Back to home

ISPFactory CGNAT

Carrier-grade NAT, built for regional ISPs

In production with 33,000 subscribers and 29 Gb/s peaks, with the logs courts ask for stored on your own server.

Standard x86 server with a 100 Gbps NIC. No proprietary appliance.

Measured in production, Sep/Oct 2026

concurrent subscribers
33.6k
peak traffic
29 Gb/s
concurrent sessions
3.5M
NIC packet loss
0

The problem

Three reasons ISPs come to us

  • IPv4 has run out.

    How ISPFactory CGNAT solves it

    Each subscriber gets blocks of 512 ports on a public IP fixed to them. Many subscribers fit behind a few public IPs.

  • Court orders ask for IP + port + time (Brazil, Decree 12,975/2026).

    How ISPFactory CGNAT solves it

    Every port block is logged on your own server, and the legal panel finds the subscriber by port and time.

  • Appliances are expensive and lock you into one vendor.

    How ISPFactory CGNAT solves it

    Runs on an off-the-shelf x86 server with an NVIDIA/Mellanox ConnectX 100 Gbps NIC.

How it works

From BRAS to log, in three steps

Subscribers
BRAS
ISPFactory CGNATtranslates into port blocks
Backup CGNATtakes over if the primary stops
Internet
  1. Step 1

    Subscribers leave through the BRAS

    The BRAS hands traffic to the CGNAT over VLAN. The CGNAT announces the public pool over BGP and gives the BRAS a default route.

  2. Step 2

    The CGNAT translates into port blocks

    Each subscriber gets blocks of 512 ports on a public IP fixed to them, up to a configurable cap (currently 32 blocks = 16,000 ports).

  3. Step 3

    The block log is stored and searchable

    Only the opening and closing of each block is logged, not every connection. It stays on the server itself and is searched from the panel.

Log events per day

Per-block logging (ISPFactory CGNAT)

hundreds of thousands

Per-session logging

billions

Measured in production, Sep/Oct 2026

Numbers from a primary CGNAT in operation

Primary CGNAT of a regional ISP in Northeast Brazil.

concurrent subscribers
33.6k
peak traffic
26–29 Gb/s
concurrent sessions
3.4–3.5M
new sessions per second
9–10k
real load per processing core
< 15%
test DDoS attack dropped with no impact on customers of the targeted IP
3.4–3.8 Mpps
NIC packet loss after queue tuning (over 1,000 samples)
0

Sizing

Current server is designed for 40 Gb/s and has sustained 29 Gb/s in production. Above that, contact us.

What sets it apart

What changes in your operation

Logs and legal panel on your server

Compressed columnar database on the CGNAT itself, no third-party log storage. Projected retention of over 4 years on the current disk, with space-based rotation so the disk never fills up.

Block quarantine

A freshly released block is not handed to another subscriber right away, so two customers are not confused in an investigation. The hold time is configurable.

Numbers measured in production

The numbers on this page come from the primary CGNAT of an ISP in operation. At under 15% load per core, there is plenty of headroom.

DDoS resilience

A 3.4 to 3.8 million packets per second test attack was dropped with no impact on customers of the targeted IP.

Changes with automatic rollback

Configuration applies live and rolls back on its own if nobody confirms within 5 minutes. Version history and a from-scratch setup wizard are included.

Built for Brazilian ISPs

Web panel and support in Portuguese, with the legal panel designed around Brazilian regulation.

Real case

A subscriber always "at the cap"

The panel flagged a subscriber who was always at the block cap. The investigation found an infected device (botnet) firing attack bursts. The block cap was already containing the damage, with about 9 attack packets per second leaving on average, and the ISP got the diagnosis to act on.

Features

What ISPFactory CGNAT does

Carrier-grade NAT

  • Port block allocation (PBA), industry standard (RFC 6888)
  • Randomized port within the block (RFC 6056)
  • Full-cone NAT (EIM/EIF): gaming, video calls and P2P work better
  • Hairpinning: subscribers reach each other through the public IP
  • Per-subscriber limits: block cap and new-connections-per-second metering, with the option to block the excess
  • PPTP ALG (legacy VPN still used by businesses), with GRE NAT
  • NAT bypass: ranges and customers with public IPs pass straight through
  • Static mappings (fixed port or dedicated 1:1 IP) from the panel

Operations and availability

  • Web panel: traffic, sessions, blocks, BGP neighbors, LACP and drops
  • Alarms by severity and by email
  • Metrics for Prometheus/Grafana
  • Built-in BGP and LACP on the 100G ports
  • Redundancy with a backup CGNAT over BGP
  • Automatic watchdog: on a serious failure, it hands traffic to the backup by itself
  • Version upgrades with one controlled stop and automatic rollback if anything fails

Additional features available per project.

