/
Open Router OS Powered by SONiC & VPP
Open SONiC + VPP
Software-defined router & firewall on x86 and OCTEON DPUs — no vendor lock-in.
Line-Rate L3 at Scale
2M RIB, BGP full tables, OSPF, ECMP/UCMP and VXLAN BGP-EVPN.
Carrier Services Built In
NAT, CGNAT, MAP-T, PPPoE and Multi-WAN, secured with IPsec & WireGuard.
Free to Try, Ready to Scale
Run free on any x86 VM, then scale to 50G / 100G on OCTEON appliances.
AsterNOS-VPP is a SONiC-based network operating system
that pairs SONiC's proven, switch-grade control plane with VPP (Vector Packet Processing) as a software-defined, programmable data plane. Running on both ARM and x86 architectures, it transforms standard servers and merchant DPUs into next-generation routers and firewalls — without locking you into proprietary hardware.
Under the hood, AsterNOS-VPP substitutes the standard libsai.so with libsaivpp.so, translating SAI commands into VPP API calls so that packet forwarding executes on the DPU or CPU with high efficiency. The result is line-rate performance for the network functions that matter most: L3 routing, NAT, PPPoE and VPN — all managed through the same operational model network teams already use across Asterfusion switches and routers.
Open NOS with a software-defined data plane
A variant of the open-source SONiC ecosystem, AsterNOS-VPP keeps SONiC's containerized, Linux-kernel-based architecture and rich Layer-2/Layer-3 feature set, while VPP handles high-throughput forwarding. This delivers an open, disaggregated alternative to traditional fixed-function routers from Cisco, Arista and Dell.
Line-rate routing and rich Layer 3
AsterNOS-VPP supports line-rate L3 routing with 2M RIB entries, including BGP full routing tables and BGP/MP-BGP peering, OSPFv2/v3, policy-based routing, VRF, ECMP/UCMP and VXLAN BGP-EVPN with multihoming — ready for service-provider and data center edge roles.
Carrier-grade and broadband IP services
Built-in NAT, CGNAT and MAP-T let operators share public IPv4 addresses via large-scale NAPT and perform stateless IPv4-to-IPv6 translation. Integrated PPPoE client and server support authentication, billing and IP assignment, while Multi-WAN routing distributes traffic across multiple ISPs or paths by policy.
Security and VPN
Secure, encrypted connectivity is delivered through IPsec and WireGuard VPN, complemented by N-tuple wild-match ACLs, Dynamic ARP Inspection, IP Source Guard, DHCP/ND snooping and interface-based storm suppression for fine-grained, stateful traffic control.
High availability and automation
Carrier-class resilience is provided by MC-LAG, VRRP, BFD, Monitor Link and SLA tracking. As part of the SONiC ecosystem, AsterNOS-VPP inherits a consistent operations model — ZTP, Klish CLI, RESTful API (OpenStack-interoperable), gNMI, NetConf/YANG and uCentral — for NetDevOps-style automation.
Built-in observability
Streaming telemetry and monitoring are native: NetFlow/IPFIX for real-time flow analysis, a Prometheus Exporter for system and network metrics, SNMP v1/v2/v3, and SPAN/RSPAN/ERSPAN for deep packet visibility.
Flexible editions and deployment
AsterNOS-VPP is available as a free edition for x86 virtual machines (KVM or VMware ESXi, minimum 4 cores / 4GB RAM with DPDK-supported NICs) — ideal for evaluation, lab, and proof-of-concept. For production line-rate throughput, hardware-accelerated licensed editions run on Marvell OCTEON appliances: the E2 edition (OCTEON CN102, 50 Gbps) and the M3 edition (OCTEON CN103, 100 Gbps), licensed perpetually with an annual major-version upgrade subscription.
