Skip to content

ISP & telecom

End-to-end network engineering and operations for ISPs

From RIPE resources, BGP edge and MPLS core through to network digital twins, observability, security, backup and disaster recovery.

The problem

The network grew faster than its documentation

The typical Tier-2/Tier-3 operator: a single edge router, BGP policy grown over years, no flow data collected, manual backups, and a migration that hinges on one night window.

  • A single edge router — a SPOF
  • RPKI is not deployed
  • Peering decisions taken without data
  • Configuration is not versioned

Architecture

Architecture

  1. 01Transit / IXPMultiple upstreams
    • Full view
    • IXP peering
  2. 02Edge routersRedundant, with BFD
    • ASR 9000
    • MX
    • CCR
  3. 03PolicyPrefix control
    • RPKI
    • max-prefix
    • communities
  4. 04Core / MPLS
    • OSPF
    • MP-BGP
    • L3VPN
  5. 05AccessSubscriber termination
    • PPPoE/IPoE
    • RADIUS
Dual edge: transit, peering, policy and RPKI validation

Operator consoles

Operator consoles

These exact systems run on the group's own infrastructure — the screenshots are processed before publication.

Blurred Grafana dashboard showing traffic gauges for upstreams and peering sessions.

Bandwidth and peering in real time

Every upstream and every peering session is measured separately, with global and local traffic split apart. Capacity and peering decisions come from this view — not from a hunch.

GrafanaZabbixper-peerIXP
Flow analytics dashboard: total volume, the share of CDN/OTT and Georgian ISP traffic, and a category breakdown chart.

Where the traffic actually comes from — flow analytics

Flow records grouped into ASN categories: CDN/OTT, Georgian ISPs, the group's own networks and international transit. This is the picture that decides which cache to bring inside the network, where peering pays for itself and what stays on paid transit. It is the one screen published legible — everything in it is an aggregate share, with no customer and no address anywhere.

NetFlow / IPFIXper-ASNCDN / OTTpeering economics
Flow dashboard: traffic per router over time and the top source and destination ASNs — the byte figures are blurred.

Who is actually sending the traffic — per ASN

The same flow data, this time with names on it: which CDN and which platform sends the most, where it lands and which router carries it. This list is what turns a peering or cache-placement conversation into an argument with evidence — Akamai, Fastly, Meta, Google. The volumes are blurred; the names and the proportions are not.

NetFlow / IPFIXtop talkersCDNpeering
Blurred AS Upstream analyser showing a per-prefix visibility table across three transits.

BGP visibility per upstream

Each prefix and how visible it is through each transit — which upstream propagates which prefix, and in what share. This is how a route leak, a missing announcement or a mis-built policy becomes visible before it becomes an incident. The tool is public on noc.com.ge.

BGPper-prefixRPKIpublic tool
An automated BGP report from four locations — loss and latency per prefix, with a priority verdict at the end.

Global BGP Report — automatic, every day

From four international vantage points — Sofia, the USA, Amsterdam, India — every one of our prefixes is measured for reachability, loss and latency. No human assembles this: the system compares a 3-hour window against a 24-hour baseline, picks out the direction that is degrading and assigns the priority itself — in this frame P1 is India, where RTT passes 190 ms.

BGPpacket lossRTTautomated
A network map of wireless links — each node showing client count, CCQ, noise floor, airMAX quality and capacity, distance and frequency; hostnames removed.

One map — MikroTik, Ubiquiti and Cambium together

A small or mid-sized operator's network is rarely single-vendor: MikroTik in the core, Ubiquiti on the wireless links, Cambium at the access layer. This map carries, per link, what operations actually runs on — wireless clients on the sector, CCQ, noise floor, airMAX quality and capacity, distance, frequency, Rx/Tx and uptime. The tower power nodes sit on the same map: battery voltage is a metric like any other here, and it explains half of the night-time outages.

MikroTikUbiquitiCambiumairMAXSNMP
Blurred LibreNMS dashboard with a device availability map and alert history.

Network inventory and health

Over 130 devices and thousands of ports in one system: an availability map, alert history and the top errored interfaces — including the GPON/EPON access layer, where a fault shows up on the port before the subscriber notices it.

LibreNMSSNMPGPON/EPONalerting
A Zabbix graph for a single circuit — inbound and outbound traffic over time.

One circuit, one graph — QoS in real time

This is what one business circuit looks like in Zabbix: inbound and outbound traffic, peaks, the real use of the committed rate, and history. It is the graph that answers "is the link actually enough" — and the customer can see that answer too, not only us.

ZabbixQoSSNMPper-circuit
Blurred OpenPath NOC console showing service status, latency sparklines and an incident feed.

OpenPath — our own NOC console

Live path monitoring on a 15-second refresh: latency and packet loss to each service, including cache servers hosted inside individual operators. A path change is recorded as its own incident, with filters by ASN, ISP and customer. We wrote this tool ourselves because no off-the-shelf product answered the question.

in-houselatency / losspath changeper-ASN
Blurred FortiGate dashboard: session, memory and throughput graphs with security-fabric status.

The firewall — policy, sessions and load

A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.

FortiGateHAsegmentationIPsec
Blurred ros-backup dashboard showing device coverage, backup success rate and a fleet table broken down by company.

ros-backup — the configuration archive, collected on its own

A device's configuration is the one file whose loss is measured in hours of downtime. ros-backup collects it every day over SSH — MikroTik RouterOS, Juniper JunOS, Cisco IOS and Arista EOS — and keeps it in a git repository, versioned, with a line-by-line diff between any two. No engineer signs in to each device to copy a config by hand: any router's configuration from any day is two clicks away — including when the device itself will no longer power on. We wrote this one ourselves too.

in-houseRouterOS / JunOS / IOS / EOSgit-versioneddaily over SSH
Heavily blurred billing system screen with a subscriber list — no personal data is legible.

