Logs and legal panel on your server
Compressed columnar database on the CGNAT itself, no third-party log storage. Projected retention of over 4 years on the current disk, with space-based rotation so the disk never fills up.
ISPFactory CGNAT
In production with 33,000 subscribers and 29 Gb/s peaks, with the logs courts ask for stored on your own server.
Standard x86 server with a 100 Gbps NIC. No proprietary appliance.
Measured in production, Sep/Oct 2026
The problem
IPv4 has run out.
How ISPFactory CGNAT solves it
Each subscriber gets blocks of 512 ports on a public IP fixed to them. Many subscribers fit behind a few public IPs.
Court orders ask for IP + port + time (Brazil, Decree 12,975/2026).
How ISPFactory CGNAT solves it
Every port block is logged on your own server, and the legal panel finds the subscriber by port and time.
Appliances are expensive and lock you into one vendor.
How ISPFactory CGNAT solves it
Runs on an off-the-shelf x86 server with an NVIDIA/Mellanox ConnectX 100 Gbps NIC.
How it works
The BRAS hands traffic to the CGNAT over VLAN. The CGNAT announces the public pool over BGP and gives the BRAS a default route.
Each subscriber gets blocks of 512 ports on a public IP fixed to them, up to a configurable cap (currently 32 blocks = 16,000 ports).
Only the opening and closing of each block is logged, not every connection. It stays on the server itself and is searched from the panel.
Log events per day
Per-block logging (ISPFactory CGNAT)
hundreds of thousands
Per-session logging
billions
Measured in production, Sep/Oct 2026
Primary CGNAT of a regional ISP in Northeast Brazil.
Sizing
Current server is designed for 40 Gb/s and has sustained 29 Gb/s in production. Above that, contact us.
What sets it apart
Compressed columnar database on the CGNAT itself, no third-party log storage. Projected retention of over 4 years on the current disk, with space-based rotation so the disk never fills up.
A freshly released block is not handed to another subscriber right away, so two customers are not confused in an investigation. The hold time is configurable.
The numbers on this page come from the primary CGNAT of an ISP in operation. At under 15% load per core, there is plenty of headroom.
A 3.4 to 3.8 million packets per second test attack was dropped with no impact on customers of the targeted IP.
Configuration applies live and rolls back on its own if nobody confirms within 5 minutes. Version history and a from-scratch setup wizard are included.
Web panel and support in Portuguese, with the legal panel designed around Brazilian regulation.
Real case
A subscriber always "at the cap"
The panel flagged a subscriber who was always at the block cap. The investigation found an infected device (botnet) firing attack bursts. The block cap was already containing the damage, with about 9 attack packets per second leaving on average, and the ISP got the diagnosis to act on.
Features
Additional features available per project.
Comparison
Swipe the table sideways to see every column.
| Feature | ISPFactory CGNAT | NFWare vCGNAT | A10 Thunder CGN | MikroTik (RouterOS 7) |
|---|---|---|---|---|
| Type | Software on x86 server + 100G NIC | x86 software (VM, container or VPP plugin) | Appliance or virtual (vThunder) | Router with generic NAT |
| Port blocks (PBA) | Yes(512 ports, configurable cap) | Yes | Yes | No(fixed rules via script) |
| Released-block quarantine | Yes(configurable) | Not documented | Partial(TCP wait of up to 10 min) | No |
| Full-cone NAT (EIM/EIF) + hairpin | Yes | Yes | Yes | Partial(EIM UDP only; manual hairpin) |
| Per-subscriber limits | Yes(blocks + connections/s) | Yes | Yes | Only the rule’s fixed limit |
| Block logging | Yes(IPFIX, stored on the server itself) | Yes(syslog/NetFlow/IPFIX, external collector) | Yes(syslog/NetFlow/IPFIX, external collector) | No |
| Legal panel (lookup, cases, hash-sealed report) | Yes(included) | Not included | Not included | No |
| 2FA + access inventory (Brazil, Decree 8,771) | Yes(included) | Not documented | Not documented | No |
| Pool DDoS protection | Absorbs floods (3.8 Mpps measured, no impact) | Not documented | Yes(per-IP limits, SYN cookie) | No |
| Panel and support in Portuguese | Yes | No | No | Multilingual panel (WinBox); support via resellers |
Competitors per public documentation reviewed in October 2026; features may vary by version, model and license. NFWare, A10 and MikroTik are trademarks of their respective owners.
Want to see it running on your topology?
We walk you through the live panel and answer your network team’s questions.
Log retention (Brazil)
ISPFactory CGNAT was designed to meet these rules and helps ISPs comply with them. It stores connection records and does not store browsing destinations.
Law 12,965/2014, art. 13
Connection providers keep connection records for 1 year, confidentially.
In ISPFactory CGNAT: The block log stays on your server, with projected retention of over 4 years on the current disk.
Decree 8,771/2016, art. 13
Requires security over access to the stored records.
In ISPFactory CGNAT: Mandatory password + authenticator (2FA) login, roles (admin, operator, legal, auditor) and a hash-chained access inventory. Tampering with one line breaks the chain.
Decree 12,975/2026, art. 15-A
Requires keeping the logical source port.
In ISPFactory CGNAT: The log records the opening and closing of each port block, on the subscriber’s fixed public IP.
Lookups, cases and reports in one panel, with a dedicated role for the legal team.
This summary is not legal advice. Check your ISP’s obligations with your legal counsel.
FAQ
Traffic moves to the backup CGNAT over BGP on its own. An automatic watchdog also hands traffic to the backup if it detects a serious failure.
Every change made from the panel applies live and rolls back on its own if nobody confirms within 5 minutes. Version upgrades have one controlled stop and roll back to the previous version automatically if anything fails.
Brazil’s Marco Civil requires 1 year. On the current server’s disk, projected retention is over 4 years. Space-based rotation ensures the disk never fills up.
Open a case in the legal panel and search by public IP + port + date/time (or by private IP + period). If the order has no port, use "candidates" mode. For many addresses, run a CSV batch lookup. The case goes through two-person approval and produces a final report with a SHA-256 seal.
An off-the-shelf x86 server (for example, with 2 Intel Xeon processors) and an NVIDIA/Mellanox ConnectX 100 Gbps NIC. The current server is designed for 40 Gb/s and has sustained 29 Gb/s in production. Above that, contact us.
It works with any BRAS that speaks BGP and delivers traffic over VLAN.
ISPFactory CGNAT uses full-cone NAT (EIM/EIF), which makes these services work better, plus hairpinning so subscribers can reach each other through the public IP. Customers with public IPs bypass NAT, and static mappings are set from the panel.