Comparison

Side by side with the usual options

Swipe the table sideways to see every column.

CGNAT comparison table
FeatureISPFactory CGNATNFWare vCGNATA10 Thunder CGNMikroTik (RouterOS 7)
TypeSoftware on x86 server + 100G NICx86 software (VM, container or VPP plugin)Appliance or virtual (vThunder)Router with generic NAT
Port blocks (PBA)Yes(512 ports, configurable cap)YesYesNo(fixed rules via script)
Released-block quarantineYes(configurable)Not documentedPartial(TCP wait of up to 10 min)No
Full-cone NAT (EIM/EIF) + hairpinYesYesYesPartial(EIM UDP only; manual hairpin)
Per-subscriber limitsYes(blocks + connections/s)YesYesOnly the rule’s fixed limit
Block loggingYes(IPFIX, stored on the server itself)Yes(syslog/NetFlow/IPFIX, external collector)Yes(syslog/NetFlow/IPFIX, external collector)No
Legal panel (lookup, cases, hash-sealed report)Yes(included)Not includedNot includedNo
2FA + access inventory (Brazil, Decree 8,771)Yes(included)Not documentedNot documentedNo
Pool DDoS protectionAbsorbs floods (3.8 Mpps measured, no impact)Not documentedYes(per-IP limits, SYN cookie)No
Panel and support in PortugueseYesNoNoMultilingual panel (WinBox); support via resellers

Competitors per public documentation reviewed in October 2026; features may vary by version, model and license. NFWare, A10 and MikroTik are trademarks of their respective owners.

Want to see it running on your topology?

We walk you through the live panel and answer your network team’s questions.

Book a demo

Log retention (Brazil)

What Brazilian law requires, in plain words

ISPFactory CGNAT was designed to meet these rules and helps ISPs comply with them. It stores connection records and does not store browsing destinations.

Law 12,965/2014, art. 13

Marco Civil da Internet

Connection providers keep connection records for 1 year, confidentially.

In ISPFactory CGNAT: The block log stays on your server, with projected retention of over 4 years on the current disk.

Decree 8,771/2016, art. 13

Secure access to records

Requires security over access to the stored records.

In ISPFactory CGNAT: Mandatory password + authenticator (2FA) login, roles (admin, operator, legal, auditor) and a hash-chained access inventory. Tampering with one line breaks the chain.

Decree 12,975/2026, art. 15-A

Source port

Requires keeping the logical source port.

In ISPFactory CGNAT: The log records the opening and closing of each port block, on the subscriber’s fixed public IP.

Legal panel included

Lookups, cases and reports in one panel, with a dedicated role for the legal team.

  • Lookup by public IP + port + date/time, or by private IP + period
  • Batch lookup (CSV)
  • "Candidates" mode when the court order has no port (Brazilian Superior Court of Justice, REsp 2,170,872/2025)
  • Case and court-order management with two-person approval
  • Final report with a SHA-256 seal that proves the document’s integrity

This summary is not legal advice. Check your ISP’s obligations with your legal counsel.

FAQ

Questions from network operators

What happens if the server goes down?

Traffic moves to the backup CGNAT over BGP on its own. An automatic watchdog also hands traffic to the backup if it detects a serious failure.

Can a configuration change take the network down?

Every change made from the panel applies live and rolls back on its own if nobody confirms within 5 minutes. Version upgrades have one controlled stop and roll back to the previous version automatically if anything fails.

How long are logs kept?

Brazil’s Marco Civil requires 1 year. On the current server’s disk, projected retention is over 4 years. Space-based rotation ensures the disk never fills up.

How do I answer a court order?

Open a case in the legal panel and search by public IP + port + date/time (or by private IP + period). If the order has no port, use "candidates" mode. For many addresses, run a CSV batch lookup. The case goes through two-person approval and produces a final report with a SHA-256 seal.

What hardware do I need?

An off-the-shelf x86 server (for example, with 2 Intel Xeon processors) and an NVIDIA/Mellanox ConnectX 100 Gbps NIC. The current server is designed for 40 Gb/s and has sustained 29 Gb/s in production. Above that, contact us.

Does it work with my BRAS?

It works with any BRAS that speaks BGP and delivers traffic over VLAN.

Do gaming, video calls and P2P work behind the CGNAT?

ISPFactory CGNAT uses full-cone NAT (EIM/EIF), which makes these services work better, plus hairpinning so subscribers can reach each other through the public IP. Customers with public IPs bypass NAT, and static mappings are set from the panel.

Book a live demo of the panel

See the operations panel and the legal panel at work.

Book a demo