Skip to main content

Key concepts

Cpehub was built and integrated with distributed, scalable environments in public clouds, so it runs in a cloud environment — the ISP doesn't need local infrastructure to run the servers/services.

Because of this architecture, Cpehub can't be installed locally at the ISP, but this doesn't create any limitation or problem, since all communication is encrypted, controlled, and secure!

Communication

Communication between network elements (OLTs and CPEs) happens through a VPN.

Using a VPN is mandatory to manage CPEs with private IP addresses (CGNAT) in real time. It also avoids exposing management protocols publicly, keeping the provider's backbone isolated.

Supported VPN tunnel types

Cpehub establishes the VPN tunnel with the provider's network using one of these protocols. Choose the one that best fits your scenario:

OpenVPN — coming soon.

Which one to choose?

All of them serve the same purpose (a secure tunnel between Cpehub and your network). When in doubt, WireGuard is the simplest to set up. If your infrastructure already uses IPSec/L2TP, that's supported too. If you're unsure, talk to the deployment team.

Important note

Use ACLs to restrict access exclusively to the IP provided by the deployment team. Equipment IPs/ports must not be globally accessible, not even during system testing.