Subscriber Edge on Commodity Servers
Broadband Gateway · CGNAT · QoS · Protection
Capacity · Measured, Not Modelled
4,400 Subscribers. One Server From 2016. Still Not Working Hard.
Every capacity figure you have been shown by a vendor is a model — a spreadsheet extrapolation from a lab box running a stripped-down configuration. This page is the opposite. It is a single minute, taken from a live subscriber network at evening peak, on hardware a decade old, with every protection feature switched on. We publish what the box was actually doing, including the part that is not flattering.
The question that matters to a finance team isn't "how fast is it in a lab." It's how many subscribers fit on one box, and how many years before I have to buy another one.
4,400+
live subscribers on a
single server
2016
the year that server's
processor was launched
Under ¾
how loaded its busiest core got,
at the busiest hour of the day
Zero
packets lost during the
whole measurement
A six-core server bought in 2016 is, by any normal standard, obsolete. It is the machine an operator would have written off two refresh cycles ago. On our software it is currently carrying more than 4,400 broadband subscribers through the evening peak — shaping every one of them, protecting every one of them, and finishing each second with a comfortable margin of unused capacity. That is the whole argument for buying a software subscriber edge instead of a chassis, expressed as one honest measurement.
1 · What was measured, and under what conditions
Benchmarks earn their bad reputation by hiding the setup. So here is ours, in full, before any of the numbers.
THE CONDITIONS
A real network, at its worst hour.
- A production node carrying paying subscribers — not a lab rig, not a traffic generator.
- Sampled during the evening peak, the busiest period of the day, when a broadband network is under its heaviest sustained load.
- A continuous one-minute window, checked every single second — so a brief spike cannot hide inside an average.
- Confirmed by two independent measurements taken from different places in the system, which agreed.
THE HARDWARE
Deliberately unimpressive.
- One six-core server built on a processor generation launched in 2016.
- Ordinary server hardware from a general-purpose vendor. No specialist forwarding cards, no purpose-built silicon.
- No second box standing by, and no capacity borrowed from anywhere else.
- We picked the oldest node we could find on purpose. A new server would have made the numbers look better and proved less.
2 · Everything was switched on
The usual trick in a capacity benchmark is to turn the features off. Traffic shaping, protection and monitoring all cost something, so a number quoted with them disabled is a number you will never see again once the box is in service. On this node, all of it was running, for all 4,400 subscribers, for the whole measurement.
Per-subscriber speed controlEvery subscriber shaped to their own plan rate
Low-latency queueingKeeps video calls and gaming responsive under load
Interactive traffic protectionProtects latency-sensitive flows when a line is congested
DDoS protectionAttack detection running inline on all traffic
Source-address validationBlocks spoofed traffic leaving your network
Outbound abuse containmentLimits compromised subscribers before they harm your reputation
This matters more than the headline number. A capacity figure is only useful if it survives contact with the configuration you actually intend to run. Ours was measured with the full protection suite live and enforcing — not as a best case with the features waiting to be enabled later.
3 · What the box was doing
THE LOAD IT CARRIED
A serious amount of traffic
~16 Gbit/s
of subscriber traffic carried, peaking near 18
- More than 4,400 concurrent subscriber sessions.
- Close to two million packets every second — the measure that actually stresses a forwarding system.
- Sustained, not a momentary burst: this was the level for the entire window.
WHAT IT COST THE SERVER
Less than you would expect
73%
the highest any single core reached, at peak
- Not one second of the measurement saw any core cross 80%.
- Across the server as a whole, roughly two-fifths of the processing capacity was still unused.
- Zero packets lost — no discards, no overrun, nothing dropped anywhere in the window.
Where the pressure actually is
Two different resources on the same server, at the same moment, at evening peak. One of them is close to full. It is not the one people assume.
Network ports (in use)
near limit
Processor — busiest core
headroom
Processor — server average
headroom
4 · The limit is the ports, not the server — and that is the cheap problem to have
This is the part most vendors leave out, and it is the most useful thing on the page. On this node the network ports fill up before the processor does. At peak the links were running around 85–88% full while the processor still had roughly two-fifths of its capacity spare.
WHAT FILLS FIRST
The network ports.
- Traffic enters and leaves on the same set of ports, so port capacity is consumed twice per subscriber packet.
- That is the resource you will exhaust first — and it is visible months in advance.
WHAT THAT COSTS TO FIX
A network card.
- More port capacity is a card upgrade, not a server replacement.
- Far cheaper than a new chassis, a new line card, or another licensed node.
