BNG/BRAS Service Router

License is an asset

The license can be expanded: new features added and performance increased, and if needed, moved to new hardware. This simplifies network development planning as subscriber count and traffic grow.

Easy scalability

Stingray BNG is ready to scale up to 360 Gbps per server and 9.6 Tbps per cluster.

Any scenario

Continuous product development lets the operator be confident in supporting all possible BNG scenarios.

DPI capabilities

Extended functionality and analytics thanks to the built-in deep traffic inspection engine.

Stingray BNG/BRAS (Broadband Network Gateway/Broadband Remote Access Server) is a software product installed on x86 server hardware and virtual environments. Stingray BNG implements the service router function for authorizing and terminating IPoE/PPPoE/L2TP subscribers, allowing a broadband access operator to control subscriber connections to the internet over IPv4 and IPv6, apply tariff plan policies, and offer additional services.

BNG capabilities based on Stingray

Key functional capabilities

Integration

  • combining different authorization types on one device: Static IP, IPoE DHCP, PPPoE, L2TP
  • integration via the RADIUS protocol with CoA and Accounting sent by traffic class
  • RADIUS server load balancing and redundancy
  • local subscriber authorization when RADIUS is unavailable
  • local policing profiles and transmission of absolute speed values
  • session quota by time and by traffic volume consumed
  • integration via API without RADIUS

Connection scheme

  • redirection to a Captive Portal via HTTP Redirect
  • routing: BGP, OSPF, BFD, VRF-lite, ECMP
  • separation of Control Plane and Data Plane
  • Active-Standby and Active-Active redundancy

Services

  • Dual Stack IPv4/IPv6 support
  • group policing (multi-user) – one login linked to multiple IPs
  • support for DHCP Relay and DHCP RADIUS Proxy modes
  • local DHCP server for IPv4/IPv6/IPv6-PD
  • processing of DHCP options (option 82, option 60, and others)
  • VLAN, Q-in-Q, LACP support
  • operation in on-stick and in-line modes
  • CG-NAT, NAT 1:1, NAT64 support and NAT log export via IPFIX
  • Control Plane protection against ARP and DHCP packet attacks

Administration

  • subscriber tracing by IP, MAC
  • traffic dump recording to PCAP locally and to a remote server
  • monitoring via SNMP and Syslog
  • TACACS+ integration
  • administration via CLI and graphical interface

DPI capabilities for Stingray BNG

  • extended QoS support, hierarchical QoS at the subscriber and virtual channel level (VLAN, CIDR)
  • speed boost for local resources and peering networks
  • whitelists with support for hostname, URL, and *.domain masks
  • assignment of additional tariff options
  • traffic coloring (VLAN, IP, MPLS) and processing of already-tagged traffic
  • statistics collection by protocol and direction for the QoE Analytics module
  • marketing capabilities – subscriber behavior analysis
  • internet traffic quality monitoring – network health analysis and detection of BotNet threats and DDoS attacks

The main object of BNG is to authorize users and apply tariff plans.

BNG as the Stingray Service Gateway function provides an opportunity to improve Quality of Service and the way the user perceives it (QoS and QoE). Stingray analyzes traffic at levels 2-7 of the OSI model and handles the protocol data units according to rules applied to them. This allows the broadband operator to use traffic balancing within each uplink, for each subscriber, and for all traffic within the device.

Traffic can get a mark from Stingray SG and be passed further on for prioritization on the router. The platform itself can control the bandwidth according to the algorithms (HTB, TBF) for each of the 8 traffic classes, which are determined on the basis of signatures (instant messengers, streaming video, social networks, torrent, etc).

CG-NAT and 1:1 NAT are available for all authorization types in the BNG solution. IPv4 address translation allows saving address space and gives flexibility in cases if private and public addresses are provided to end subscribers.

