Product · Netavo BNG
A subscriber edge you can read like a spec sheet.
Every claim below carries its status. Green means in the shipping release and covered by tests. Amber means in development. Outlined means designed, not built. We'd rather you knew.
| Capability | Detail | Status |
|---|---|---|
| PPPoE server | PAP / CHAP / MS-CHAPv2 · RFC 2516 | shipping |
| L2TP LAC + LNS | RFC 2661 · terminate wholesale hand-offs at scale; LNS appliance mode | shipping |
| IPoE / DHCPv4 | Option 82 · live-ingest appliance mode | shipping |
| IPv6 dual-stack | IPv6CP · RA · DHCPv6 — one session per circuit, both address families | shipping |
| Shared-VLAN PPPoE (N:1) | PPPoE Intermediate Agent circuit-id / remote-id | in development |
One subscriber, one session: IPv4 and IPv6 together, with QoS and VRF placement per service plan.
Many software BNGs assume routing happens somewhere else. Netavo BNG carries a complete routing control plane: BGP with VPNv4 and VPNv6 address families, IS-IS, MPLS L3VPN, per-service VRFs and ECMP. Subscribers can be placed directly into L3VPNs, and the BNG participates in your MPLS core as a full provider-edge device.
Wholesale voice, walled garden, management — each in its own VRF with its own routing. Every entry in the table below is present in the evaluation build and can be verified directly.
| BGP / MP-BGP | VPNv4 · VPNv6 · route reflection | shipping |
| IS-IS | v4/v6 | shipping |
| MPLS L3VPN | LDP · PE/CE · multi-VRF | shipping |
| ECMP | flow-consistent hashing | shipping |
A provider-edge routing table on the subscriber gateway — VPNv4/VPNv6 peers and per-VRF tables.
| Per-subscriber QoS | rate limiting per service plan · TCP MSS clamp, all paths | shipping |
| CGNAT (NAT44) | included in every licence · port-block logging (RFC 5424 JSON / Service Bus) · EIF for gamer-friendly NAT · sticky public-IP affinity | in development |
| Lawful-intercept readiness | LI-ready primitives + mediation-vendor integration — we do not claim an in-product ETSI stack | designed |
| IPFIX export | sampled flow export from the punt path | designed |
| Walled garden | pre-auth redirect | designed |
fig 4.0 — the forwarding guarantee is structural, not aspirational
Session state lives in shared memory. The DPDK data plane reads it directly and keeps forwarding whether the control plane is up, restarting, or mid-upgrade — the same property that makes our licensing enforcement incapable of touching traffic.
Deploys as a self-contained software appliance on standard x86 servers. Hierarchical CLI with commit and rollback, web UI with two-factor authentication, structured JSON syslog, database or RADIUS authentication, and accounting to RADIUS or Azure Service Bus.
Candidate configuration with commit and rollback. Changes apply to the data plane in place.