GridM BNG.The broadband network gateway, rebuilt as software.
GridM BNG is a carrier-grade, cloud-native software BNG (vBNG). It terminates PPPoE and IPoE subscriber sessions at line rate on commodity x86 servers, speaks RADIUS with CoA to your existing stack, and ships CGNAT, dual-stack IPv6, hierarchical QoS and real-time per-subscriber observability in one horizontally scalable package.
GridM BNG · Console
cluster: delhi-core · 2/2 nodes online
▼ Download
62.2 Gbps
▲ upload 4.44 Gbps
Subscribers
23,312
PPPoE + IPoE · 0 faults
Live network throughput
Per BNG
N+1 · session sync
IPDR flows today
1,842,032,315
Flows / last 5 min
12,252,753
The full broadband edge, in software
Eight subsystems that used to be line cards, licenses and side-boxes. Now one scalable package.
Subscriber session termination
PPPoE and IPoE (DHCP) termination that scales to hundreds of thousands of sessions per node.
- PPPoE (PAP/CHAP) and IPoE with DHCPv4 option-82 awareness
- 802.1Q and QinQ (S-VLAN/C-VLAN) subscriber encapsulation
- Hundreds of thousands of concurrent sessions per node
- Per-VLAN, per-OLT and per-partner session views
- Session sync between nodes for stateful failover
AAA and policy
Standards-based RADIUS that drops into the billing and CRM stack you already run.
- RADIUS authentication, authorization and accounting (RFC 2865/2866)
- Change of Authorization, CoA, for live plan changes and mass disconnects (RFC 5176)
- Multiple RADIUS realms on one cluster for wholesale and partner billing
- Interim accounting tuned for billing accuracy
- Works with FreeRADIUS and any RFC-compliant RADIUS or ISP CRM
- Local fallback policy when RADIUS is unreachable
Addressing, IPv6 and CGNAT
Stretch scarce IPv4 with integrated CGNAT while rolling out native dual-stack IPv6.
- IPv4 address pools with DHCP and static assignment
- Native dual-stack: IPv6CP, SLAAC and DHCPv6 prefix delegation
- Integrated CGNAT (NAT44) with deterministic NAT and port-block allocation
- Per-session NAT logging and IPDR export for lawful compliance
- NAT port pressure analytics to right-size public pools
QoS and plan enforcement
Enforce every plan, fairly, at line rate, without external shaper boxes.
- Per-subscriber two-rate shaping and policing
- Hierarchical QoS: subscriber, VLAN, port and node tiers
- Plan and fair-usage enforcement driven by RADIUS attributes
- Live plan changes via CoA, no session drop
- Burst profiles for speed-test friendly delivery
Line-rate data plane
A kernel-bypass forwarding plane that turns commodity NICs into carrier capacity.
- DPDK-class forwarding on commodity Intel and NVIDIA/Mellanox NICs
- Multi-gigabit to terabit: scale up with cores, scale out with nodes
- ECMP scale-out across nodes, add capacity node by node
- Runs on standard x86: your servers, your favorite OEM or white-box
- No proprietary line cards, optics markup or chassis fabric
High availability
Carrier availability from redundant software, not redundant chassis.
- N+1 node redundancy with session synchronization
- Hitless failover: subscribers stay online through node loss
- In-service software upgrades, canary one node at a time
- BFD-backed upstream and downstream convergence
- Cluster-wide health checks and automatic fault isolation
Observability
Per-subscriber truth in real time, built into the console. No external monitoring stack to run.
- Real-time per-subscriber bandwidth, sessions and VLAN analytics
- Flow-level traffic analytics: top talkers by ASN, country and protocol, 30-day retention
- DDoS detection and auto-mitigation: volumetric, protocol, reflection and amplification
- NAT port pressure with per-subscriber blocked-connection counts
- CPE diagnostics and IPv6 adoption cohorts, exportable as call lists
- Faults, IPv6 tracking and a tamper-proof audit log, all visualized in the console
Central web console
Manage the whole cluster from one beautiful web console. No CLI, no per-box logins.
