The access edge,
on one gateway.
Netvyn terminates PPPoE and IPoE subscribers, authenticates them against your RADIUS, assigns addressing, enforces their plan, translates and filters their traffic — and accounts for all of it against a single session record.
01 Platform
One gateway between your core and your subscribers
A broadband network gateway is where subscriber sessions begin and end. Netvyn owns that boundary — and everything that normally gets bolted on around it.
Every session, connect to disconnect
Connect, authenticate, address, apply policy, shape, account. Six steps that usually span three systems, held against one record.
Subscriber management AccessPPPoE and IPoE
Both access models on one gateway, dual-stack, identified by username, MAC or the circuit the subscriber arrived on.
Access models AuthenticationYour RADIUS stays your RADIUS
Authenticate against the server you already run, take each plan from the reply, and account back in the records your billing reads.
RADIUS PolicyBandwidth and filtering as one policy
Rates and filter rules are properties of the same session, bound as it comes up and changeable while it stays up.
QoS and firewall AddressingNAT and CGNAT on the gateway
Stateful translation and deterministic carrier NAT in the same place as the session — no extra hop, no extra appliance.
Address translation ComplianceAnswerable to regulators
Session and translation records are a first-class output. Subscriber traceability becomes a lookup rather than a reconstruction.
Records and IPDR02 Architecture
Inline between the core and the access network
Upstream, Netvyn is an ordinary IP neighbour and a real traceroute hop. Downstream, it is the gateway every subscriber session terminates on. That position is exactly why access, policy and translation belong in the same place.
- 01
Replaces a stack of boxes
Subscriber access, bandwidth management, translation and filtering are one configuration and one commit — not three vendors and three change windows.
- 02
Fits your existing operations
Your RADIUS stays your RADIUS, your billing system stays the system of record, your monitoring keeps scraping.
- 03
Grows without a forklift
Capacity comes from the server you run it on. More subscribers and more traffic mean more cores and memory, not a new chassis or a licence tier.
03 The console
See what the gateway is doing, live
A web console for day-to-day operations, a structured command line for change, and an event stream that tells you what happened to which subscriber — all reading the same state.
Console views
| subscriber | type | address | plan | state |
|---|---|---|---|---|
| subscriber-4471 | pppoe | 100.64.10.83 | res-100 | up |
| subscriber-2210 | pppoe | 100.64.10.41 | res-200 | up |
| a4:2b:8c:11:03:9f | ipoe | 100.64.20.19 | res-050 | up |
| subscriber-0932 | pppoe | — | res-100 | cleared |
| subscriber-1180 | ipoe | 100.64.20.77 | biz-500 | up |
Illustrative layout. Session records shown are examples, not measurements.
Gauge positions are illustrative. Every one of these is a counter you can scrape into your own dashboards.
Shape only
Downstream over upstream. Unlabelled — illustrates the view, not a measurement.
04 Built for your infrastructure
Runs on the operating systems your team already administers
No appliance, no proprietary hardware, no hypervisor requirement. Install it on a server you own and keep your existing patch and monitoring routine.
05 Capability matrix
Which plane each capability operates on
Nine capabilities, five planes of the access edge. Every filled marker is something the same gateway does against the same session.
| Capability | Subscriber access | Policy | Security | Addressing | Network services |
|---|---|---|---|---|---|
| PPPoESession-based access | |||||
| IPoEDHCP-based access | |||||
| RADIUSAAA against your server | |||||
| QoSPlan enforcement | |||||
| FirewallTraffic filtering | |||||
| NATStateful translation | |||||
| CGNATDeterministic port blocks | |||||
| VLAN / QinQAccess topology | |||||
| IP poolsAddress management |
06 Architecture comparison
A multi-appliance edge, and a single-gateway edge
Both architectures work. They differ in how many systems have to agree before a subscriber gets what they paid for.
| Dimension | Multi-appliance access edge | Netvyn single gateway |
|---|---|---|
| Deployment | Separate systems for access, translation and filtering, each with its own lifecycle. | One software install on a server you specify, carrying all three. |
| Change process | A subscriber-facing change may touch several devices and several change windows. | One candidate configuration, one commit, with auto-revert if access is lost. |
| Subscriber state | Identity, address, policy and translation state live in different places and are correlated after the fact. | All of it hangs off one session record, queryable while the session is live. |
| Plan changes | Depends on the device enforcing the rate; a reconnect is sometimes the practical answer. | Applied to a live session by RADIUS CoA, with no disconnect. |
| Address translation | Usually a separate carrier NAT tier with its own capacity planning and its own hop. | NAT and CGNAT run on the gateway, sized as part of the same server. |
| Compliance records | Session logs and translation logs are produced by different systems and joined later. | Session and translation records are produced together as a first-class output. |
| Operating system | Whatever the appliance vendor ships. | Ubuntu 24.04 LTS, Rocky Linux 9 or FreeBSD 14.3, administered by your team. |
| Capacity growth | A larger chassis, or the next licence tier. | More cores, queues and memory on the same licence and the same binary. |
Comparison is against the general multi-appliance pattern. It does not describe any specific vendor’s product.
07 Performance & scale
No software limits. Scale with your hardware.
Netvyn ships no session cap, no throughput tier and no per-subscriber licence step. What the gateway carries is decided by the server you run it on. The figures here are reference points from a validation run, not a product ceiling.
Reference validation run
| Software-imposed limit | None |
|---|---|
| Concurrent sessions | 20,000 PPPoE and IPoE |
| Forwarded traffic | 2.5 Mpps of subscriber traffic |
| Services active | CGNAT, hierarchical QoS, stateful firewall |
| Forwarding loss | Zero |
| Headroom | Scales further with additional cores and memory |
Concurrency is bounded by the memory you give it, never by a licensed ceiling in the software.
Concurrent PPPoE and IPoE subscribers at 2.5 Mpps with CGNAT, QoS and firewalling all active, zero loss.
The same release plans itself across a small gateway or a fully populated carrier server.
Ubuntu 24.04 LTS, Rocky Linux 9 and FreeBSD 14.3, on hardware you specify.
How capacity scales
- More traffic — allocate more CPU cores and receive queues to forwarding.
- More subscribers — sessions and translation tables are memory structures, so concurrency grows with RAM.
- More services — translation and filtering cost per packet, shaping costs per session; we size against your actual service mix.
- More headroom — growth is a configuration change on the same licence, not a tier upgrade or a new chassis.
Sized against your network
Every deployment is sized against your server, your access model and the services you actually enable. We do not quote a number without knowing those three things.
Build your broadband network on Netvyn
A demo with one of our network engineers, against your access model, your RADIUS attributes and your address plan. Thirty minutes, no sales deck.