Test for free our BNG/BRAS solution on your own hardware or virtual machine

BNG/BRAS solution architecture

Stingray BNG is built on CUPS architecture (Control and User Plane Separation), separating the control and user planes. The Control Plane implements integration with external systems and management. The User Plane handles traffic processing and applies tariff profiles, routing, NAT. Thanks to this separation, high load on the User Plane does not affect the system’s logic, and complex Control Plane logic does not affect traffic processing.

The platform core is a high-performance, in-house-developed DPI engine that detects more than 6,200 protocols and applications using a continuously updated database. The GUI allows the system to be managed (configuration, monitoring, administration) through a graphical interface. Reports are generated in QoE Analytics.

Operating principle

Subscriber traffic – IPoE, PPPoE, or L2TP – placed in Q-in-Q arrives from the aggregation switch over aggregated links (LAG) to the Stingray BNG platform. In the Data Plane, traffic is processed sequentially: BNG terminates subscriber sessions and manages access, DPI performs deep traffic inspection and implements hierarchical policing, and NAT is applied if needed. Processed traffic is forwarded to the Border Router according to BGP/OSPF routing rules.

Session establishment and subscriber authorization are handled in the Control Plane in parallel with the Data Plane, without affecting traffic processing performance. RADIUS Proxy implements load balancing and AAA distribution by subscriber type. IP addresses are issued by the local DHCP server. Soft Router maintains the routing table and exchanges routes with the Border Router. The IPFIX balancer distributes statistics export between QoE nodes for analytics and billing.

BNG Router Architecture Diagram

Broadband Network Gateway Operating Modes

Routed traffic of subscribers with already assigned IP addresses reaches Stingray Service Gateway, it doesn’t identify the original MAC-addresses of subscribers. Identification occurs only by IP address.

BNG L3 IPoE with SSH Management

Preloading of the IP-tariff_plan map using PUSH method; if the dynamic IP assignment is used, the Radius monitor installation or final migration to the Radius is needed.

BNG L3 IPoE with RADIUS Management

Subscriber authorization by the first IP packet via Radius. Stingray Service Gateway operates in transparent bridge mode.

In the L2 BRAS mode, subscriber traffic reaches the Stingray Service Gateway n a unique VLAN /Q-in-Q/PPPoE tunnel. To authorize a subscriber and to assign him an IP address, the MAC/VLAN/Q-in-Q /login PPPoE /option 82 is used. Stingray operates as a virtual gateway for the subscriber and responds to its ARP requests. DHCP settings are provided by the Stingray SG via DHCP Relay or Radius Proxy.

Advantages of the L2 BNG mode: Full-Proxy-ARP, subscriber-to-subscriber connections management, the ability to access to network services in the kernel (dns/www/billing/tv/etc).

BNG L2 DHCP Relay Agent

Subscriber authorization is performed by the Radius server based on the MAC address; DHCP server is used to assign IP addresses.

BNG L2 DHCP RADIUS Proxy

Subscriber authorization is performed by the Radius server based on the MAC address; Radius server is used instead of DHCP servers and the fast-DPI in combination with the fastPCRF operate as a DHCP server.

BNG L2 PPPoE Access

PPPoE subscribers authorization using the PAP, CHAP or MS-CHAPv2 protocols or by MAC address.

L2 BNG PPPoL2TP/LNS

For L2TP connections, the subscriber uses the server name in the L2TP client settings, resolved by the operator’s DNS balancer. BNG LNS establishes an L2TP tunnel with any initiator. From the BNG’s perspective, there are two types of L2TP subscribers:

  • A PPPoL2TP subscriber receives an IP address via DHCP on the current BNG and establishes L2TP with the current BNG.
  • A PPPoL2TP subscriber receives an IP address via DHCP on a remote BNG and establishes L2TP with the current BNG.

BNG Solution Video Overview

Request a Free BNG/BRAS Demo

Fill in the form
We will contact you, specify the task, provide access to the documentation and answer your questions.
Choose the solution
We discuss the current situation: traffic volume, available equipment, the functionality you need.
Free trial
Our engeniers install the selected software and adapt it to your specific tasks. Сontract — only after the test is successful.