- One web console manages every node in the cluster, centrally and in real time
- Light and dark modes, role-based access (admin, operator, partner, LEA) and a full audit log
- Preview a configuration change, then apply it cluster-wide in a click
- A REST API mirrors the console for your billing and CRM
- Scoped API tokens, shown once and stored hashed, expose the realtime bandwidth API
- Multi-tenant partner consoles scoped to their own VLANs and subscribers
Separated control and data planes, on your hardware
A kernel-bypass data plane forwards at line rate while a distributed control plane handles sessions, AAA and APIs. Add nodes, not chassis.
Bare metal
Maximum packets per rack unit. Install on your x86 servers with supported NICs and go line rate.
Virtual machine
Run alongside existing workloads on KVM or VMware with SR-IOV for near bare-metal throughput.
Kubernetes
Cloud-native from the start: operator-managed lifecycle, rolling upgrades and declarative config.
On-prem POPs, edge sites or your data center. Same software, same console, every footprint.
Specs at a glance
The reference card for architects. Full datasheets and sizing guides come with the demo.
Session and access
- Access protocols
- PPPoE (PAP/CHAP), IPoE (DHCPv4, option 82)
- Encapsulation
- 802.1Q, QinQ (S-VLAN/C-VLAN)
- Sessions per node
- Hundreds of thousands, hardware dependent
- Access interop
- Any OLT, DSLAM, switch or wireless access layer
AAA and policy
- AAA
- RADIUS auth, authorization, accounting (RFC 2865/2866)
- Dynamic policy
- CoA (RFC 5176): plan change, disconnect, quota
- Billing interop
- FreeRADIUS and RFC-compliant RADIUS/CRM stacks
Addressing
- IPv4
- Pools, DHCP, static, framed routes
- IPv6
- Dual-stack, IPv6CP, SLAAC, DHCPv6-PD
- CGNAT
- NAT44, deterministic NAT, port-block allocation, NAT logging
QoS
- Shaping
- Per-subscriber two-rate shaping and policing
- Hierarchy
- Subscriber, VLAN, port and node tiers (HQoS)
- Enforcement
- RADIUS-driven plans, fair usage, CoA live changes
Performance and HA
- Data plane
- Kernel-bypass, line rate on commodity NICs
- Throughput
- Multi-gigabit to terabit via ECMP scale-out
- Redundancy
- N+1 with session sync, hitless failover
- Upgrades
- In-service software upgrades, canary per node
Operations
- Management
- One central web console (light/dark), cluster-wide, real-time
- Analytics
- Built in: live graphs, 30-day flow history, IPDR, faults, DDoS
- Integration
- REST API + scoped tokens for billing, CRM and portals
- Access control
- Roles: admin, operator, partner (VLAN-scoped), LEA; audit log
- Deployment
- Bare metal, VM, containers, Kubernetes; on-prem or edge
CGNAT and native IPv6 in the same hop
Stop buying IPv4 blocks and NAT appliances. GridM BNG shares your public pool across subscribers with deterministic CGNAT, logs every mapping for lawful compliance, and rolls out dual-stack IPv6 with prefix delegation so NAT demand shrinks over time.
- Deterministic NAT44 + port blocks
- IPDR / NAT logging built in
- IPv6CP, SLAAC, DHCPv6-PD
- NAT port pressure analytics
/26 public pool · 1:64 sharing · headroom OK
dual-stack sessions · PD ::/56 per CPE
Per-subscriber truth, ten seconds after you ask
The GridM console answers the questions your NOC actually gets: why is this customer slow, who is saturating that VLAN, is this an attack. Live per-subscriber bandwidth, flow-level traffic analytics with 30-day retention (top talkers by ASN, country and protocol), automatic DDoS mitigation with per-rule drop effectiveness and CPE diagnostics are all built in. There is no Prometheus, Grafana or external collector to deploy: the graphs and history live in the console itself, in light and dark modes, because NOCs work nights.
