Bluedot Quantum IPoE BNG - Feature List
Every item below is implemented and running in this build. Designed-but-not-yet-shipping capabilities are listed only under Coming Next.
Forwarding & Identity
- L3-routed IPoE forwarding (/32 in FIB)
- IP-keyed sessions (framed IP)
- Anti-spoof source-IP guard
- Shared edge-router next hop
- Deny-by-default forwarding
Rate Limiting & QoS
- RFC 2698 two-rate three-colour policing
- Per-direction CIR/PIR (up + down)
- Green / yellow / red colouring
- Per-subscriber colour × direction counters
- Node-wide QoS band counters
- Zero-burst-safe policer
Filtering & Interception
- Captive walled-garden filter (DNS/HTTP/HTTPS)
- DHCP intercept & punt
Data-Plane Platform
- Userspace VPP on DPDK
- Access + core/uplink NICs (Intel E810)
- Multi-worker-correct counters
- Bulk counter RPC
- Duplicate-address protection
Control Plane Features
Subscriber Lifecycle
- Five-state session machine
- Live re-rate (no re-DHCP)
- Operator disconnect / revoke / activate
- Standard RFC 2866 terminate causes
Embedded DHCP & Addressing
- Embedded DHCPv4 server
- CIDR pools, first-free allocation
- Option 82 identity (circuit / remote-id)
- giaddr topology pool selection
- Infrastructure-IP reservation
- Retransmit-safe onboarding
- Pool-driven leases
Authentication & Service Plans
- Local AAA provider (open + gated)
- Per-line subscriber records API
- Local plan catalog (named plans)
- Default-plan guarantee (never unpoliced)
- Captive re-auth on activation
Captive Portal & Prepaid
- Walled-garden onboarding
- Portal-only DNS steering
- Prepaid expiry → captive (keeps IP)
- Activate endpoint (top-up)
Accounting
- Start / Interim / Stop orchestration
- Counter refresh before final record
- Stable Acct-Session-Id
- Restart-safe counter pre-load
Timers & Scale
- Batched interim loop ("tickler")
- Counter-derived idle detection
- Batched teardown cascade
- One-shot offer / lease timers
Persistence & Recovery
- Durable SQLite session state
- Timer rebuild from timestamps
- Three recovery modes
- Clean stale-session close
- Config & keys preserved on upgrade
Configuration & Integration
- Ownership-split config (file vs API)
- Poll-over-push integration
- Role-based API-key auth
- Audit log of mutating calls
Management, Platform & Roadmap
Management & Observability
- Versioned REST API (
/v1/bng/*) - OpenAPI spec + ReDoc reference
- Single-status health rollup (ok / degraded / fault)
- Accounting read path (
/bng/sessions) - Telemetry read path (
/bng/counters) - Live pool / plan / router config API
- Rotating JSON audit log
Platform & Capacities
- IPoE, IPv4
- RFC 2698 policing (per sub, per direction)
- VPP / DPDK userspace data plane
- Commodity x86 (Dell R360-class)
- Intel E810-class NICs
- Ubuntu 24.04 / kernel 6.14 / x86_64
- ~100k subs/node target; validated to 10k
- Horizontal scaling (add nodes)
- Community Edition session cap
Coming Next
- Production RADIUS client (sockets, failover, CoA)
- RADIUS accounting on the wire (gigawords, Class)
- PEN 65664 QoS vendor attributes + Filter-Id
- Prometheus
/metrics+ JSON app logs - DSCP remarking (out-of-contract)
- IPv6 / dual-stack (DHCPv6, PD)
- Per-worker session tables (~400–500k)
- Paid license tiers
Scope & Caveats
- IPoE only (no PPPoE / 802.1X)
- L3-routed access, no per-sub VLAN / QinQ
- Policing, not shaping (no AQM)
- Pull-based telemetry (SNMP is an add-on)
- No hard data-plane volume cap
- Local AAA this build (RADIUS deferred)
- IPv4 only
Prepared from the BlueDot Quantum IPoE BNG source tree (ipoe/bng, main). Field-level request/response shapes are authoritative in the generated OpenAPI spec and the source. © 2026 BlueDot Insight LLC. BlueDot Proprietary.