Product · netavo-cgn · standalone CGNAT design-partner preview
netavo-cgn learns subscribers straight from traffic — no RADIUS integration, no vendor API, no forklift. Drop it in a VRF, point IPv4 at it, and it starts translating. Licensed by the only number that maps to your revenue: subscribers.
Every translation is a subscriber → public-IP + port-block record — the answer to “who held this address and port?” in one query.
fig 1.0 — replaces firewall-in-a-VRF CGN without touching the BNG
Subscribers learned directly from traffic — deployed behind another vendor's BNG.
netavo-cgn replaces the common firewall-in-a-VRF CGN deployment with a purpose-built translation appliance. It learns subscriber bindings directly from traffic — inside prefixes in, public pools out, with inactivity ageing and optional identity enrichment via API.
Because it needs nothing from the BNG, it works behind whatever you run today — and keeps working when you change it.
Standalone CGNAT is conventionally metered by throughput tiers, core counts, session tables or flow blocks — measures driven by user behaviour rather than your subscriber base. A single heavy user should not consume licence capacity.
netavo-cgn is licensed by distinct inside subscribers under translation. One customer is one unit, whether they hold six flows or sixty thousand — the one measure in CGN that tracks your subscriber base rather than traffic patterns.
| Vendor | Metering |
|---|---|
| netavo-cgn | inside subscribers |
| A10 Thunder CGN | bandwidth tiers + core-tied bands |
| netElastic CGN | bandwidth tiers + CGNAT licence |
| RtBrick CGNAT | per-1k subs (add-on) or per-500k flows |
Vendor licensing pages/datasheets, 2026-07-16. Corrections welcome.
Fig 2.0 — what you're licensed for
| Capability | Detail |
|---|---|
| Port-block allocation | dynamic uniform chunks · per-subscriber port cap · sticky public-IP affinity · freed-block quarantine |
| Session logging | port-block events (not per-flow noise) · RFC 5424 JSON syslog or Azure Service Bus · sequence numbers and restart markers make any gap in the record detectable |
| Gamer-friendly NAT | endpoint-independent filtering (EIF) — "open NAT" behaviour by default |
| Bypass prefixes | per-group destination prefixes that skip NAT entirely |
Every port-block allocation is a sequence-numbered log event — the answer to "who held this address and port?" is one query.
We are recruiting design partners currently running CGN on firewall platforms or under throughput-based licensing. Partners receive early access, direct engineering contact and launch pricing.
Join the design-partner list