Product · netavo-cgn · standalone CGNAT in development

CGNAT that works behind anyone's BNG.

netavo-cgn learns subscribers straight from traffic — no RADIUS integration, no vendor API, no forklift. Drop it in a VRF, point IPv4 at it, and it starts translating. Licensed by the only number that maps to your revenue: subscribers.

Join the design-partner listRead the spec
01
Auto-learn
Zero integration · any vendor's BNG

fig 1.0 — replaces firewall-in-a-VRF CGN without touching the BNG

Subscribers learned directly from traffic — deployed behind another vendor's BNG.

netavo-cgn replaces the common firewall-in-a-VRF CGN deployment with a purpose-built translation appliance. It learns subscriber bindings directly from traffic — inside prefixes in, public pools out, with inactivity ageing and optional identity enrichment via API or RADIUS.

Because it needs nothing from the BNG, it works behind whatever you run today — and keeps working when you change it.

02
The metering nobody else uses
Inside subscribers · not flows, not Gbps

Standalone CGNAT is conventionally metered by throughput tiers, core counts, session tables or flow blocks — measures driven by user behaviour rather than your subscriber base. A single heavy user should not consume licence capacity.

netavo-cgn is licensed by distinct inside subscribers under translation. One customer is one unit, whether they hold six flows or sixty thousand — the one measure in CGN that tracks your subscriber base rather than traffic patterns.

VendorMetering
netavo-cgninside subscribers
A10 Thunder CGNbandwidth tiers + core-tied bands
netElastic CGNbandwidth tiers + CGNAT licence
RtBrick CGNATper-1k subs (add-on) or per-500k flows

Vendor licensing pages/datasheets, 2026-07-16. Corrections welcome.

Fig 2.0 — what you're licensed for

inside subscribersthe only metered field
flowsunmetered
gbpsunmetered
portsunmetered
ON NETAVO BNG — CGNAT is included in every Netavo BNG licence; a translated subscriber is not an additional billable unit. This page describes the standalone appliance for deployment behind other vendors' BNGs.
03
Compliance-grade logging
Port blocks · sequence-numbered · your SIEM
CapabilityDetail
Port-block allocationdynamic uniform chunks · per-subscriber port cap · sticky public-IP affinity · freed-block quarantine
Session loggingport-block events (not per-flow noise) · RFC 5424 JSON syslog or Azure Service Bus · sequence numbers and restart markers make any gap in the record detectable
Gamer-friendly NATendpoint-independent filtering (EIF) — "open NAT" behaviour by default
Bypass prefixesper-group destination prefixes that skip NAT entirely

Every port-block allocation is a sequence-numbered log event — the answer to "who held this address and port?" is one query.

In development — join the design-partner programme.

We are recruiting design partners currently running CGN on firewall platforms or under throughput-based licensing. Partners receive early access, direct engineering contact and launch pricing.

Join the design-partner list