ISP billing and subscriber management

The whole subscriber lifecycle in one system: tariffs, balances, services (internet, Wi-Fi, IPTV), statuses, SMS notifications, logs and financial reports — wired into provisioning. We built it, and it runs a real ISP.

in-housebillingprovisioningIPTV
The phpIPAM dashboard — aggregate statistics for subnets, VLANs and addresses, with usage charts.

IPAM — the address space in one system

A live phpIPAM deployment: subnet hierarchy, VLAN domains, VRFs, devices and locations in one searchable database. Only the aggregate statistics are public — customer names, individual subnets and locations are not on the frame, and should not be.

phpIPAMIPv4 / IPv6VLANVRF
Blurred EVE-NG topology showing routers, switches, peerings and management network links.

The digital twin — the lab that comes before production

A topology built from real network operating systems: border routers, IXP and CDN peerings, the aggregation layer, VLANs and the management network — production, replicated in the lab. Migration, failure and rollback run here first; only then does anyone touch the live network.

EVE-NGIOS XRBGPpre-production

Portfolio

16 delivery modules

Design & build

01

Network audit & architecture

  • Topology mapping
  • SPOF analysis
  • Roadmap
02

L2 engineering

  • VLAN
  • QinQ
  • MSTP
  • LACP
  • Metro Ethernet
  • MTU
03

Routing

  • OSPF
  • iBGP/eBGP
  • MP-BGP
  • MPLS
  • VRF
  • L3VPN
  • BFD
04

Internet edge

  • Transit
  • IXP
  • Full view
  • Dual edge
  • Communities
  • RPKI
05

RIPE NCC resources

  • ASN
  • IPv4/IPv6
  • RIPE DB
  • route/route6
  • ROA
  • rDNS
06

Subscriber & billing

  • RADIUS
  • AAA
  • PPPoE/IPoE
  • DHCP
  • Accounting
  • API

Validate

07

Digital twin / EVE-NG

  • NOS replication
  • Migration test
  • Failure test
  • Rollback
08

Critical infrastructure security

  • FortiGate
  • HA
  • Segmentation
  • Policy
  • SIEM

Observe

09

Observability

  • SNMP
  • Telemetry
  • Prometheus
  • InfluxDB
  • Grafana
  • Zabbix
10

Flow analytics

  • NetFlow
  • IPFIX
  • sFlow
  • Akvorado
  • ClickHouse
11

Managed NOC

  • 24/7
  • Escalation
  • Runbooks
  • Reporting

Protect & recover

12

Configuration backup

  • Versioning
  • Off-device
  • Diff alerts
13

Failover architecture

  • Redundancy
  • BFD
  • Dual homing
14

Disaster recovery

  • DR plan
  • Workload tiering
  • Runbook
15

Validated restore

  • Tested restore
  • Spare hardware
  • Post-restore checks
16

Capacity planning

  • Growth forecast
  • Link saturation
  • Peering strategy

verified infrastructure

ASN

AS203136

OrduNet LLC

Prefix

185.143.176.0/22

announced

RPKI

valid

maxLength /22

Upstream operators

3

Caucasus Online · System Net Ltd · Silknet

Source: RIPE NCC — the group's own resources

Capabilities

Capabilities

Every item is marked: verified production experience, or engineering capability.

Multi-homed BGP edge

Proven

The group's own AS203136 runs on three upstreams — built on the same design principles.

  • BGP
  • BFD
  • Communities

RPKI and routing hygiene

Proven

ROAs published and valid — verifiable in the RIPE registry. Max-prefix limits and route-leak filtering are part of the design on every edge we build.

  • RPKI
  • ROA
  • max-prefix

RIPE NCC resource management

Proven
  • ASN
  • IPv6
  • RIPE DB
  • rDNS

MPLS core and L3VPN

Capability
  • MPLS
  • MP-BGP
  • VRF

Akvorado flow platform

Capability
  • Akvorado
  • ClickHouse
  • IPFIX

Subscriber termination and AAA

Proven
  • PPPoE
  • IPoE
  • RADIUS
  • DHCP

Technology stack

Technology stack

Edge hardware
Cisco ASR 9000Juniper MXMikroTik CCRArista
Telemetry
IOS XR telemetrygNMIPrometheusInfluxDBGrafana
Flow
AkvoradoNetFlow v9IPFIXsFlowClickHouse
Security
FortiGateRPKI validatorRoutinator
Validation
EVE-NG
Alerting
Grafana AlertsTelegramPagerDutyWebhooks

Engagement model

Engagement model

Project

A one-off scope: audit, migration or implementation with a fixed outcome.

Retainer

Monthly engineering hours — specialist access on demand.

Co-managed

NetWizard and your in-house team together, with split responsibility.

Critical operations

24/7 monitoring, response and severity-based escalation.

Use cases

Use cases

Adding a second edge

Removing the SPOF: a second upstream, rewritten policy, validated in the lab first.

Peering optimisation

Reducing transit spend on the basis of actual flow data.

IPv6 rollout

Addressing plan, ROAs, dual-stack termination and monitoring.

FAQ

FAQ

Do you operate an ISP yourselves?

Yes. The group holds AS203136, announces 185.143.176.0/22 with a valid RPKI ROA and connects to three upstream operators. All of it is verifiable in the RIPE registry.

Do you test migrations in production?

No. The migration is first built in EVE-NG: same configuration, same network OS, with failure and rollback tested. Only an approved plan reaches production.

Does telemetry replace SNMP?

No — they work together. Streaming telemetry where sampling rate matters; SNMP polling where the device or metric requires it. Flow then provides a third, independent view.

Tell us about your infrastructure