Partner solution · netElastic vBNG + OcNOS

Open vBNG: netElastic subscriber management on an OcNOS network

A virtual BNG terminates broadband subscribers in software on standard servers. IP Infusion and netElastic deliver it as one open architecture: OcNOS runs the aggregation and edge routing on open white-box hardware, and the netElastic vBNG handles subscriber management and carrier-grade NAT. Validated by IP ArchiTechs, in production at Amplex.

up to 1 TbpsnetElastic vBNG per server
2,000 to 128,000subscribers per server
50,000+CGNAT subscribers
sub-50msOcNOS TI-LFA reroute
Was Sie erhalten

Open architecture, delivered as a complete solution

Delivered complete

Partners deliver OcNOS routers and switches, the netElastic vBNG, and services as one integrated solution.

No lock-in

Open networking underneath, so you are not tied to one proprietary stack.

Scale independently

Add servers for subscribers, add routers for capacity. Neither forces the other.

Deploy your way

Centralized or distributed on the same OcNOS transport, with no redesign to switch.

Available as a complete solution from
RocNet Supply EPS Global World Wide Technology SOSnet
Two specialists, one edge

One subscriber edge, built from two open layers

The open subscriber edge splits cleanly in two. netElastic owns the subscriber: session termination, authentication, policy, and carrier-grade NAT. IP Infusion owns the network under it: aggregation and edge routing on open hardware.

+
Who owns what across the open subscriber edge.
Schicht Ownerthe specialist Was es bewirkt
Subscriber terminationnetElastic vBNGTerminates PPPoE, IPoE, and L2TP sessions, authenticates through RADIUS, assigns addresses, and applies per-subscriber policy and hierarchical QoS.
IPv4 conservationnetElastic CGNATCarrier-grade NAT44 shares public IPv4 across subscribers, up to 100 per address, with adjustable logging. Integrated with the vBNG or standalone.
Aggregation and edge routingOcNOSBuilds the ISIS-SR core, SR-MPLS with TI-LFA fast reroute, and EVPN-MPLS Layer 2 services that carry subscriber traffic to the vBNG.
Offene HardwareOcNOSRuns the aggregation and edge routers on validated white boxes from Edgecore, UfiSpace, and others. The vBNG runs on standard x86 servers.
So funktioniert es

From the access line to the internet, on one open network

Subscriber traffic enters at the access edge, is aggregated by OcNOS on open routers, and is carried over an ISIS-SR and EVPN-MPLS network to the netElastic vBNG, which terminates the session and applies CGNAT before the traffic reaches peering and the internet.

Open subscriber edge data path: broadband access (fiber, copper, and fixed wireless) is aggregated by an OcNOS router on open white-box hardware, carried over an ISIS-SR and EVPN-MPLS core across a VPLS attachment circuit to the netElastic virtual BNG and carrier-grade NAT, then out to peering and the internet.
The open subscriber edge, left to right: OcNOS aggregates and transports broadband subscribers over ISIS-SR and EVPN-MPLS to the netElastic vBNG and CGNAT, which terminate sessions before the internet.
Access

Broadband access

Fiber (PON and OLT), copper (DSL), and fixed wireless subscriber lines enter the network at the access edge.

OcNOS

Aggregation router

OcNOS on an open white box aggregates subscriber VLANs and shapes traffic with hierarchical QoS before the core.

OcNOS

IP and MPLS core

An ISIS-SR core with SR-MPLS and TI-LFA carries subscriber Layer 2 services over EVPN-MPLS to the vBNG.

netElastic

vBNG and CGNAT

The netElastic vBNG terminates the session, authenticates the subscriber, assigns an address, and applies CGNAT.

Two deployment models

Centralized or distributed, the same open transport

The vBNG can sit centralized or distributed. netElastic supports both, and the same OcNOS transport carries either one. The choice is about latency, fault domains, operating cost, and geography.

Design A · centralized

vBNG and CGNAT groomed at the core

Access networks carry subscriber traffic back to the core, where one pool of netElastic vBNG and CGNAT grooms it before the internet. Hardware, space, power, and cooling are minimized because the subscriber functions live in one place.

Best when the subscriber base is evenly spread. Fewer sites and CGNAT pools to operate, with more backhaul and a larger blast radius.
Centralized vBNG architecture: several access sites aggregate through OcNOS routers into a shared core, where one central pool of netElastic vBNG and carrier-grade NAT grooms all subscriber traffic before peering and the internet.
Centralized design: one pool of netElastic vBNG and CGNAT at the core grooms all subscriber traffic, which minimizes hardware, space, power, and cooling.
Design B · distributed

A local vBNG close to each metro

A netElastic vBNG sits near each metro or region and terminates subscribers locally, then hands groomed traffic up to the OcNOS core. Latency drops, local services stay local, and a fault in one region does not spread to the others.

