Bluedot Quantum IPoE BNG - Feature List

Every item below is implemented and running in this build. Designed-but-not-yet-shipping capabilities are listed only under Coming Next.

Forwarding & Identity

  • L3-routed IPoE forwarding (/32 in FIB)
  • IP-keyed sessions (framed IP)
  • Anti-spoof source-IP guard
  • Shared edge-router next hop
  • Deny-by-default forwarding

Rate Limiting & QoS

  • RFC 2698 two-rate three-colour policing
  • Per-direction CIR/PIR (up + down)
  • Green / yellow / red colouring
  • Per-subscriber colour × direction counters
  • Node-wide QoS band counters
  • Zero-burst-safe policer

Filtering & Interception

  • Captive walled-garden filter (DNS/HTTP/HTTPS)
  • DHCP intercept & punt

Data-Plane Platform

  • Userspace VPP on DPDK
  • Access + core/uplink NICs (Intel E810)
  • Multi-worker-correct counters
  • Bulk counter RPC
  • Duplicate-address protection

Control Plane Features

Subscriber Lifecycle

  • Five-state session machine
  • Live re-rate (no re-DHCP)
  • Operator disconnect / revoke / activate
  • Standard RFC 2866 terminate causes

Embedded DHCP & Addressing

  • Embedded DHCPv4 server
  • CIDR pools, first-free allocation
  • Option 82 identity (circuit / remote-id)
  • giaddr topology pool selection
  • Infrastructure-IP reservation
  • Retransmit-safe onboarding
  • Pool-driven leases

Authentication & Service Plans

  • Local AAA provider (open + gated)
  • Per-line subscriber records API
  • Local plan catalog (named plans)
  • Default-plan guarantee (never unpoliced)
  • Captive re-auth on activation

Captive Portal & Prepaid

  • Walled-garden onboarding
  • Portal-only DNS steering
  • Prepaid expiry → captive (keeps IP)
  • Activate endpoint (top-up)

Accounting

  • Start / Interim / Stop orchestration
  • Counter refresh before final record
  • Stable Acct-Session-Id
  • Restart-safe counter pre-load

Timers & Scale

  • Batched interim loop ("tickler")
  • Counter-derived idle detection
  • Batched teardown cascade
  • One-shot offer / lease timers

Persistence & Recovery

  • Durable SQLite session state
  • Timer rebuild from timestamps
  • Three recovery modes
  • Clean stale-session close
  • Config & keys preserved on upgrade

Configuration & Integration

  • Ownership-split config (file vs API)
  • Poll-over-push integration
  • Role-based API-key auth
  • Audit log of mutating calls

Management, Platform & Roadmap

Management & Observability

  • Versioned REST API (/v1/bng/*)
  • OpenAPI spec + ReDoc reference
  • Single-status health rollup (ok / degraded / fault)
  • Accounting read path (/bng/sessions)
  • Telemetry read path (/bng/counters)
  • Live pool / plan / router config API
  • Rotating JSON audit log

Platform & Capacities

  • IPoE, IPv4
  • RFC 2698 policing (per sub, per direction)
  • VPP / DPDK userspace data plane
  • Commodity x86 (Dell R360-class)
  • Intel E810-class NICs
  • Ubuntu 24.04 / kernel 6.14 / x86_64
  • ~100k subs/node target; validated to 10k
  • Horizontal scaling (add nodes)
  • Community Edition session cap

Coming Next

  • Production RADIUS client (sockets, failover, CoA)
  • RADIUS accounting on the wire (gigawords, Class)
  • PEN 65664 QoS vendor attributes + Filter-Id
  • Prometheus /metrics + JSON app logs
  • DSCP remarking (out-of-contract)
  • IPv6 / dual-stack (DHCPv6, PD)
  • Per-worker session tables (~400–500k)
  • Paid license tiers

Scope & Caveats

  • IPoE only (no PPPoE / 802.1X)
  • L3-routed access, no per-sub VLAN / QinQ
  • Policing, not shaping (no AQM)
  • Pull-based telemetry (SNMP is an add-on)
  • No hard data-plane volume cap
  • Local AAA this build (RADIUS deferred)
  • IPv4 only

Prepared from the BlueDot Quantum IPoE BNG source tree (ipoe/bng, main). Field-level request/response shapes are authoritative in the generated OpenAPI spec and the source. © 2026 BlueDot Insight LLC. BlueDot Proprietary.