BGP scale, OSPFv2/v3, and MP-BGP. Features like 256-way ECMP, Policy-Based Routing, Multi-VRF, and EVPN-VXLAN enable intelligent traffic steering, resilient multi-path load balancing, and secure overlay segmentation.

Application Scenarios


The open enterprise router leverages a hardware-software disaggregated architecture, combining an Enterprise SONiC control plane with a hardware-optimized data plane. This architecture suits diverse application scenarios and flexible deployments.

Cloud Edge

High-performance Cloud edge routing with EVPN-VXLAN and L3 VPN capability.

BNG/BRAS Networking

Subscriber management, PPPoE access termination, and traffic shaping.

Security Gateway

Secure edge connectivity with IPsec/WireGuard VPN

scenarios-Cloud-data-center-edge-router

Cloud Edge Gateway: AsterNOS-VPP

  • The Cloud Edge Gateway enables edge routing scenarios for effective egress traffic management and scalable cloud federation.
  • Supporting protocols such as BGP and VXLAN to manage complex traffic for edge gateways.
  • Hardware-optimized vector packet technology and DPDK accelerate data plane forwarding.
  • Enables exact traffic control across apps with comprehensive QoS policies.
ISP BNG-BRAS Networking

ISP BNG/BRAS Networking

  • RT3608: High-Performance BNG/BRAS for Carrier-Grade Networks
  • Granular Session Management: Full IPoE/PPPoE access with integrated AAA & dynamic billing.
  • Multi-dimensional H-QoS: User/Service-based scheduling for IPTV, VoIP, and Data.
scenarios-vpn-gateway

Intelligent Security Gateway: SONiC-VPP + Wireguard

  • AsterNOS-VPP with WireGuard, along with NAT (Network Address Translation) and ACL (Access Control List) functionalities, can serve as a security gateway.
  • Hardware-accelerated VPN with encryption/decryption engine supports up to 100Gbps throughput.

Operating System


AsterNOS-VPP

AsterNOS-VPP bridges SONiC’s robust management control plane with VPP’s vector-based packet processing architecture. Replacing standard SAI with a VPP-integrated translation layer (libsaivpp), it executes L3 routing, firewall, VPN, and NAT at line rate across both hardware and virtual platforms.

To maximize forwarding efficiency, the OS leverages an optimized DPDK framework tightly integrated with Marvell hardware crypto and offload engines. It extends core routing capability through a rich suite of VPP plugins, including QUIC, SRv6, NAT64, LACP, LLDP, and SRTP, enabling granular service expansion without compromising throughput.

AsterNOS-VPP NOS Architecture on Open Edge Router

Rich Software Features


Domain & Location-Based Traffic Control

Leverages GeoIP and GeoSite ACLs to enforce location-aware access policies and domain-based traffic steering. The platform enables automated routing and filtering by dynamically mapping traffic to geographic regions or specific internet services.
Geosite-GeoIP-on data center edge router

Enterprise Edge Security with SPI & uRPF

Integrates Stateful Packet Inspection (SPI) with Unicast Reverse Path Forwarding (uRPF) to protect edge networks. This combined architecture enforces session-aware traffic filtering while validating source IP integrity to prevent IP spoofing and unauthorized access.
SPI-URPF on data center edge router

Wire-speed Encryption and Decryption – IPsec and WireGuard VPN

Features IPsec and WireGuard VPN offloaded to the Marvell OCTEON 10 DPU inline crypto engine, delivering wire-speed encryption and secure enterprise connectivity without taxing CPU performance.
IPSec-on data center edge router

Point-to-Point Layer 2 Encryption – MACSec

Supports MACsec (Media Access Control Security), providing layer 2 encryption for secure, high-speed connectivity across your campus or enterprise network.
ai-ml-hpc

Cloud Edge Router with PTP Support(Optional)

Offers hardware and software support for IEEE 1588 PTPv2, delivering sub-microsecond precision. The platform accommodates key industry profiles, including IEEE 1588v2, G.8275.1, G.8275.2, SMPTE 2059-2, and AES67. It operates flexibly across clock roles, such as Boundary Clock (BC) and Ordinary Clock (OC).
PTP Networking with Open Edge Router

Modern Network Monitoring & Visualization

AsterNOS-VPP supports Node Exporter to send CPU, traffic, packet loss, latency, and RoCE congestion metrics to Prometheus.
Paired with Grafana, it enables real-time, visual insight into network performance.
prometheus-paired-with-grafana

Unified Visualization, Management & O&M with OpenWiFi Network Controller

Integrated with Asterfusion Controller, our Enterprise SONiC edge router enables unified monitoring, ZTP, and automated deployment. It delivers centralized control, real-time visualization, and simplified management across campus WAN edge networks.
Unified Management for Edge Router by OpenWiFi Controller

