See and control every application flowing through VPP.

PacketLens is an open-source DPI and call intelligence plugin suite for FD.io VPP. It classifies 300+ applications, enforces per-application policy and rate limits, exports IPFIX flow records and SIP CDRs, and applies a three-tier spam filter to flag suspicious calls for transcription and enforcement — all inside the data plane, at line rate, with zero hardware changes.

Pre-production · lab-validated on our own bench, not yet deployed in production
300+protocols
< 8 nscached overhead
100G–800GVPP line rate
Apache 2.0license
PacketLens Grafana dashboard showing live application traffic

What PacketLens does

🔍

App classification

Identifies 300+ protocols — YouTube, Zoom, Netflix, SIP, RTP, DNS, TLS, QUIC, GTP-U, BitTorrent — using nDPI. SNI extraction, JA3 fingerprinting, risk scoring. Under 8 ns per cached flow.

Source
🚦

Per-app policy

Drop or permit traffic by application class. Rules installed at runtime via CLI or binary API — no restarts, no config files. set policy app BitTorrent action drop.

Source
🎚️

Per-app rate limiting

Token-bucket policer per application. Cap YouTube to 5 Mbps, DSCP-mark excess for downstream QoS — all in the forwarding path. set policer-ndpi app YouTube rate 5M.

Source
📡

IPFIX / NetFlow export

RFC 7011 flow records enriched with application name, category, TLS SNI, and JA3 fingerprint. Sends to any collector — ntopng, Elasticsearch, Splunk, or custom pipeline.

Source
📊

Prometheus metrics

Per-application packet, byte, and flow counters scraped directly from VPP's stats segment. Grafana dashboard included — zero extra config.

Source
🎙️

Spam & robocall detection — selective transcription

vpp-rtp-asr applies a three-tier filter to RTP audio: keyword spotting, audio heuristics (WPM, energy variance, silence ratio), and per-session score accumulation. Suspicious calls are flagged for transcription via Moonshine ASR — no external recorder, no SIP signaling dependency.

Source
🤖

AI-ready enforcement plane

Register any AI/ML scoring function as a callback. PacketLens calls your model once per new flow with the full L7 verdict — application, category, risk score, TLS SNI, JA3 — and applies your policy inline, classification to enforcement in under 1 ms. Pair with vpp-rtp-asr transcripts to run speech-based spam classifiers per call.

Source
📞

SIP CDR export to Homer

Mirrors every SIP packet to Homer SIPCapture via HEP3 — the same protocol used by SBCs and SIP proxies. INVITE, 200 OK, BYE, and all SIP methods land in Homer's call search in real time. set cdr hep server 10.0.0.5 port 9060.

Source

Inside the data plane, not next to it

Commercial DPI appliances sit next to your router on a mirror port. They cost $80K–$300K per chassis, require dedicated hardware, and add an extra hop to your management plane.

PacketLens runs inside VPP itself, as a feature arc node on ip4-unicast. Classification happens in nanoseconds, on the same CPU core as your forwarding path. No mirror port. No extra server. No per-Gbps license.

VPP is the forwarding engine behind 100G–800G production deployments at ISPs and carriers. PacketLens is built to preserve that scale rather than inherit it by assumption — on our bench it adds ~8 ns per cached packet on the fast path once a flow is classified.

Get in touch →
Without PacketLens
Router VPP ──mirror──► DPI Appliance
$200K
→ slow · expensive · extra hardware
With PacketLens
Router VPP
+ ndpi-observe
→ in-process · free · < 8 ns overhead

Live application visibility in Grafana

The included Grafana dashboard shows real-time application traffic — throughput, flow rates, and engine metrics — scraped from VPP's stats segment via Prometheus.

PacketLens Grafana dashboard — kiosk view

Application classification in action

Watch nDPI classify live traffic in real time — YouTube, DNS, TLS, HTTP/2, and more appear in show ndpi applications as the engine identifies each flow. Per-application packet and byte counters tick up live alongside each verdict.

nDPI classification demo — 12 apps appear in show ndpi applications while stats counters tick up live

IPFIX export to any collector

PacketLens exports RFC 7011 IPFIX flow records enriched with nDPI metadata — application name, category, TLS SNI, and JA3 fingerprint. Any standard IPFIX/NetFlow collector can consume the stream.

ntopng live flow browser receiving IPFIX from VPP via PacketLens
ntopng dashboard — Top Flow Talkers, Top Applications from VPP IPFIX

ntopng dashboard

ntopng host table — VPP lab hosts visible via IPFIX

Per-host breakdown

Lab stack: VPP → IPFIX UDP/2055 → nProbe → ZMQ → ntopng.

SIP CDR export to Homer SIPCapture

vpp-cdr mirrors every SIP packet to Homer SIPCapture via HEP3 — the same protocol used by SBCs and SIP proxies. INVITE, 100 Trying, 180 Ringing, 200 OK, ACK, BYE — every SIP message in every call lands in Homer's call search in real time, enriched with timestamps and flow metadata.

Homer SIPCapture dashboard — 19 SIP messages from 5 calls visible: INVITE, 100 Trying, 180 Ringing, 200 OK, ACK, BYE — alice→bob and trunk→user1..4 — captured from VPP via HEP3

Homer dashboard — 19 SIP messages from 5 concurrent calls captured via HEP3. Two commands: set cdr hep server 10.0.0.5 port 9060 + set interface cdr enable eth0.

