Caveats — Specific to This Release

These describe where this build stops short of the full design, each with a defined path forward:

  • Authentication is local in this build. The production RADIUS client — live sockets, retransmit and dual-server failover, the CoA/Disconnect listener, and RADIUS accounting-record assembly — is the defined next addition. Today the box runs a local AAA provider (open or gated) and can operate standalone with no RADIUS server at all, which is exactly the Community-Edition free-tier on-ramp. Design surfaces that depend on RADIUS (the eight QoS vendor attributes, inbound CoA) exist but light up with that client.
  • IPv4 only on this version. Address assignment, forwarding, policing, and accounting are IPv4 throughout.
  • No IPv6 on this release. IPv6 — dual-stack or IPv6-only, DHCPv6, and prefix delegation — is deferred until prioritised for a future version.
  • Single-node capacity in this release. A node carries on the order of 100,000 concurrent subscribers on commodity R360-class hardware. The per-worker session-table option that would raise a single node to roughly 400,000–500,000 is not in this build; scale beyond a node's ceiling is achieved by adding nodes.

None of the caveats are gaps in the running system so much as the seam between a focused Alpha and the full product design: a line-rate, horizontally-scalable, deeply-observable IPoE BNG that a small or mid-size ISP can stand up on commodity hardware, run standalone today, and federate into RADIUS when the production client lands.


Prepared from the BlueDot Quantum IPoE BNG source tree (ipoe/bng, main) — the architecture summary, the life-of-packet/-event flows, and the engineering overview. Field-level request/response shapes are authoritative in the generated OpenAPI spec and the source, which change faster than this document. © 2026 BlueDot Insight LLC. BlueDot Proprietary.