Skip to content
Broadband Network Gateway

GridM BNG.The broadband network gateway, rebuilt as software.

GridM BNG is a carrier-grade, cloud-native software BNG (vBNG). It terminates PPPoE and IPoE subscriber sessions at line rate on commodity x86 servers, speaks RADIUS with CoA to your existing stack, and ships CGNAT, dual-stack IPv6, hierarchical QoS and real-time per-subscriber observability in one horizontally scalable package.

PPPoE + IPoERADIUS AAA + CoACGNAT + dual-stack IPv6Bare metal, VM or Kubernetes

GridM BNG · Console

cluster: delhi-core · 2/2 nodes online

Live

▼ Download

62.2 Gbps

▲ upload 4.44 Gbps

Subscribers

23,312

PPPoE + IPoE · 0 faults

Live network throughput

15m1h6h24h
Download Upload Subscribers

Per BNG

N+1 · session sync

bng-n1 · 11,868 subs31.8G 2.22G
bng-n2 · 11,444 subs30.5G 2.23G
IPv6 Adoption17.7%
NAT Port Pressure62%
DDoS Protection98 mitigating

IPDR flows today

1,842,032,315

Flows / last 5 min

12,252,753

Capabilities

The full broadband edge, in software

Eight subsystems that used to be line cards, licenses and side-boxes. Now one scalable package.

Subscriber session termination

PPPoE and IPoE (DHCP) termination that scales to hundreds of thousands of sessions per node.

  • PPPoE (PAP/CHAP) and IPoE with DHCPv4 option-82 awareness
  • 802.1Q and QinQ (S-VLAN/C-VLAN) subscriber encapsulation
  • Hundreds of thousands of concurrent sessions per node
  • Per-VLAN, per-OLT and per-partner session views
  • Session sync between nodes for stateful failover
Go deeper

AAA and policy

Standards-based RADIUS that drops into the billing and CRM stack you already run.

  • RADIUS authentication, authorization and accounting (RFC 2865/2866)
  • Change of Authorization, CoA, for live plan changes and mass disconnects (RFC 5176)
  • Multiple RADIUS realms on one cluster for wholesale and partner billing
  • Interim accounting tuned for billing accuracy
  • Works with FreeRADIUS and any RFC-compliant RADIUS or ISP CRM
  • Local fallback policy when RADIUS is unreachable
Go deeper

Addressing, IPv6 and CGNAT

Stretch scarce IPv4 with integrated CGNAT while rolling out native dual-stack IPv6.

  • IPv4 address pools with DHCP and static assignment
  • Native dual-stack: IPv6CP, SLAAC and DHCPv6 prefix delegation
  • Integrated CGNAT (NAT44) with deterministic NAT and port-block allocation
  • Per-session NAT logging and IPDR export for lawful compliance
  • NAT port pressure analytics to right-size public pools
Go deeper

QoS and plan enforcement

Enforce every plan, fairly, at line rate, without external shaper boxes.

  • Per-subscriber two-rate shaping and policing
  • Hierarchical QoS: subscriber, VLAN, port and node tiers
  • Plan and fair-usage enforcement driven by RADIUS attributes
  • Live plan changes via CoA, no session drop
  • Burst profiles for speed-test friendly delivery
Go deeper

Line-rate data plane

A kernel-bypass forwarding plane that turns commodity NICs into carrier capacity.

  • DPDK-class forwarding on commodity Intel and NVIDIA/Mellanox NICs
  • Multi-gigabit to terabit: scale up with cores, scale out with nodes
  • ECMP scale-out across nodes, add capacity node by node
  • Runs on standard x86: your servers, your favorite OEM or white-box
  • No proprietary line cards, optics markup or chassis fabric
Go deeper

High availability

Carrier availability from redundant software, not redundant chassis.

  • N+1 node redundancy with session synchronization
  • Hitless failover: subscribers stay online through node loss
  • In-service software upgrades, canary one node at a time
  • BFD-backed upstream and downstream convergence
  • Cluster-wide health checks and automatic fault isolation
Go deeper

Observability

Per-subscriber truth in real time, built into the console. No external monitoring stack to run.

  • Real-time per-subscriber bandwidth, sessions and VLAN analytics
  • Flow-level traffic analytics: top talkers by ASN, country and protocol, 30-day retention
  • DDoS detection and auto-mitigation: volumetric, protocol, reflection and amplification
  • NAT port pressure with per-subscriber blocked-connection counts
  • CPE diagnostics and IPv6 adoption cohorts, exportable as call lists
  • Faults, IPv6 tracking and a tamper-proof audit log, all visualized in the console
Go deeper

Central web console

Manage the whole cluster from one beautiful web console. No CLI, no per-box logins.

