NVIDIA DOCA 2.5 BlueField Appliance

NVIDIA DOCA 2.5 BlueField Appliance

Brand: NVIDIA | Category: Network Security

SKU: NVID-BF3DOCAAPPL25 | Part #: BF3-DOCA-APPL-25 | MPN: BF3-DOCA-APPL-25

Contact for Pricing — Request a Quote

Request a Quote Contact Us

About the NVIDIA DOCA 2.5 BlueField Appliance

The NVIDIA DOCA 2.5 BlueField Appliance is a purpose-built network security appliance anchored by the NVIDIA BlueField-3 Data Processing Unit, combining programmable Arm Cortex-A78 cores with a 400 Gbps ConnectX-7 network engine in a single hardened platform. Running the NVIDIA DOCA 2.5 software framework, the appliance exposes a unified API surface for constructing stateful firewall pipelines, cryptographic offload, deep packet inspection, and telemetry collection entirely within the DPU data path—freeing host CPU cycles for application workloads while enforcing policy at line rate.

The appliance is architected for zero-trust enforcement at the infrastructure layer, making it suitable for east-west microsegmentation between bare-metal servers, virtualized environments, and containerized workloads. DOCA 2.5 introduces enhanced service chaining capabilities, allowing operators to compose ordered security functions—including TLS 1.3 decryption, intrusion detection sensor integration, and flow-based analytics—without introducing additional appliance hops. Hardware-accelerated IPsec and TLS offload engines natively embedded in the BlueField-3 ASIC sustain cryptographic throughput that software-only solutions cannot match at comparable power envelopes.

Launched in 2025-Q3, this appliance addresses the growing enterprise requirement for a SmartNIC-class security enforcement point that is operationally transparent to host operating systems and hypervisors. Integration with NVIDIA DOCA App Shield enables runtime attestation and memory telemetry of host workloads directly from the DPU, adding a lateral inspection capability that complements perimeter controls. The result is a converged compute-and-security platform suited to hyperscale data centers, sovereign cloud deployments, financial services infrastructure, and any environment where encrypted traffic volumes and east-west traffic densities have outpaced conventional firewall appliance throughput.

Ideal for

  • East-west microsegmentation enforcement between bare-metal and virtualized server workloads in multi-tenant data centers, isolating tenant traffic without requiring host agent software
  • Inline TLS 1.3 and IPsec encrypted traffic inspection for compliance-driven environments such as financial services and healthcare, offloading cryptographic operations from host CPUs
  • Zero-trust infrastructure enforcement at the server NIC layer for sovereign cloud and government data center deployments requiring hardware-attested policy enforcement
  • High-frequency trading and low-latency financial workload protection where kernel-bypass RDMA traffic must be secured without introducing measurable latency penalties
  • Runtime host workload attestation and memory telemetry via DOCA App Shield for detecting in-memory threats on co-located virtual machines without hypervisor-level agents
  • Service provider NFV security insertion supporting ordered chaining of DPI, stateful firewall, and flow-based analytics functions within a single appliance at 400 Gbps line rate

Technical specifications

ManufacturerNVIDIA
Product LineDOCA 2.5 BlueField Appliance
DPU ASICNVIDIA BlueField-3 (Armv8.2-A, 16 x Cortex-A78 cores)
DPU Core ClockUp to 2.0 GHz per Arm core
Network InterfaceNVIDIA ConnectX-7 integrated, dual-port 200 GbE / single-port 400 GbE (QSFP-DD)
Maximum Network Throughput400 Gbps aggregate line rate
Stateful Firewall ThroughputUp to 400 Gbps inline with DOCA 2.5 pipeline
Encrypted Traffic InspectionHardware-accelerated TLS 1.3 and IPsec offload; sustained crypto throughput 200 Gbps+
IPsec OffloadFull hardware inline IPsec ESP encrypt/decrypt, AES-256-GCM
Concurrent Flow Table CapacityUp to 256 million hardware-tracked flows
DPU Onboard Memory32 GB LPDDR5 ECC
DPU Storage64 GB eMMC (OS and DOCA runtime); NVMe expansion supported
Host InterfacePCIe Gen 5 x16 (host server connection) or standalone appliance mode
Software FrameworkNVIDIA DOCA 2.5 (service chaining, DOCA Flow, DOCA Firewall, DOCA App Shield, DOCA Telemetry Service)
Operating SystemNVIDIA BlueField OS (Ubuntu 22.04 LTS-based, hardened) on DPU
MicrosegmentationVXLAN-aware, VRF-based policy enforcement; integration with Kubernetes Network Policy and VMware NSX
Telemetry and ObservabilityDOCA Telemetry Service exporting gRPC/Prometheus streams; hardware flow counters at nanosecond resolution
Security Certifications TargetFIPS 140-3 Level 2 cryptographic module (planned), Common Criteria EAL4+
Form Factor1U rackmount appliance (standalone) or half-height PCIe add-in card (server-installed)
Power Consumption (TDP)75 W (PCIe card mode); 150 W (standalone appliance with NIC and platform)
Operating Temperature0°C to 40°C (ASHRAE A2 class)
Launch Date2025-Q3

Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.