See it live in a demoClick a username, get the live graph. Identifiers are fictional.
The controls, up close
Eight of the screens your NOC will live in. Illustrations mirror the shipping console; the identifiers are fictional, the capabilities are not.
BNG Sessions
Every live session, one query away
- Filter tens of thousands of live sessions by username, MAC, IPv4/IPv6, VLAN or QinQ tag, access type or CGNAT IP
- Plan, live rates, addresses, NIC vendor and uptime on every row
- Disconnect one session or every match, via CoA, straight from the console
DDoS Protection
Detects in seconds, mitigates automatically
- Four independent detection layers: signatures, volumetric, fanout/entropy and adaptive baseline
- Sub-second fast-signal detection with thresholds you can retune live, no restart
- Live offenders ranked by pps and bps, with one-click rate limit, whitelist and clear
Traffic Analytics
Billions of flows, answers in seconds
- Top talkers by destination ASN, country, protocol or subscriber, with 30-day retention
- Filter by CIDR, ASN, country, protocol number or exact username, down to 5-minute buckets
- A top-N query over a full day of flows typically returns in about two seconds
NAT Port Pressure
Know who is out of ports before they call
- Live per-subscriber port usage against the allocation, with peak and blocked-connection counts
- Separates heavy use from infected CPEs port-scanning, with DDoS state inline
- Right-size public pools with measured pressure, not guesswork
IPv6 Adoption
Dual-stack rollout, measured honestly
- Every subscriber lands in a cohort: two-way IPv6 working, prefix but broken, or no prefix yet
- The broken cohort exports as a call list your support team can actually work through
- Traffic share and per-subscriber IPv6 volume over 24-hour windows
IPDR / Legal
Compliance workflows, not compliance projects
- Search flow records by private IP, public NAT IP and port, destination, TCP flags or username
- Unlimited Excel exports, and legal-authority requests tracked in their own workflow
- A scoped LEA role gives law enforcement read-only access with a full audit trail
CPE Diagnostics + Faults
Support answers without a truck roll
- Type a MAC and see what the CPE has been doing, even while the customer is offline
- Unstable-connectivity faults auto-flag CPEs that reconnect repeatedly, with reconnects per hour
- Severity, mean session length and last-seen say "replace the router" before the customer calls twice
Partners + RADIUS
Wholesale-grade tenancy built in
- Partners and LCOs get read-only consoles scoped to their own VLANs and subscribers
- RADIUS interceptor with multiple realms, Operator-Name injection (RFC 5580) and YAML preview before apply
- Scoped API tokens, shown once and stored hashed, feed CRM vendors the realtime bandwidth API
And every other module in the same console:
From chassis to software without a big-bang cutover
Every GridM migration runs in parallel with the incumbent. Subscribers move in slices; rollback stays one command away.
Run in parallel
Stand up GridM BNG next to the incumbent chassis. Same RADIUS, same pools, zero subscriber impact.
Interop and verify
Point a test VLAN or OLT at GridM. Validate auth, accounting, QoS and CGNAT against real traffic.
Migrate in slices
Move subscribers VLAN by VLAN or POP by POP during normal windows. CoA keeps plans live throughout.
Retire the chassis
Decommission line cards and support contracts. Keep the old box as cold standby until you are ready.
GridM BNG, in detail
Standard x86 servers with supported Intel or NVIDIA/Mellanox NICs, from any OEM or white-box vendor. A single 1U server handles tens of gigabits and tens of thousands of subscribers; clusters scale out with ECMP to hundreds of thousands of sessions and terabit-class forwarding. We publish sizing guidance and validate hardware during onboarding.
Put GridM BNG on your test bench
Get a guided demo, a sizing recommendation for your hardware and a migration plan for your topology.
Runs on your hardware · One plan, every feature · Migrate in slices