  • One web console manages every node in the cluster, centrally and in real time
  • Light and dark modes, role-based access (admin, operator, partner, LEA) and a full audit log
  • Preview a configuration change, then apply it cluster-wide in a click
  • A REST API mirrors the console for your billing and CRM
  • Scoped API tokens, shown once and stored hashed, expose the realtime bandwidth API
  • Multi-tenant partner consoles scoped to their own VLANs and subscribers
Go deeper
Architecture

Separated control and data planes, on your hardware

A kernel-bypass data plane forwards at line rate while a distributed control plane handles sessions, AAA and APIs. Add nodes, not chassis.

OLT / GPONFTTH accessDSLAM / SwitchDSL + ethernetWireless / RFWISP accessSUBSCRIBERSPPPoE · IPoE · QinQbng-node-01bng-node-02bng-node-NGridM BNG clusterN+1 · session sync · ECMP scale-outcommodity x86 · bare metal / VM / K8sRADIUS · BillingAAA + CoA · your stackIP core · InternetBGP · upstreams · peering

Bare metal

Maximum packets per rack unit. Install on your x86 servers with supported NICs and go line rate.

Virtual machine

Run alongside existing workloads on KVM or VMware with SR-IOV for near bare-metal throughput.

Kubernetes

Cloud-native from the start: operator-managed lifecycle, rolling upgrades and declarative config.

On-prem POPs, edge sites or your data center. Same software, same console, every footprint.

Specifications

Specs at a glance

The reference card for architects. Full datasheets and sizing guides come with the demo.

Session and access

Access protocols
PPPoE (PAP/CHAP), IPoE (DHCPv4, option 82)
Encapsulation
802.1Q, QinQ (S-VLAN/C-VLAN)
Sessions per node
Hundreds of thousands, hardware dependent
Access interop
Any OLT, DSLAM, switch or wireless access layer

AAA and policy

AAA
RADIUS auth, authorization, accounting (RFC 2865/2866)
Dynamic policy
CoA (RFC 5176): plan change, disconnect, quota
Billing interop
FreeRADIUS and RFC-compliant RADIUS/CRM stacks

Addressing

IPv4
Pools, DHCP, static, framed routes
IPv6
Dual-stack, IPv6CP, SLAAC, DHCPv6-PD
CGNAT
NAT44, deterministic NAT, port-block allocation, NAT logging

QoS

Shaping
Per-subscriber two-rate shaping and policing
Hierarchy
Subscriber, VLAN, port and node tiers (HQoS)
Enforcement
RADIUS-driven plans, fair usage, CoA live changes

Performance and HA

Data plane
Kernel-bypass, line rate on commodity NICs
Throughput
Multi-gigabit to terabit via ECMP scale-out
Redundancy
N+1 with session sync, hitless failover
Upgrades
In-service software upgrades, canary per node

Operations

Management
One central web console (light/dark), cluster-wide, real-time
Analytics
Built in: live graphs, 30-day flow history, IPDR, faults, DDoS
Integration
REST API + scoped tokens for billing, CRM and portals
Access control
Roles: admin, operator, partner (VLAN-scoped), LEA; audit log
Deployment
Bare metal, VM, containers, Kubernetes; on-prem or edge
PPPoE (RFC 2516)IPoE / DHCPv4 (option 82)RADIUS (RFC 2865/2866)CoA (RFC 5176)IPv6CP + SLAACDHCPv6-PD (RFC 8415)CGNAT / NAT44 (RFC 6888)802.1Q / QinQREST APIBFD (RFC 5880)
IPv4 exhaustion, handled

CGNAT and native IPv6 in the same hop

Stop buying IPv4 blocks and NAT appliances. GridM BNG shares your public pool across subscribers with deterministic CGNAT, logs every mapping for lawful compliance, and rolls out dual-stack IPv6 with prefix delegation so NAT demand shrinks over time.

  • Deterministic NAT44 + port blocks
  • IPDR / NAT logging built in
  • IPv6CP, SLAAC, DHCPv6-PD
  • NAT port pressure analytics
Address efficiency Live
NAT port pressure62%

/26 public pool · 1:64 sharing · headroom OK

IPv6 adoption41%

dual-stack sessions · PD ::/56 per CPE

nat.log → IPDR export Compliant
Observability

Per-subscriber truth, ten seconds after you ask

The GridM console answers the questions your NOC actually gets: why is this customer slow, who is saturating that VLAN, is this an attack. Live per-subscriber bandwidth, flow-level traffic analytics with 30-day retention (top talkers by ASN, country and protocol), automatic DDoS mitigation with per-rule drop effectiveness and CPE diagnostics are all built in. There is no Prometheus, Grafana or external collector to deploy: the graphs and history live in the console itself, in light and dark modes, because NOCs work nights.

