Deployment profile
A software BNG built for how ISPs actually run
Most ISPs terminate PPPoE or DHCP subscribers from OLTs and access switches, stretch a small public IPv4 holding with CGNAT, and have to produce subscriber and NAT records on demand. Netvyn does all of it on a server you buy locally — no chassis, no line cards, no per-feature licence.
Typically deployed by
- ISPs of 2,000 to 100,000+ subscribers
- FTTH operators terminating PPPoE from GPON OLTs
- Operators outgrowing a router-based PPPoE concentrator
- Cable, wireless and regional ISPs adding CGNAT
01 What matters here
Built for how this network actually behaves
The four decisions that make the difference on this kind of network.
PPPoE at FTTH scale
Thousands of PPPoE sessions per server from GPON and XGS-PON OLTs, with per-ONT or per-OLT VLANs and the session state kept in userspace on DPDK, not on a router CPU.
CGNAT with traceability
Deterministic or dynamic port-block CGNAT so a /24 covers thousands of subscribers, and every block allocation is logged so a public IP and port resolves to one subscriber.
Compliance logging
Session and NAT records are produced as standard output and shipped to your collector. A missed record raises an alarm rather than being dropped silently.
Your RADIUS and billing stay
Works with the FreeRADIUS, billing and ISP management software already in the rack. Plans, rate limits and address pools arrive as RADIUS attributes.
02 Deployment shape
How it is put together
Sizing is a conversation about your server, your access model and the services you enable. Your licence is sized on concurrent sessions or on throughput, perpetual or subscription, and every service is included either way.
| Access model | PPPoE (PAP, CHAP, MS-CHAP) and IPoE, single-tag or QinQ per OLT |
|---|---|
| Bandwidth | Per-subscriber plan enforcement, upload and download, from RADIUS or local profiles |
| Public IPv4 | CGNAT with port-block allocation and per-subscriber logging; static and 1:1 NAT for business lines |
| Compliance | Session and translation records to file and remote collector |
| Hardware | Standard Dell / HP / Supermicro servers with Intel or Mellanox 10G / 25G NICs |
| Redundancy | Optional active/standby pair with session and NAT state replication |
03 What a BNG provider gives an ISP
What a BNG provider gives an ISP
A broadband network gateway (BNG, still called a BRAS by many vendors) is the device your subscribers actually connect to. It terminates the PPPoE or DHCP session, checks the login against RADIUS, hands out the address, enforces the plan speed, translates private addresses to public ones and produces the per-session records the network has to keep. In many ISP networks this role is spread across a router-based PPPoE concentrator, a separate NAT box and a logging appliance, each with its own limit and its own licence.
Netvyn collapses that stack into one piece of software on one server. The same binary carries PPPoE and IPoE termination, RADIUS authentication and accounting, hierarchical QoS, CGNAT, firewall and compliance logging, all configured from one CLI or the web GUI with commit and rollback. Growth is a bigger server or a second one, not a new chassis.
04 Why a software BNG instead of a hardware appliance
Why a software BNG instead of a hardware appliance
A carrier-grade hardware BNG from a global vendor is priced and sized for a telecom operator, and the per-session or per-feature licensing rarely fits an ISP with 5,000 to 50,000 subscribers. At the other end, router-based PPPoE concentrators are inexpensive but run out of CPU as sessions and CGNAT load grow, and they were never designed to produce compliance records.
A software BNG (often called a virtual BNG or vBNG) runs on an ordinary x86 server with 10G or 25G network cards. Netvyn uses DPDK to move packets in userspace, so a single dual-socket server handles the throughput of a mid-sized ISP with per-subscriber shaping and NAT applied in the same pass. The server is available from any local Dell, HP or Supermicro reseller, spares are cheap to keep, and the operating system is Ubuntu, Rocky Linux or FreeBSD.
05 Compliance records without a separate appliance
Compliance records without a separate appliance
Most regulators require ISPs to retain subscriber session details and, once CGNAT is in use, the translation records that map a public address and port back to a subscriber at a given time. Netvyn writes both as a standard part of session handling: a session record when a subscriber connects and disconnects, and a translation record for every CGNAT port block allocated and released. Records go to local files and to a remote collector, and the logging path alarms if a record cannot be delivered instead of quietly discarding it.
Because the CGNAT allocates port blocks rather than individual ports, the record volume stays manageable even at tens of thousands of subscribers, and a lookup for a public IP, port and timestamp resolves to exactly one session.
06 Migrating from an existing gateway
Migrating from an existing gateway
Netvyn is normally introduced beside the existing gateway rather than as a cutover. A VLAN range or an OLT is moved to Netvyn, subscribers on it re-authenticate against the same RADIUS with the same credentials and the same plan attributes, and the rest of the network is untouched. Once the first group has run cleanly, further ranges move at your own pace. The same approach is used when replacing a MikroTik, Cisco or Juniper PPPoE concentrator, and when consolidating a separate NAT box.
FAQ Common questions
Questions ISPs ask before choosing a BNG
Short answers; the documentation and a demo cover the rest.
Other solutions
Size a gateway for your network
Bring your subscriber counts, access model and address plan. We size against your hardware, not a product tier.