Best when the network spans multiple geographies. Smaller fault domains and lower latency, with more sites and CGNAT pools to run.
Distributed vBNG architecture: each metro has a local netElastic vBNG that terminates subscribers close to the access edge and hands groomed traffic up to a shared OcNOS core, isolating fault domains between regions.
Distributed design: a local netElastic vBNG near each metro lowers latency and isolates fault domains, over one shared OcNOS core.
The subscriber layer

netElastic vBNG and carrier-grade NAT

netElastic builds virtual networking software for broadband providers. Its vBNG and CGNAT run on standard x86 servers, so subscriber capacity grows by adding servers instead of forklifting an edge chassis. Figures below are from netElastic.

netElastic

Every access method

Terminates PPPoE, IPoE, and L2TP with dual-stack IPv4 and IPv6, DHCP, and RADIUS authentication, accounting, and change of authorization.

netElastic

Scale on x86

Up to 1 Terabit per second on a 2RU server, 2,000 to 128,000 subscribers per server, with a separate control and data plane that scales with server cores.

netElastic

Carrier-grade NAT

NAT44 from 10G to 1 Tbps, over 50,000 subscribers, up to 100 per public address, with adjustable logging for compliance.

netElastic

High availability

A second vBNG in active-active or active-standby mode, or a geo-redundant pair, gives N+1 redundancy for maintenance, upgrades, and failover.

The network layer

Go deeper on the OcNOS transport

The division of labor above sets out what OcNOS carries under the vBNG: the ISIS-SR core, EVPN Layer 2 services, and open hardware. For the full aggregation and edge-routing detail, follow these.

Reference configuration

The handoff, in real config

These excerpts come from the IP ArchiTechs validated reference design that pairs OcNOS with the netElastic vBNG over EVPN-MPLS. OcNOS builds the EVPN Layer 2 service with active-active multihoming; netElastic terminates the subscribers on the other end of it.

OcNOS · access PE · EVPN-MPLS Layer 2 service (access-facing)
! Enable EVPN-MPLS forwarding (requires reboot)
evpn mpls enable
evpn mpls multihoming enable
! MAC-VRF for the subscriber service
mac vrf ORANGE
 rd 100.127.0.7:1
 route-target both evpn-auto-rt
evpn mpls vtep-ip-global 100.127.0.7
evpn mpls id 1
 host-reachability-protocol evpn-bgp ORANGE
! Access-facing attachment circuit into the EVPN service
interface xe44.10 switchport
 encapsulation dot1q 10-50
 access-if-evpn
  map vpn-id 1

Source: IP ArchiTechs validated design, EVPN multihoming over MPLS, OcNOS to netElastic vBNG. Verify the current syntax in the OcNOS configuration guides at documentation.ipinfusion.com before deployment.

OcNOS · aggregation PE · EVPN multihoming with ESI-LAG
! Bundle the dual-homed link into a port-channel
interface xe10
 channel-group 1 mode active
! Shared ESI system-MAC for active-active forwarding
interface po1
 evpn multi-homed system-mac 0200.0000.0001 load-balancing port-active
! Double-tagged subscriber service on the bundle
interface po1.532 switchport
 encapsulation dot1q 532 inner-dot1q 10-50
 rewrite pop
 access-if-evpn
  map vpn-id 1

Two aggregation PEs share one ESI system-MAC, so both forward for the dual-homed access at once. A PE failure reroutes with only a few packets lost. Source: IP ArchiTechs validated design.

netElastic vBNG · IPoE subscriber termination with RADIUS
# RADIUS authentication group
radius authentication group RADIUS_AUTH
 nas-ip-address 100.127.0.6
 server 1 ipv4-address 192.168.0.2 port 1812 key netelastic
# BRAS subscriber management and IPoE template
bras
 domain IPA_DOMAIN
  bind authentication-template RADIUS_AUTH
  bind accounting-template RADIUS_ACCT
  bind-pool 1 TEST
 ipoe template IPOE_TEST
  authentication-type ipv4 dhcpv4 option
 vci-configuration
  interface eth-trunk1.532
   ipoe template IPOE_TEST
   max-ipox-session 32000

The vBNG receives the same double-tagged service (outer tag 532) that OcNOS delivers over EVPN-MPLS, terminates each subscriber, authenticates through RADIUS, and assigns an address. Source: IP ArchiTechs validated design; see netElastic vBNG.

In der Produktion bewährt

Running in real broadband networks

The open subscriber edge is deployed today. Amplex Internet runs OcNOS aggregation with the netElastic vBNG, and the pairing is captured as a reference design by IP ArchiTechs.

Joint deployment

Amplex Internet, Ohio

Amplex upgraded its network with OcNOS aggregation routers on Edgecore and UfiSpace hardware. IP Infusion's OcNOS "bridges Amplex's customer edge and netElastic virtual Broadband Network Gateways," adding SR-MPLS with sub-50ms TI-LFA while interoperating with the installed base of Juniper and Ciena equipment.

