BNGSOFT PRODUCTS
Carrier BNG, CGNAT and edge routing — as software, on hardware you already buy.
50 Mpps per box with PPPoE, CGNAT, hQoS and ACLs all enabled. No appliance, no line cards, no per-subscriber licence.
50 Mpps per box with PPPoE, CGNAT, hQoS and ACLs all enabled. No appliance, no line cards, no per-subscriber licence.
When a NIC driver misbehaves at line rate, the fix goes into the driver — not around it.
Security fixes ship as software. No line-card refresh and no waiting on a silicon vendor.
Buy the server you want. Nothing in the licence counts your subscribers or pins you to a chassis.
A proof of concept runs on your own x86 against your own traffic.
Subscriber termination, address translation, hierarchical shaping, filtering and border routing — all of it on one commodity server, with no per-subscriber licence tied to hardware.
Select a stage to see what it actually does
Every capability below runs in the same eBPF program, on the same packet, in the same pass. Nothing here is a separate appliance, a licence tier, or a feature that costs you another hop.
PPPoE and IPoE on the same node, with the access encapsulation you already run.
Port blocks, not per-flow connection tracking — which is what keeps the log volume and the state small.
Three levels of shaping, and a queue measured by how long packets sit in it rather than how deep it is.
Source validation and DDoS containment in the same pass that forwards — no scrubbing hop to trombone through.
Upgrades that keep the sessions, and enough telemetry to answer a subscriber complaint without a packet capture.
The same signed image runs at every position in the network. What a node does is decided by which stages you licence and enable — not by which box you bought.
Shaping and protection, no translation, no route lookups in the forwarding plane. The smallest footprint, for operators who already have public addressing sorted.
Model A plus carrier-grade translation, the firewall engine, port forwarding and the walled garden. Selected automatically when translation or firewalling is licensed and enabled.
Translation only. Subscriber and session management are skipped entirely — for dropping CGNAT in behind a BNG you are keeping.
Moving a node between roles is a configuration change on the same signed image, not a different product and not a different licence SKU.
50 Mpps is the measured ceiling with PPPoE, CGNAT, hierarchical QoS and ACLs all switched on at the same time — not a stateless forwarding number with the features turned off. Everything below follows from it.
at 64-byte frames, with the engine held at 50 Mpps
The packet rate is what the engine is held to. The bit rate is arithmetic on top of it: wire_bits = (frame_bytes + 20) × 8, then Gbps = pps × wire_bits ÷ 1e9. The 20 bytes are preamble, start-of-frame delimiter and inter-frame gap. Past about 980-byte frames the adapters saturate before the engine does.
| Build | Adapter | CPU | RAM | Capacity | Subscribers | Power |
|---|---|---|---|---|---|---|
| Edge 1U | Intel X710-DA2 · i40e | 8-core | 32 GB | ~20 Gbps | ~6,700 | ~250 W |
| Standard 1U | Intel E810-CQDA2 · ice | 16-core | 64 GB | ~100 Gbps | ~33,000 | ~380 W |
| High-density 2U | 2 × E810-CQDA2 · ice | 2 × 16–24-core | 128 GB | ~200 Gbps | ~64,000 | ~650 W |
| SmartNIC 2U | ConnectX-6 Dx · mlx5 | 24-core | 128 GB | ~200 Gbps | ~64,000 | ~600 W |
| Adapter | Ports | PCIe | Driver | XDP mode |
|---|---|---|---|---|
| Intel X710-DA2 | 2 × 10G | Gen3 ×8 | i40e | native |
| Intel XL710-QDA2 | 2 × 40G | Gen3 ×8 | i40e | native |
| Intel E810-CQDA2 | 2 × 100G | Gen4 ×16 | ice | native |
| NVIDIA ConnectX-6 Dx | 2 × 100/200G | Gen4 ×16 | mlx5 | native |
| VMware vmxnet3 | — | — | vmxnet3 | generic only — no native path |
Subscriber figures above assume roughly 3.2 Mbps per subscriber at busy hour, which is the median we measure across production gateways. Size your uplinks from your subscriber count; size your CPU from your own telemetry.
32 GB minimum, 64 GB at 40G, 128 GB at 100G and above — with every memory channel populated. The tables that hold sessions, port blocks and the flow cache all live in RAM.
On a well-configured node it is usually the PCIe link and the port, not the processor. A dual-40G card on a Gen3 ×8 slot shares about 56 Gbps of usable bus bandwidth between both ports.
x86-64, Intel or AMD. Kernel 5.10 is the minimum and 6.x is recommended. The image ships as one artefact — you do not install it onto a distribution you already run.
Eight things the subscriber edge has to do, and one XDP data plane that does them. Each card links to the technical brief behind it — and says plainly where it stands.
Port-block NAT44 in the forwarding path — no per-flow connection tracking, one log record per block, and idle reclaim that tightens as the pool fills.
PPPoE and IPoE termination with RADIUS AAA, CoA applied to the live forwarding plane, QinQ access and per-subscriber hierarchical shaping.
Kernel, forwarding path and BNG daemon built from source into one signed artefact that boots to a RAM root. No package manager, no shell, no drift.
Transparent caching and local peering for the traffic that is still cacheable — HTTP objects and P2P — billed on the upstream traffic it saves you.
White-label streaming platform: CMS and playout, apps for Android and Android TV, VOD and live channels, visible and forensic watermarking.
BCP 38 source validation, ACL chains and victim-and-vector DDoS containment — all in the same pass that forwards the packet, with no scrubbing hop.
Transit forwarding with eBGP and FRR as the routing authority, on the same commodity server. Design complete and reviewed — not yet running in a network.
NAT64, MAP-T and MAP-E wired end to end in the shipping image and selected by one config key. Implemented and lab-validated — not yet deployed in production.
There is no support tier between you and the engineers who built the forwarding path. When you report something in the data plane, it reaches the person who wrote that code path. More about how we work →
Contact us if you need a solution.