Specification


Network interface
10GE (SFP+)2 ports2.5GE (RJ45)Option2 ports
100GE (QSFP28)2 portsAntenna(Option)4
5G/LTE (Option)2 SIM cards, M.2 B key
Misc. interface
USB1 x USB3.0Console1 x Console RJ45
MGMT1 x MGMT RJ45
Computing
DPU Marvell OCTEON 10 CN103
8 Core ARM64 N2 @ 2.5 GHz
Flash1 x 64GB eMMC
Cache capacityL2 8MB, L3 16MBMemory16GB DDR5, maximum 48GB
NVME SSD (Option)up to 4TB, M.2 M key
Network performance
L2/L3 Switching capacity220GbpsRouting capacity100Gbps
Ingress/Egress ACL Entries2k tables/1000k rulesEncryption and Decryption capacity100Gbps
PTP/SyncE accuracy20nsPTP/SyncE holdover time> 8hours
Electrical characteristics
Fan1 + 1Power Module1 + 1
Maximum power consumption100W (FULL configuration and workload)Input voltage100~240VAC
Mechanical
Operating temperature0 – 45℃Dimensions (W x H x D mm)440 x 44 x 470
Relative humidity5% - 95% (non-condensing)Height1U

Hardware Panel

FAQs

How does the RT3608 achieve 100Gbps line-rate IPsec VPN encryption without bottlenecking the system?

Traditional x86 routers often hit a severe CPU bottleneck when processing encrypted traffic at 100Gbps. The RT3608 solves this by pairing a Marvell OCTEON CN103 DPU (8-core ARM64 @ 2.5GHz) with a dedicated true inline crypto engine. By offloading cryptographic operations (such as AES-GCM-256) directly to hardware, the RT3608 delivers 100Gbps encrypted throughput simultaneously with 100Gbps Layer 3 routing forwarding, freeing the CPU entirely for control plane and policy processing.

Can the RT3608 handle massive BGP routing tables and dynamic session scaling in enterprise Data Center Interconnect (DCI) or high-density WAN hubs?
Yes. Designed for enterprise WAN hubs and service provider access, the RT3608 comes with 16GB DDR5 memory (expandable to 48GB). In its default configuration, it supports up to 1.2 Million IPv4/IPv6 host and prefix routes, and scales up to 4 Million routes with memory upgrade. It also supports 256-way ECMP, 64k/128k dynamic neighbor table scaling, and up to 10,000 WireGuard / 2,000 IPsec VPN tunnels, making it fully equipped for full-table BGP peering and large-scale overlay networks.
What high-availability (HA) and hardware redundancy features does the RT3608 provide for mission-critical deployments?

Unlike smaller edge appliances, the RT3608 is built in a standard 440mm-wide 1RU chassis featuring 1+1 redundant hot-swappable power supplies (PSUs) and 1+1 redundant fans, ensuring zero downtime from power or thermal failures. On the software layer, running AsterNOS-VPP, it supports enterprise high-availability features like MC-LAG, VRRP, VRRP Sync Group, BFD, and SLA Link Monitoring for sub-second failover in active-backup or active-active topologies.

How does the RT3608 fit into a modern Multi-WAN and Broadband Access (BNG/PPPoE) deployment?

Equipped with dual 100GE QSFP28 and dual 10GE SFP+ ports, the RT3608 serves a dual purpose:

  • For Enterprise WAN Edge: It offers application-aware traffic steering via GeoSite/GeoIP ACLs, EVPN-VXLAN virtualization, and Multi-WAN policy routing.

  • For Service Providers / BNG: It acts as a broadband access gateway supporting PPPoE subscriber termination, Hierarchical QoS (HQoS), CGNAT, and RADIUS AAA interaction for centralized subscriber policy control at 100Gbps speeds.

How can network engineers monitor the real-time performance and telemetry of an RT3608 cluster?

The RT2508 supports both traditional network management via Klish CLI and modern network automation via REST API, gNMI, and NETCONF. Because AsterNOS-VPP runs as a containerized Linux-based OS, it includes a native AsterNOS Prometheus Exporter container. You can instantly export real-time platform metrics, interface stats, and telemetry to your Prometheus server and visualize them directly on standard Grafana dashboards.

How does the RT2508 handle 5G/LTE cellular connectivity compared to traditional USB-dongle-based edge routers?

The RT3608 eliminates proprietary, closed-box monitoring. Its containerized OS includes a native AsterNOS Prometheus Exporter container that streams system health, port bandwidth utilization, hardware temperature, and traffic statistics to your centralized Prometheus server. Engineers can instantly monitor the device using standard Grafana dashboards or export flow data via NetFlow and IPFIX for deep traffic analysis.