WHAT IT MEANS FOR REFRESH
The server keeps earning.
- If the processor is not the constraint, processor age is not a reason to replace the box.
- Hardware stays in service for longer, and the refresh budget goes further.
Read this as the caution it is. We are not claiming this node is half empty. Its ports are close to full and it will need more port capacity before it needs anything else. What we are claiming is narrower and more useful: the server itself is not the thing running out — so the upgrade in front of this operator is a card, not a replacement machine.
Why a buyer should care. The cost of a subscriber edge is not really the purchase price of the box. It is the number of boxes, multiplied by how often you replace them, plus whatever the vendor charges per subscriber to use them. A platform where a decade-old server still has room changes all three of those numbers at once.
5 · What this changes about the purchase
Measured capacity · what it is worth to you
▣
Fewer boxes for the same subscribersDensity this high on old hardware means a smaller estate: fewer machines to buy, rack, power, cool, monitor and eventually replace.
◷
Longer life from hardware you ownA server whose processor is not the bottleneck does not need replacing when a newer processor appears. Refresh cycles stretch.
$
No per-subscriber licence taxGrowth is a capacity question, not a licence renegotiation. Adding subscribers to a box you already own does not trigger a new purchase order.
↗
Growth you can see comingBecause the constraint is port capacity — a single, visible, trackable number — you plan expansion on a schedule instead of discovering it during an outage.
◆
Ordinary hardware, ordinary procurementStandard servers from whichever vendor already has your business. No proprietary chassis, no line cards, no single-source spares problem.
✓
Features on, not features laterThese figures were taken with the full protection and quality-of-service suite enforcing, so the capacity you are being quoted is the capacity you will run.
6 · What we are not claiming
| Claim | What we stand behind | What we do not say |
| Subscriber capacity |
More than 4,400 subscribers were carried on this node at evening peak with capacity left over. |
That 4,400 is the maximum. We did not push this node to failure — it serves real customers. |
| Headroom |
The processor had meaningful spare capacity throughout, and lost nothing. |
That the node as a whole is half empty. Its ports are close to full. |
| Hardware age |
This is a 2016-generation six-core server doing this work today. |
That every 2016 server will match it. Port capacity and configuration differ. |
| Conditions |
Full protection and quality-of-service feature set live and enforcing. |
That this node runs every product feature. It is a gateway node, not a translation node. |
| Tuning |
The node is configured to our recommended tuning for its network card family. |
That an untuned box behaves identically. Configuration is part of the deployment we deliver. |
Ask us to prove it on your own network. Every figure on this page came from commands an operator can run on their own node, in production, without a maintenance window and without taking anything offline. We would rather you measure it yourself than take the page on trust — that is the entire point of publishing it this way.
The bottom line
A server most operators would already have retired is carrying more than 4,400 live subscribers through evening peak, with every protection feature enforcing, losing nothing, and finishing every second with capacity to spare. Its ports will need upgrading before its processor does.
That is what a software subscriber edge buys you: fewer boxes, bought less often, from whoever you like — and a capacity number that was measured on a live network instead of modelled in a spreadsheet.
About these figures. All numbers on this page come from a single continuous one-minute observation of one production broadband gateway node, sampled once per second, taken during the evening peak period on the day of publication. The node was carrying more than 4,400 live subscriber sessions on a six-core server built on a 2016-generation processor. Traffic during the window averaged approximately 16 Gbit/s of subscriber traffic and close to two million packets per second, with short-term peaks approaching 18 Gbit/s. Processor utilisation is reported as the busiest individual core in each one-second sample; the highest value observed across the window was 73%, and no sample on any core reached 80%. No packets were discarded by the network interfaces or the forwarding system during the window, verified separately over a further 30-second observation at the same load. Per-subscriber speed control, low-latency queueing, interactive traffic protection, DDoS protection, source-address validation and outbound abuse containment were all enabled and enforcing throughout. The node is a broadband gateway; it does not perform carrier-grade address translation, which is a separate function that runs on other nodes in the same product family. Network port utilisation is reported against the installed port capacity in each direction. The node is configured with the network-card tuning we recommend for its interface family; this tuning is part of a delivered deployment and is applied during commissioning. Figures describe this node under this load, and are not a maximum: the node serves paying customers and was not driven to its limit. Capacity on any given deployment depends on installed port capacity, traffic profile, per-subscriber rates and feature configuration, and should be confirmed during design review. No subscriber-identifying information was accessed or is reproduced anywhere in this document.