| Feature | Free | Commercial (X86 VM) | Commercial (ARM) |
|---|
Port Speed
| 1G/100M/10M | |||
|---|---|---|---|
| 2.5G | |||
| 10G/100G |
Port Config
| (no shutdown) / shut down | |||
|---|---|---|---|
| start delay |
PoE Features
| PoE Enable/Disable | |||
|---|---|---|---|
| Power delay | |||
| 30W / 60W | |||
| Priority: Low/High / Critical | |||
| Legacy Detect | |||
| PoE Timer Control | |||
| LLDP PoE Negotiation | |||
| PoE Power Monitor |
Interface Stats
| Packets / Octets / Errors / Drops / Speed |
|---|
Module Info
| Presence / Absence | |||
|---|---|---|---|
| Vendor info | |||
| Optical Power |
Bandwidth Alert
| RX / TX Thresholds | |||
|---|---|---|---|
| Both Threshold |
Batch Config
| H/W Interfaces |
|---|
Loopback Interface
| 64 x Loopback |
|---|
LAN Interface
| 4×2.5G/1G + 8×1G/100M/10M RJ45 |
|---|
WAN Interface
| 10G SFP+ | |||
|---|---|---|---|
| PPPoE / DHCP / Static IP |
MAC
| Static MAC | |||
|---|---|---|---|
| MAC Learning | |||
| MAC Migration | |||
| MAC Flush | |||
| MAC Learning Enable/Disable | |||
| Black Hole MAC | |||
| MAC Flapping | |||
| MAC Limit | |||
| MAC Show |
VLAN
| VLAN Create/Delete | |||
|---|---|---|---|
| VLAN Member | |||
| BUM Forward Configuration Flood/Drop | |||
| Batch Configure VLAN | |||
| Show VLAN and VLAN Member |
QinQ
| 802.1aq VLAN tag |
|---|
LAG
| Create/Delete LAG | |||
|---|---|---|---|
| LAG Mode Support Static or Dynamic(LACP) | |||
| LAG Member |
STP/MSTP
| Enable/Disable | |||
|---|---|---|---|
| MSTP Instance Create, Support Priority Setting | |||
| Interface Status Transfer Time | |||
| BPDU Send Interval | |||
| Max BPDU Aging Time | |||
| Set STP Area Name | |||
| Security, Support BPDU Filter/Guard | |||
| Show MSTP Tree |
LLDP
| Disable/Enable | |||
|---|---|---|---|
| LLDP Neighbor Information | |||
| MgmtIP Configuration | |||
| PortId Subtype |
MVRP
| - |
|---|
Port Isolation
| - |
|---|
Static Routing
| - |
|---|
VRF
| L3 Port Isolation | |||
|---|---|---|---|
| VLAN IF Isolation | |||
| LAG IF Isolation | |||
| Neighbor Isolation | |||
| LPM Isolation | |||
| Inter-VRF Forwarding |
PBR
| - |
|---|
BGP / MP-BGP
| IBGP / EBGP | |||
|---|---|---|---|
| BGP Neighbor configration | |||
| Peer Group | |||
| BGP Listen | |||
| Distance setting | |||
| Routing redistribute | |||
| BGP best-path select | |||
| BGP Route Reflector | |||
| Graceful restart | |||
| Linkage BGP with BFD | |||
| BGP routing policy |
OSPF v2/v3
| - |
|---|
RIP v1/v2
| - |
|---|
Routing Policy
| Route Map | |||
|---|---|---|---|
| Prefix List (v4/v6) |
ECMP/UCMP
| - |
|---|
Dynamic LSP
| LDP |
|---|
Static LSP
| Support multi nexthop |
|---|
Basic MPLS
| Enable/disable on phy port |
|---|
L2VPN
| Static/dynamic VPWS, VPLS |
|---|
L3VPN
| - |
|---|
NAT
| 1:1 NAT | |||
|---|---|---|---|
| 1:1 NAT | |||
| Port Forwards | |||
| TCP MSS Clamping | |||
| Static / Dynamic Mapping | |||
| Sub-Port Support | |||
| Support phy port/VLAN IF/LAG/Loopback | |||
| SNAT/DNAT/DNAT POOL |
L3 Interface
| Create/Delete L3 Interface | |||
|---|---|---|---|
| IPv4/v6 Address | |||
| Alloc IPv4/IPv6 Address by DHCP Client | |||
| Configure MAC Address | |||
| Configure MTU | |||
| L3 Sub Interface |
ARP/NDP
| Static ARP/NDP Configuration | |||
|---|---|---|---|
| Dynamic ARP/NDP | |||
| Dynamic ARP/NDP Migration | |||
| Dynamic ARP/NDP Aging Interval | |||
| ARP/NDP Detection |
ARP/ND to Host
| - |
|---|
DHCPv4 Server
| Bind address pool to VLAN IF or phy port | |||
|---|---|---|---|
| Configure the address lease period | |||
| Information carried by server | |||
| Allocate Address Policy | |||
| DHCP Option Group | |||
| Option93/82 | |||
| Show Address Pool Policy | |||
| DNS Server Configuration | |||
| DHCP Failover |
DHCPv4 Relay
| DHCP Server Address | |||
|---|---|---|---|
| Uplink Port | |||
| Downlink Port | |||
| Agent IP | |||
| Option82 |
DHCPv6 Server
| Bind address pool to VLAN IF or phy port | |||
|---|---|---|---|
| Configure the address lease period | |||
| DNS Server |
DHCPv6 Relay
| DHCP Server Address | |||
