Open platform for high-speed network applications

We offer our clients unique and open platform for network shaping, routing and security. Deploying NetX platform allows to reduces network latency for end customers and increase quality of experience.
NetX OS offers various features necessary for area border routers, such as traffic shaping for improving latency for your subscribers, advanced routing capabilities, comprehensive IPv6 support and DDoS Protection.
Several boxes are available with various range of ports and performance speed. Every NETX router is equipped with netc – powerful and easy management and configuration tool.

QoS And Traffic management

NetX allows to use advanced shaping algorithms, such as FQ-CoDel, SFQ or CAKE to ensure low latency for end user, efficient delivery of data traffic and fair distribution among consumers.

Together with hierarchical shaping, NetX allows better experience for subscribers, even when end subscriber use multiple devices in the home at the same time.

Each NetX allows defining tens of thousands of traffic groups (depending on the used hardware platform) with minimal impact on the device's performance.

Traffic Management highlights
Hierarchical organization of QoS classes into a tree structure with an unlimited number of nesting and the ability to define traffic priorities among the classes.
Traffic classification into classes based on sources and destinations with the option to aggregate traffic for one class from multiple sources within the IPv4 and IPv6 protocols.
*QoS* And Traffic


The NetX platform functions as a full-fledged router supporting key routing protocols (BGP, BGPv4+, RIPv2, RIPng, OSPFv2, OSPFv3), internally managed by the first-class routing software BIRD developed by the CZ.NIC association.
In the case of the BGP protocol, it is possible to process full BGP tables (BGP full feed) from multiple sources simultaneously and maintain information about millions of routing entries. To enhance security, routing information from the BGP protocol can be validated against Route Origin Authorization (ROA) records using the Resource Public Key Infrastructure (RPKI). For more demanding implementations and scenarios, Policy Based Routing and virtual routing instances (VRF) can be utilized.


For application security, the NetX platform is equipped with a packet filter and a stateful firewall that allows blocking or modifying traffic. In addition to filtering incoming and outgoing traffic, the firewall also provides address translation (NAT).

The DDoS Guard module is responsible for protection against DDoS attacks. It utilizes advanced algorithms that monitor network traffic and automatically learn baselines for configured rules. In the event of a DDoS attack, it is capable of triggering actions for its elimination. This action can be directly handled by NetX or can be signaled to the rest of the network infrastructure using the BGP FlowSpec protocol or custom action definitions.

For the speeds higher then 200Gb/s, there is a specialized expansion module card called DDoS Protector, developed by the association CESNET NREN. This expansion card ensures DDoS attack mitigation in specialized hardware based on FPGA technology.



NetX provides full IPv6 protocol functionality, allowing a smooth transition to the new standard for your organization.

The IPv6 protocol is the successor to the existing and well-known IP protocol, aiming to address several issues of the current protocol, especially the shortage of public IP addresses.

Within the development of the NetX platform, significant emphasis is placed on supporting the IPv6 protocol. All functionalities of the NetX platform are fully supported for IPv6 as well, in conjunction with all essential standards for dual-stack or IPv6-only networks.

Traffic management is fully supported for the IPv6 protocol, allowing bandwidth allocation for customers regardless of the protocol used.

Our team has been actively and extensively involved in the IPv6 domain, participating in conferences and writing specialized articles. Therefore, we can recommend and assist in implementing IPv6 in your network, ensuring compliance with all recommendations and security standards.

IPv6 transition


NetX Carrier Grade NAT enables organizations and network operators to maximize the use of IPv4 addresses.

The address translation feature for operator environments (Carrier Grade NAT / Large Scale NAT) enables efficient use of IPv4 address blocks by translating them into shared (RFC6598) or private addresses (RFC1918). NetX supports both fully stateful 1:N, 1:1, and stateless address translation modes. Address translation events can be exported using the NetFlow protocol extension (NEL - NAT Event Logging). Configuration rules for address translation can also be configured via API or through the integration with ISP CRM systems (such as ispadmin, mango or adminus).


Integration, DevOPS, API

The automation and integration capabilities of NetX allow seamless integration into organizational processes, saving significant time and resources. It supports a full-fledged REST API and a unified management interface (CLI) that reflects the specific network environment. Integration with major network CRM systems and databases is supported, enabling efficient connectivity and data exchange.