Stingray Service Gateway - a multifunctional platform based on Deep Packet Inspection technology
Stingray Service Gateway -
a feature-rich traffic management platform.
Determining over 6000 protocols.
Support for the following operation modes: in-line, using routing asymmetry in outgoing traffic, and traffic mirroring mode.
Subscriber management with dynamic IP-addressing and with multiple IP addresses.
Possibility to scale the solution to provide traffic handling up to 4,6 Tbit/s.
Scopes of application
The products developed by VAS Experts are used in high-loaded systems of large fixed-line operators. Multifunctionality of the solutions allows to use them in the corporate segment as well: for organization of public Wi-Fi, optimization and reorganization of networks, control of networks at sites. VAS Experts products are used by Internet providers, IPTV service providers and data centers.

Stingray Service Gateway has been successfully operating on the telecommunications market since 2013
Quality of Service
Quality of Service (QoS) enables traffic prioritization using DPI, ensuring critical applications get the necessary bandwidth. This improves overall network performance and reduces delays in sensitive services. QoS is a key factor in maintaining stable access to IP telephony, IPTV, video conferencing, and other latency-dependent systems. By analyzing traffic in real time, it adjusts resource allocation based on application needs.Traffic Filtering
Telecom networks must comply with regional regulations requiring the blocking of illegal or harmful content. Stingray Service Gateway (SG) provides a flexible, scalable solution for traffic filtering in accordance with local laws.Quality of Experience
Quality of Experience (QoE) is a software solution that measures how subscribers perceive service quality. Based on DPI data, it helps operators improve customer satisfaction, reduce churn, and increase ARPU.Access Control List
Unlike traditional network ACLs that define service ports or domain names on a third-tier OSI, access to which is allowed or denied, the Stingray platform manages traffic up to the 7th level of OSI. This means that one can restrict or allow access to certain services, applications, resources for specific users or groups of users.Mini-Firewall
Mini-Firewall is a Stingray SG feature designed to protect subscribers from hacking and malicious activity.Lawful Interception
Lawful Interception (LI) enables telecom providers to legally grant law enforcement access to private communications to ensure state security. Stingray LI supports interception, storage, and analysis of VoIP, landline, and internet traffic.Advantages of Stingray Service Gateway
Customer is not dependent on a specific hardware vendor, gets the opportunity to reduce capital costs and flexibly scale the solution based on business needs
With Stingray SG, you can analyze packets in transit up to Layer 7 of the OSI model.
Not just by standard port numbers. Deep behavioral analysis of traffic allows you to recognize applications that do not use known headers and structures for communication.
The Stingray platform provides scalability up to 4.6 Tbit/s traffic processing and fast license migration to new equipment. This simplifies network development planning as the number of subscribers and traffic grows.
Related Solutions
CG-NAT
QoE
BRAS/BNG
Lawful Interception (LI)
Get a consultation on Stingray Service Gateway
Basic schemes of Stingray Service Gateway operation
The DPI is connected between the border router and the termination device (BRAS). Fault tolerance is provided by the bypass function in Silicom cards
Asymmetric traffic handling scheme – for policy based routing to filter only web traffic.
Traffic mirroring scheme via SPAN ports or optical splitters.
Demonstration of Stingray Service Gateway solution
Stingray Service Gateway
Characteristics
Feature | SSG 6 | SSG 40 | SSG 80 | SSG 120 | SSG 240 | SSG 360 |
---|---|---|---|---|---|---|
Performance (Gbit)
|
6
|
40
|
80
|
120
|
240
|
360
|
Rack Units
|
1
|
1
|
2
|
2
|
2
|
2
|
Ports (pcs.xGbps)
|
2x10
|
6x10/4x25/4x40/2x100
|
12x10/6x25/6x40/4x100
|
20x10/8x25/8x40/4x100
|
16x25/14x40/8x100
|
28x25/20x40/12x100
|
Subscribers
|
2,5K
|
20K
|
35K
|
50K
|
100K
|
150K
|
Maximum number of sessions
|
8M
|
64M
|
160M
|
256M
|
512M
|
768M
|
New sessions (sessions/sec)
|
250К
|
2000K
|
3000K
|
5000K
|
10 000K
|
15 000K
|
Delay (average) microseconds (µs)
|
30
|
30
|
30
|
30
|
30
|
30
|
Licensing
Options | BASE | BNG | COMPLETE |
---|---|---|---|
Bypass support
|
|
|
|
Statistics gathering and analysis on protocols and directions
|
|
|
|
Traffic prioritization depending on protocols and directions
|
|
|
|
Common and virtual channel policy
|
|
|
|
Subscriber notification and marketing campaigns
|
|
|
|
Subscriber channel policing for IPv4 and IPv6
|
|
|
|
Allow Lists and Captive Portal
|
|
|
|
BNG L3 (IPoE), Dual Stack IPv4/IPv6, Radius with CoA
|
|
|
|
BNG L2 (PPPoE,DHCP), Dual Stack IPv4/IPv6
|
|
|
|
Router with BGP, OSPF, IS-IS support
|
|
|
|
Carrier-Grade NAT
|
|
|
|
Ads blocking and replacing
|
|
|
|
Mini-Firewall for blocking on certain ports
|
|
|
|
Protection against DOS and DDOS attacks
|
|
|
|
Regulatory Compliance | BASE | BNG | COMPLETE |
---|---|---|---|
Filtering by blocklisted Internet sites
|
|
|
|
Lawful Interception (LI)
|
|
|
|
Additional modules and services | BASE | BNG | COMPLETE |
---|---|---|---|
URL Classifier Local version
|
|
|
|
URL Classifier Cloud version
|
|
|
|
Graphical User Interface Base version
|
|
|
|
Graphical User Interface Global version
|
|
|
|
Quality of Experience Module Base version
|
|
|
|
Quality of Experience Module Stadard version
|
|
|
|
Adding banners to HTTP resorses
|
|
|
|
Signatures SDK
|
|
|
|
Extended signatures packs
|
|
|
|