See it live in a demo

Click a username, get the live graph. Identifiers are fictional.

Inside the console

The controls, up close

Eight of the screens your NOC will live in. Illustrations mirror the shipping console; the identifiers are fictional, the capabilities are not.

BNG Sessions

Every live session, one query away

  • Filter tens of thousands of live sessions by username, MAC, IPv4/IPv6, VLAN or QinQ tag, access type or CGNAT IP
  • Plan, live rates, addresses, NIC vendor and uptime on every row
  • Disconnect one session or every match, via CoA, straight from the console

DDoS Protection

Detects in seconds, mitigates automatically

  • Four independent detection layers: signatures, volumetric, fanout/entropy and adaptive baseline
  • Sub-second fast-signal detection with thresholds you can retune live, no restart
  • Live offenders ranked by pps and bps, with one-click rate limit, whitelist and clear

Traffic Analytics

Billions of flows, answers in seconds

  • Top talkers by destination ASN, country, protocol or subscriber, with 30-day retention
  • Filter by CIDR, ASN, country, protocol number or exact username, down to 5-minute buckets
  • A top-N query over a full day of flows typically returns in about two seconds

NAT Port Pressure

Know who is out of ports before they call

  • Live per-subscriber port usage against the allocation, with peak and blocked-connection counts
  • Separates heavy use from infected CPEs port-scanning, with DDoS state inline
  • Right-size public pools with measured pressure, not guesswork

IPv6 Adoption

Dual-stack rollout, measured honestly

  • Every subscriber lands in a cohort: two-way IPv6 working, prefix but broken, or no prefix yet
  • The broken cohort exports as a call list your support team can actually work through
  • Traffic share and per-subscriber IPv6 volume over 24-hour windows

IPDR / Legal

Compliance workflows, not compliance projects

  • Search flow records by private IP, public NAT IP and port, destination, TCP flags or username
  • Unlimited Excel exports, and legal-authority requests tracked in their own workflow
  • A scoped LEA role gives law enforcement read-only access with a full audit trail

CPE Diagnostics + Faults

Support answers without a truck roll

  • Type a MAC and see what the CPE has been doing, even while the customer is offline
  • Unstable-connectivity faults auto-flag CPEs that reconnect repeatedly, with reconnects per hour
  • Severity, mean session length and last-seen say "replace the router" before the customer calls twice

Partners + RADIUS

Wholesale-grade tenancy built in

  • Partners and LCOs get read-only consoles scoped to their own VLANs and subscribers
  • RADIUS interceptor with multiple realms, Operator-Name injection (RFC 5580) and YAML preview before apply
  • Scoped API tokens, shown once and stored hashed, feed CRM vendors the realtime bandwidth API

And every other module in the same console:

DashboardBNG ClustersBNG DevicesVLANsBNG SessionsNAT Port PressureCPE DiagnosticsTraffic AnalyticsIPv6 AdoptionBandwidth MeterDDoS ProtectionFaultsIPDR / LegalAudit LogSubscriber MappingsRADIUSPartnersAPI Tokens
Migration

From chassis to software without a big-bang cutover

Every GridM migration runs in parallel with the incumbent. Subscribers move in slices; rollback stays one command away.

Run in parallel

Stand up GridM BNG next to the incumbent chassis. Same RADIUS, same pools, zero subscriber impact.

Interop and verify

Point a test VLAN or OLT at GridM. Validate auth, accounting, QoS and CGNAT against real traffic.

Migrate in slices

Move subscribers VLAN by VLAN or POP by POP during normal windows. CoA keeps plans live throughout.

Retire the chassis

Decommission line cards and support contracts. Keep the old box as cold standby until you are ready.

FAQ

GridM BNG, in detail

Standard x86 servers with supported Intel or NVIDIA/Mellanox NICs, from any OEM or white-box vendor. A single 1U server handles tens of gigabits and tens of thousands of subscribers; clusters scale out with ECMP to hundreds of thousands of sessions and terabit-class forwarding. We publish sizing guidance and validate hardware during onboarding.

Put GridM BNG on your test bench

Get a guided demo, a sizing recommendation for your hardware and a migration plan for your topology.

Runs on your hardware · One plan, every feature · Migrate in slices