|---|---|---|---|
| Uplink Port | |||
| Downlink Port | |||
| Agent IP |
DNS
| DNS Proxy | |||
|---|---|---|---|
| DNS cache name resolver,cache( A/AAAA) |
MAP-E
| - |
|---|
MAP-T
| - |
|---|
IGMP Snooping
| Enable/Disable IGMP Snooping | |||
|---|---|---|---|
| Static IGMP Snooping | |||
| Dynamic IGMP Snooping | |||
| Support IGMP Protocol Version(v1/v2/v3) | |||
| Entry Limit Based on IGMP Member Port | |||
| IGMP Snooping Mulicast Query | |||
| IGMP Snooping Proxy |
MLD Snooping
| Enable/Disable MLD Snooping | |||
|---|---|---|---|
| Static MLD Snooping | |||
| Dynamic MLD Snooping | |||
| Support MLD Protocol Version(v1/v2) | |||
| Entry Limit Based on Member Port | |||
| MLD Snooping Multicast Query | |||
| MLD Snooping Proxy |
PIM
| PIM Version Support v4 and v6 | |||
|---|---|---|---|
| PIM Sparse Mode | |||
| SPT Mode | |||
| Enable/Disable PIM | |||
| Support phy port/VLAN IF/LAG |
VXLAN
| VTEP Address Support IPv4 | |||
|---|---|---|---|
| Dynamic VXLAN Tunnel Configuration | |||
| VXLAN Gateway | |||
| EVPN VXLAN | |||
| encap format(v4 over v4, v6 over v4) | |||
| VXLAN Stats encap/decap |
L2TPv3 VPN
| - |
|---|
IPsec VPN
| Route Based VPN | |||
|---|---|---|---|
| Policy-Based (bypass / discard / protect) | |||
| IKEv2 | |||
| Diffie-Hellman (DH) |
BUM Packet Policy Based on Interface
| - |
|---|
Storm Suppression Based on Interface
| - |
|---|
System User Access Control Policy
| - |
|---|
DHCP v4/v6 Snooping
| - |
|---|
ND Snooping
| - |
|---|
ND Policy
| - |
|---|
DAI (Dynamic ARP Inspection)
| - |
|---|
IPSG v4/v6
| - |
|---|
ACL
| Ingress/Egress | |||
|---|---|---|---|
| Match: MAC/IP/L3/L4 Fields | |||
| Permit/Deny | |||
| Hit Statistics | |||
| Port/LAG/VLAN/SubIF Bind | |||
| CtrlPlane (NTP/SNMP/SSH/Telnet) | |||
| DNS/GeoIP/Geosite | |||
| Stateless/Stateful |
*SPI(Stateful packet inspection)
| - |
|---|
Unicast Reverse Path Forwarding (uRPF)
| - |
|---|
PPPoE Client
| - |
|---|
PPPoE Server
| - |
|---|
Ipsec VPN
| - |
|---|
Wireguard Security VPN
| - |
|---|
Priority Mapping
| dot1p to tc | |||
|---|---|---|---|
| dscp to tc | |||
| tc to queue |
Queue Schedule
| Strict | |||
|---|---|---|---|
| DWRR |
Rate Limit (RFC2697/2698/4115)
| per port | |||
|---|---|---|---|
| per queue |
Shaping
| per interface |
|---|
Flow Classify
| IACL + CAR Binding | |||
|---|---|---|---|
| EACL | |||
| CAR (Committed Access Rate) |
QoS Status
| Show Interface QoS Statistics |
|---|
HQoS
| Sub/User-Level | |||
|---|---|---|---|
| Service-Level(VOIP/Video/Internet) | |||
| App-Level (DSCP: EF/AF41/CS3/AF21) |
MC-LAG
| - |
|---|
VRRP
| Backup group (HW/VLAN IF) | |||
|---|---|---|---|
| VRRPv3 (RFC5798) | |||
| Advertise interval / priority config | |||
| Master auto send ARP/ND |
BFD
| - |
|---|
Monitor Link
| - |
|---|
SLA
| - |
|---|
Routing Track
| - |
|---|
Hash
| - |
|---|
SPAN/ ERSPAN
| - |
|---|
SNMP
| - |
|---|
NetFlow/IPFIX
| - |
|---|
Prometheus exporter
| - |
|---|
Dot1x
| - |
|---|
System User/Privilege Management
| Local User Authentication | |||
|---|---|---|---|
| Radius User Authentication | |||
| TACACS+User Authentication | |||
| Add/Change User ID/Password |
Login Method
| out-of-band serial console | |||
|---|---|---|---|
| SSH | |||
| Telnet | |||
| in-band management |
Management
| MGMT IP Address | |||
|---|---|---|---|
| MGMT Gateway | |||
| MGMT VRF |
Troubleshooting Information
| SONiC Bash Show Tech Support |
|---|
ZTP (Zero Touch Provisioning)
| - |
|---|
Configure Host Name
| - |
|---|
System Time Management
| - |
|---|
License Management
| - |
|---|
FTP/TFTP
| - |
|---|
Device Status Summary
| - |
|---|
Critical Resource Monitoring (CRM)
| - |
|---|
NTP Client
| - |
|---|
Log management
| - |
|---|
Diagnostic Tools
| Ping | |||
|---|---|---|---|
| Traceroute |
SONiC-VPP Routing OS
AsterNOS-VPP is a production-hardened SONiC routing OS with VPP as the data-plane engine. The full feature set ships pre-activated on RT2500 series routers — no per-feature license keys, no add-on modules to purchase separately.