PPPoE and IPoE termination, carrier-grade NAT, hierarchical QoS and ACLs — one XDP data plane, 50 Mpps per box with every feature enabled. No appliance. No per-subscriber licence tied to hardware.
50 Mpps
per box, with every feature enabled
~500 ns
per packet through the XDP data plane
x86
commodity servers — no appliance, no lock-in
Days
to ship security fixes, not release trains
Why operators switch
Port-block allocation reads real pressure per subscriber and reclaims idle ports — never a live one.
CGNAT brochure →
Kernel-depth engineering. When a card driver misbehaves at line rate, the fix goes into the driver.
Driver reliability →
Kernel 6.18.2 to 6.18.3 in five days. Security fixes ship as software — no line-card refresh.
Platform security →
A proof of concept runs on your own x86 against your traffic. Send subscriber count and busy-hour throughput and we size it with you.
Request a PoC →
Start here
Pick the problem you are solving. Each path goes straight to the pages, numbers and tools that answer it.
PPPoE and IPoE termination, RADIUS AAA with CoA and hierarchical QoS on commodity x86.
See the vBNG / BRAS →
Carrier-grade NAT with port-block allocation that never drops a live session, plus NAT64 and MAP-T / MAP-E.
See XDP CGNAT →
Work out Gbps, Mpps and box count from your own subscriber numbers and traffic mix.
Open the sizing tools →
How a software BNG on x86 stacks up against appliance-based BNG and BRAS.
Compare options →
Products
Same XDP data plane, same commodity server — termination, translation, traffic management and border routing become configuration, not four more boxes in the rack.
Port-block NAT44 with per-subscriber pressure sensing, plus NAT64 and MAP-T / MAP-E for IPv6-only access.
How XDP CGNAT works →
PPPoE and IPoE termination, RADIUS AAA with CoA, hierarchical QoS and QinQ — 50 Mpps per box.
Inside the vBNG / BRAS →
Built from source into one signed artefact that boots to a RAM root. Every node verifiably runs the same code.
OrionOS brochure →
Cache and accelerate at the edge — less upstream transit, faster page loads for subscribers.
How it works →
TV apps, edge cache, timeshift, VOD and EPG for operator-run television.
The IPTV / OTT platform →
Anti-spoof, DDoS mitigation and abuse containment at the subscriber edge, before traffic reaches your core.
Edge security →
Border routing on the same box that terminates subscribers — no separate edge router to licence.
Border router brochure →
Billing and customer management for operators, alongside the network.
See Billing & CRM →
Built for your network
What an ISP needs before buying a BNG: sizing, IPv4 sharing, day-to-day operations and how it compares with a chassis.
BNG for ISPs →
Cut the round-trip climb under load and run CGNAT at constellation scale on commodity x86.
Satellite and FWA →
Hold queuing latency near 0.6 ms under load with L4S, fair queuing and interactive protection.
Low latency →
Anti-spoof filtering, per-victim DDoS containment and abuse blocking in the same data plane that forwards.
Edge security →
In-service upgrades that keep every session, and one control plane for the whole fleet.
Operations →
Work with BNGSOFT to deliver the subscriber edge to your own customers.
Partnership →
On one box
One data plane does termination, translation, shaping and filtering. No separate CGNAT appliance, no separate edge router, and no per-feature licence to negotiate.
✓ PPPoE and IPoE termination
✓ QinQ and VLAN stacking
✓ Hierarchical QoS per subscriber
✓ ACLs and anti-spoof filtering
✓ Carrier-grade NAT, port-block allocation
✓ NAT64 and MAP-T / MAP-E
✓ IPv6 dual-stack
✓ L4S and low-latency queueing
✓ IPFIX / NetFlow with flow aggregation
✓ Port-block logging for subscriber attribution
✓ Syslog export to your own collector
✓ DDoS protection and abuse containment
✓ BGP border routing on the same box
✓ 802.3ad LACP bonding
✓ In-service upgrades, no session loss
✓ IP pool changes without a restart
Packet size, not gigabits, decides the answer. Enter your subscribers and busy-hour traffic and get Gbps, Mpps and box count in seconds.
How buying works
No procurement maze. You talk to the engineers who wrote the data plane, and you see it working on your own hardware before you commit.
01
Send your subscriber count and busy-hour throughput. That is enough to start.
02
We work out Gbps, Mpps and box count against your traffic — packet size, not gigabits, decides it.
03
A proof of concept runs on your own x86 server against your real traffic.
04
In-service upgrades without session loss. Security fixes ship as software in days.
Who you will actually talk to
BNGSOFT is a team of ten. There is no support tier between you and the people who wrote the forwarding path — when a network card driver misbehaves at line rate, the person who answers is the person who fixes it.
That is why security patches ship in days instead of release trains, and why a proof of concept is a conversation with engineers rather than a procurement process.
Learn the subscriber edge
Guides and tools for the people who design and run broadband networks.
The virtual Broadband Network Gateway explained — what it does and where it sits.
Read the guide →
What the difference actually is, and why it matters when you replace one.
Read the guide →
How packet processing in the Linux kernel reaches 50 Mpps per box.
Read the guide →
Choosing how to deliver television to your subscribers.
Read the guide →
BNG sizing, IPv4 savings, frame size and packet path calculators.
Open the tools →
CGNAT, border router, OrionOS and platform security, one page each.
Browse brochures →
Buying questions
No. BNGSOFT runs on commodity x86 servers — there is no appliance to buy. A proof of concept runs on your own hardware.
One box handles 50 Mpps with every feature enabled. The real answer depends on your packet sizes, so use the BNG sizing calculator or send us your numbers and we size it with you.
No. Termination, carrier-grade NAT, hierarchical QoS, ACLs and BGP border routing run in one data plane on the same box — no separate CGNAT appliance and no per-feature licence to negotiate.
Yes. We run a proof of concept on your own x86 server against your own traffic. Request a PoC.
The same engineers who wrote the forwarding path. BNGSOFT is a team of ten, with no support tier between you and the people who fix the code.
As software. Upgrades run in service without dropping sessions, and security fixes ship in days rather than release trains.
Send your subscriber count and busy-hour throughput. An engineer — not a salesperson — will size it with you and set up a proof of concept.