Technical Specifications

BrandNVIDIA
CategoryNetwork Security
SKUNVID-BF3DOCAAPPL25
Part NumberBF3-DOCA-APPL-25
ConditionNew
Product LineDOCA 2.5 BlueField Appliance
DPU ASICNVIDIA BlueField-3 (Armv8.2-A, 16 x Cortex-A78 cores)
DPU Core ClockUp to 2.0 GHz per Arm core
Network InterfaceNVIDIA ConnectX-7 integrated, dual-port 200 GbE / single-port 400 GbE (QSFP-DD)
Maximum Network Throughput400 Gbps aggregate line rate
Stateful Firewall ThroughputUp to 400 Gbps inline with DOCA 2.5 pipeline
Encrypted Traffic InspectionHardware-accelerated TLS 1.3 and IPsec offload; sustained crypto throughput 200 Gbps+
IPsec OffloadFull hardware inline IPsec ESP encrypt/decrypt, AES-256-GCM
Concurrent Flow Table CapacityUp to 256 million hardware-tracked flows
DPU Onboard Memory32 GB LPDDR5 ECC
DPU Storage64 GB eMMC (OS and DOCA runtime); NVMe expansion supported
Host InterfacePCIe Gen 5 x16 (host server connection) or standalone appliance mode
Software FrameworkNVIDIA DOCA 2.5 (service chaining, DOCA Flow, DOCA Firewall, DOCA App Shield, DOCA Telemetry Service)
Operating SystemNVIDIA BlueField OS (Ubuntu 22.04 LTS-based, hardened) on DPU
MicrosegmentationVXLAN-aware, VRF-based policy enforcement; integration with Kubernetes Network Policy and VMware NSX
Telemetry and ObservabilityDOCA Telemetry Service exporting gRPC/Prometheus streams; hardware flow counters at nanosecond resolution
Security Certifications TargetFIPS 140-3 Level 2 cryptographic module (planned), Common Criteria EAL4+
Form Factor1U rackmount appliance (standalone) or half-height PCIe add-in card (server-installed)
Power Consumption (TDP)75 W (PCIe card mode); 150 W (standalone appliance with NIC and platform)
Operating Temperature0°C to 40°C (ASHRAE A2 class)
Launch Date2025-Q3

Frequently Asked Questions about NVIDIA DOCA 2.5 BlueField Appliance

What does the NVIDIA DOCA 2.5 BlueField Appliance do?

The NVIDIA DOCA 2.5 BlueField Appliance is enterprise networking hardware for data-center, campus, and branch deployments. Common roles include core/distribution switching, server uplinks, top-of-rack fabric, and edge connectivity in mixed Cisco/Juniper/Arista environments.

What are the headline specs of the NVIDIA DOCA 2.5 BlueField Appliance?

Key specifications for the NVIDIA DOCA 2.5 BlueField Appliance: new condition; manufacturer NVIDIA; product line DOCA 2.5 BlueField Appliance; dpu asic NVIDIA BlueField-3 (Armv8.2-A, 16 x Cortex-A78 cores); dpu core clock Up to 2.0 GHz per Arm core; network interface NVIDIA ConnectX-7 integrated, dual-port 200 GbE / single-port 400 GbE (QSFP-DD); maximum network throughput 400 Gbps aggregate line rate. Manufacturer part number BF3-DOCA-APPL-25. For the full datasheet with electrical, environmental, and compliance details, contact our pre-sales engineering team.

Is the NVIDIA DOCA 2.5 BlueField Appliance compatible with my infrastructure?

The NVIDIA DOCA 2.5 BlueField Appliance interoperates with standard switching protocols (LACP, MLAG/VPC, 802.1Q, OSPF/BGP). For specific cross-vendor scenarios — Cisco-to-Arista MLAG peering, fabric integration with Cumulus/SONiC, or migration from legacy Catalyst — our network engineers map a compatibility plan as part of the RFQ.