Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

I built an ISP infrastructure emulator from scratch with a custom vBNG

Details

External ID
47335431
Source
HN
Company
—
Product
I built an ISP infrastructure emulator from scratch with a custom vBNG
Website domain
saphal.me
Launched
March 11, 2026
Cohort
—
Upvotes
68
Upvotes percentile
0.8739237392373924
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Demo: https://aether.saphal.me GitHub: https://github.com/saphalpdyl/AetherAether is a multi-BNG (Broadband Network Gateway) ISP infrastructure lab built almost from scratch that emulates IPoE IPv4 subscriber management end-to-end. It supports IPoE/Ipv4 networks and runs a python-based vBNG with RADIUS AAA, per-subscriber traffic shaping, and traffic simulation emulated on Containerlab. It is also my first personal networking project, built roughly over a month.Motivations behind the projectI'm a CS sophomore. About three years ago, I was assigned, as an intern, to build a OSS/BSS platform for a regional ISP by myself without mentoring. Referencing demo.splynx.com , I developed most of the BSS side ( bookkeeping, accounting, inventory management ), but, in terms of networking, I managed to install and setup RADIUS and that was about it. I didn't have anyone to mentor me or ask questions to, so I had given up then.Three years later, I decided to try cracking it again. This project is meant to serve as a learning reference for anyone who's been in that same position i.e staring at closed-source vendor stacks without proper guidance. This is absolutely not production-grade, but I hope it gives someone a place to start.Architecture overviewThe core component, the BNG, runs on an event-driven architecture where state changes are passed around as messages to avoid handling mutexes and locks. The session manager is the sole owner of the session state. To keep it clean and predictable, the direBNG never accepts external inputctly. The one exception is the Go RADIUS CoA daemon, which passes CoA messages in via IPC sockets. Everything the BNG produces(events, session snapshots) gets pushed to Redis Streams, where the bng-ingestor picks them up, processes them, and persists them.Simulation and meta-configsI am generating traffic through a simulator node that mounts the host's docker socket and runs docker exec commands on selected hosts. The topology.yaml used by Containerlab to define the network topology grows bigger as more BNG's and access nodes are added. So aether.config.yaml, a simpler configuration, is consumed by the configuration pipeline to generate the topology.yaml and other files (nginx.conf, kea-dhcp.conf, RADIUS clients.conf etc.)Known Limitations- Multiple veth hops through the emulated topology add significant overhead. Profiling with iperf3 (-P 10 -t 10, 9500 MTU, 24 vCPUs) shows BNG→upstream at ~24 Gbit/s, but host→BNG→upstream drops to ~3.5 Gbit/s. The 9500 MTU also isn't representative of real ISP deployments. This gets worse when the actual network is reintroduced capping my throughput to 1.6 Gbits/sec in local. - The circuit ID format (1/0/X) is non-standard. I simplified it for clarity. - No iBGP or VLAN support. - No Ipv6 support. I wanted to target IPv4 networks from the start to avoid getting too much breadth without a lot of depth.Nearly everything I know about networking (except some sections from AWS) I learned building this. A lot was figured out on the fly, so engineers will likely spot questionable decisions in the codebase. I'd genuinely appreciate that feedback.Questions- Currently, the circuit where the user connects is arbitrarily decided by the demo user. In a real system with thousands of circuits, it'd be very difficult to properly assess which circuit the customer might connect to. When adding a new customer to a service, how does the operator decide, based on customer's location, which circuit to provide the service to ?

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Horizontal
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
isp infrastructure emulator
Manually corrected
False

Could you build this?

No Building a virtual Broadband Network Gateway (vBNG) with IPoE subscriber management and RADIUS integration demands deep telecommunications and network protocol engineering.

What it would actually take: The project requires creating a low-level packet processing pipeline handling Ethernet/IP encapsulation, DHCP/IPoE subscriber session state machines, dynamic traffic policing, and RADIUS AAA protocol interactions. The stack typically uses Python with raw AF_PACKET sockets, Linux network namespaces, TUN/TAP interfaces, and IP route management. Implementing this requires specialized ISP network architecture expertise and deep knowledge of RFC telecommunication standards.

Discussion

20 comments analyzed.

Competitors mentioned: fd.io / VPP, P4 programming language, OpenFlow, Mininet, Containernet

Concerns raised: OpenFlow is inflexible and slow, adds complexity requiring state synchronization, P4 lacks sufficient hardware support, Software-only routing has high power consumption and packet rate variability, Mininet cannot model subscriber session lifecycle as needed, Circuit assignment mistakes can cause network noise for other customers

Feature requests: IPv6 competency prioritization, eBPF-accelerated BNG for Kubernetes edge deployments, Better circuit planning and customer location-to-circuit mapping optimization

Competitors

Other products that read as similar to this one — 96 launches clear the similarity bar, closest 8 shown.

Attention rank: #15 of 97 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 127 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.