Validated design

IP ArchiTechs reference architecture

The independent network-engineering firm IP ArchiTechs published the validated design pairing OcNOS with the netElastic vBNG over EVPN-MPLS, with active-active multihoming for high availability.

netElastic vBNG in the field

Next Gen Fibre, Ireland

Next Gen Fibre scaled its Irish broadband network on the netElastic vBNG and CGNAT. A netElastic and ITcare deployment, with Splynx for subscriber management.

FAQ

Open vBNG, answered

What is a virtual BNG (vBNG)?
A virtual BNG terminates broadband subscriber sessions in software on standard x86 servers instead of a proprietary edge chassis. It handles the subscriber side of the network: PPPoE and IPoE session termination, address assignment, RADIUS authentication and accounting, per-subscriber policy and hierarchical QoS, and optional carrier-grade NAT. Because it is software on commodity hardware, capacity scales by adding servers rather than replacing line cards.
Does IP Infusion make a BNG?
No. IP Infusion provides OcNOS, the routing and switching software that runs the aggregation and edge network on open white-box hardware. Subscriber termination is handled by a partner virtual BNG. netElastic is the vBNG partner: OcNOS carries subscriber traffic over an open IP and MPLS network to the netElastic vBNG, which terminates the sessions and applies carrier-grade NAT. Together they form one open subscriber edge from two specialists: an open, multi-vendor BNG.
How is a vBNG different from a traditional hardware BNG?
A traditional BNG is a proprietary edge chassis where subscriber capacity is added by buying line cards from one vendor. A vBNG runs the same subscriber functions in software on standard x86 servers, so capacity grows by adding servers, and the network underneath runs on open hardware from multiple vendors. The subscriber features, PPPoE and IPoE termination, RADIUS, policy, and carrier-grade NAT, are the same. The economics and the supply chain are open.
How do you migrate from an existing BNG without an outage?
The open subscriber edge interoperates with an installed base, so it runs alongside the incumbent during a transition rather than replacing it overnight. A common path is to stand up OcNOS aggregation and the netElastic vBNG next to the existing edge, then move subscribers over by service or VLAN in phases. Amplex upgraded this way, keeping its installed Juniper and Ciena equipment in service through the cutover.
How do OcNOS and the netElastic vBNG work together?
OcNOS runs on open aggregation and edge routers and builds the transport: an ISIS-SR core with SR-MPLS and TI-LFA fast reroute, and EVPN-MPLS Layer 2 services (VPLS and VPWS) that carry subscriber VLANs across the network. Those Layer 2 services deliver subscriber traffic to the netElastic vBNG, which terminates PPPoE or IPoE sessions, authenticates each subscriber through RADIUS, assigns an address, and applies policy and CGNAT. The split lets each layer scale on its own.
Should the vBNG be centralized or distributed?
Both are validated designs. In a centralized architecture, subscriber traffic is carried back to the core where one pool of vBNG and CGNAT grooms it, which minimizes hardware, space, power, and cooling and suits an evenly spread subscriber base. In a distributed architecture, a local vBNG sits close to each metro or region, which lowers latency, keeps services local, and isolates fault domains, and suits a network spread across multiple geographies. The same OcNOS transport carries either one.
What subscriber scale does the netElastic vBNG support?
The netElastic vBNG runs on standard x86 servers and reaches up to 1 Terabit per second of throughput on a 2RU server, supporting from 2,000 to 128,000 subscribers per server. It terminates PPPoE, IPoE, and L2TP, with a separate control and data plane so the data plane scales with server cores. Figures are from netElastic. Capacity grows by adding servers rather than forklifting an edge chassis.
What does netElastic CGNAT add?
Carrier-grade NAT conserves scarce public IPv4 addresses by sharing them across many subscribers. netElastic CGNAT scales from 10G to 1 Terabit per second, supports over 50,000 subscribers, and maps up to 100 subscribers per public address, with adjustable logging detail to meet regulatory requirements while controlling storage. It can run integrated with the vBNG or as a standalone function, centralized at the core or distributed near subscribers.
Is this open subscriber edge proven in production?
Yes. Amplex Internet, a broadband provider in Ohio, upgraded its network with OcNOS aggregation routers on Edgecore and UfiSpace hardware, with OcNOS bridging the customer edge to netElastic virtual BNGs and adding SR-MPLS with sub-50ms TI-LFA fast reroute. The pairing of OcNOS and the netElastic vBNG is also captured as a validated reference design by IP ArchiTechs, the independent network-engineering firm.
What hardware does the open subscriber edge run on?
OcNOS runs the aggregation and edge routers on validated open white-box hardware from vendors such as Edgecore and UfiSpace, so operators buy switching hardware and network software on independent cycles. The netElastic vBNG and CGNAT run as software on standard x86 servers. Neither layer ties the operator to a single proprietary platform, and one open network carries both.

Design your open subscriber edge

Tell us the access networks and subscriber scale you serve, and an IP Infusion engineer will help you design the OcNOS transport and size the netElastic vBNG, centralized or distributed.