Per-app enforcement — drop, permit at wire speed

vpp-policy enforces drop/permit rules inline on the ip4-unicast feature arc. Rules apply only to classified flows — unclassified packets are always permitted so nDPI can finish its verdict.

Policy enforcement demo — BitTorrent/TikTok/Facebook dropped, YouTube permitted; drop/permit counters growing live

Two CLI commands to deploy: set interface policy eth0 enable + set policy app BitTorrent action drop.

Per-app rate limiting — drop or DSCP-mark at wire speed

vpp-policer-ndpi attaches a token-bucket policer to each application class. YouTube saturating a link? Cap it to 5 Mbps and DSCP-mark excess packets for downstream QoS — all inside VPP, no separate device.

Rate limiting demo — DNS/YouTube/Netflix policers configured; conform/drop/DSCP-mark counters growing live

One command: set policer-ndpi app YouTube rate 5M burst 40K dscp-mark 8.

SIP CDR export — every call captured in Homer

vpp-cdr mirrors SIP packets to Homer SIPCapture via HEP3 — the same protocol used by SBCs and SIP proxies. Every INVITE, 200 OK, BYE lands in Homer's call search in real time. nDPI identifies SIP flows; a port heuristic (5060/5061) handles the rest. The non-blocking UDP socket never stalls the forwarding path. Pair with vpp-rtp-asr to attach a spam score and selective transcript to each CDR entry — flagged calls get both the signaling record and the spoken content.

vpp-cdr — CDR server configured at 10.0.0.5:9060; SIP INVITE/BYE/200 OK mirrored via HEP3; Homer shows 19 SIP messages across 5 calls in real time

Two commands: set cdr hep server 10.0.0.5 port 9060 + set interface cdr enable eth0. Homer UI at http://homer:9080.

Three-tier spam filter — flag suspicious calls, transcribe what matters

vpp-rtp-asr intercepts RTP flows inside VPP and runs a three-tier spam detection pipeline entirely in the data-plane worker threads. No external recorder, no SIP signaling dependency — the plugin decodes G.711/G.722/G.729/Opus, resamples to 16 kHz, and scores each 2-second audio segment before deciding whether to emit a full transcript.

Tier 1 — keyword spotting: Moonshine ASR transcribes flagged audio segments and matches against a configurable keyword list ("press 1", "social security", "call now", …). Tier 2 — audio heuristics: silence ratio, energy variance, and words-per-minute consistency catch synthetic TTS voices without any transcript. Tier 3 — session scoring: per-session score accumulates across segments; confirmed spam sources are reported with their score and transcript for downstream enforcement.

vpp-rtp-asr live transcript UI — real-time captions from active VoIP calls, showing source IP, SSRC, codec, and transcribed text updating as audio flows through VPP

Live demo: Piper TTS → ffmpeg RTP → VPP rtp-asr tap → Moonshine ASR → browser UI. Each row is one 2-second audio segment arriving as JSON-UDP.

vppctl split screen — left: show rtp-asr spam listing spam hits, thresholds, and 12 default keywords; right: show rtp-asr sessions with per-session spam score and decision (clean / SPAM?)

show rtp-asr spam — thresholds and matched keywords · show rtp-asr sessions — per-SSRC spam score and decision (clean / SPAM? / SPAM!).

Composable plugin stack

Each plugin registers on the same VPP feature arc. Enable only what you need — the data plane cost is proportional to the plugins you activate.

classify: app, category, SNI, JA3, risk score
↓
enforce: drop / permit by app
rate-limit: per-app token-bucket — drop or DSCP-mark
↓
export: IPFIX records enriched with app fields + SNI
scrape: Prometheus metrics + Grafana dashboard
mirror: SIP CDR export via HEP3 to Homer SIPCapture
spam filter: keyword spotting + audio heuristics → score suspicious calls → selective Moonshine ASR → JSON transcript

All PacketLens plugins are open-source (Apache 2.0). Commercial support and custom integration available from PacketFlow.

Performance

MetricValueCondition
Line rate100G–800GVPP multi-worker, scales linearly
Overhead per packet (classifying)~150 nsfirst 3–8 packets per flow
Overhead per packet (cached flow)~8 nsbihash lookup only — invisible at any line rate
Flow table lookupO(1)per-worker, no locks
Max flows per worker1Mconfigurable
Classification convergence3–8 pkts95th pct, TCP/TLS
Protocols classified300+nDPI 4.2.0

Figures are measured on our own lab bench — a single x86 server driven by a hardware traffic generator — not collected from a production network. Line rate is VPP's established forwarding capability, which PacketLens is designed not to reduce; it is not a figure PacketLens has itself sustained at 800G.

Built on proven open-source foundations

FD.io VPP

Packet processing framework — 100+ Gbps forwarding, used by Cisco, Ericsson, Nokia, and scores of network vendors. Apache 2.0.

ntop nDPI

Deep packet inspection — 300+ protocols, used by ntopng, Suricata, Zeek, pfSense, and Arkime. LGPL-3.0.

Prometheus + Grafana

Industry-standard metrics and dashboards. Zero-code integration via VPP's stats segment shared memory. Apache 2.0.

Get in touch

Want to try PacketLens on a bench, or talk about building on it? We'll get back to you within 24 hours.