Most operators pick a port speed the same way they pick lunch — by what's on the menu and what fits in the budget. Then they discover on a Saturday night that they bought lunch when they needed dinner, and now the whole panel is buffering.
This post is the fourth in the napkin-math series (after IPTV bandwidth sizing, GPU sizing and storage sizing). Same style: four numbers, one formula, real thresholds, no theory.
The formula
The port speed you need is roughly:
port_Gbps ≥ (peak_concurrent × avg_bitrate_mbps × abr_multiplier) / 1000 × headroom_factor- peak_concurrent — how many boxes/browsers are pulling from you at the busy moment
- avg_bitrate_mbps — weighted average across your resolution mix
- abr_multiplier — 1.25 for HLS, 1.20 for DASH, 1.0 for single-bitrate
- headroom_factor — 1.4 for a healthy panel, 1.8 if you don't want to migrate mid-year, 2.5 if you get DDoS'd regularly
Pick a port speed that satisfies that inequality with headroom. Then round UP to the next real port tier — because port speeds don't come in continuous values, they come in 1G / 10G / 25G / 40G / 100G / 200G / 400G.
The four honest tiers
Every provider brands their ports differently. In practice, the market has four real tiers, and each one has a natural workload range.
| Port | Real max sustained | Real-world concurrent HD (5 Mbps × 1.25 ABR) | Monthly egress ceiling |
|---|---|---|---|
| 1 Gbit/s | 900 Mbps | ~144 streams | 320 TB |
| [10 Gbit/s](/net10g) | 9.2 Gbps | ~1,470 streams | 3.2 PB |
| [25 Gbit/s](/net25g) | 23 Gbps | ~3,680 streams | 8.1 PB |
| [100 Gbit/s](/net100g) | 92 Gbps | ~14,720 streams | 32 PB |
| [400 Gbit/s](/net400g) | 380 Gbps | ~60,800 streams | 132 PB |
40G exists on paper but is fading — most switch fabrics went straight from 10G to 25G, and modern hardware uses 4×25G LAG for aggregate 100G instead of 40G. 200G exists in transit gear but rarely in dedicated hosting SKUs.
Rule of thumb: whatever port speed you calculate, jump one tier higher. Migration cost is always > port cost delta.
Tier 1 — 10 Gbit/s. The honest starter.
Who this is for:
- IPTV panels up to ~15,000 active lines
- Starter tube sites doing < 50k daily uniques
- Regional CDN cache in front of a bigger origin
- Small streaming platforms, growing SaaS backends
Napkin math example: 12,000 active IPTV lines × 38 % peak concurrency × 5 Mbps × 1.25 ABR = 28.5 Gbps of demand at peak. That's already over a single 10G port — meaning if you have 12k active, you're past this tier.
Real customer numbers (mid-size EU IPTV reseller, ~8k active lines):
- Average night: 4.1 Gbps
- Friday sports peak: 7.8 Gbps
- 10G port utilisation at that peak: 78 %
That's a good ratio — headroom to absorb an event without buffering. When their peak crossed 8.5 Gbps regularly, we moved them to 25G. Their monthly bill went up by $250/mo. Their support ticket volume dropped 60 %.
When it stops working:
- Peak utilisation over 70 % for more than 3 nights per week
- You're getting DDoS traffic that fills the pipe alongside legit users
- Any single event pushes you past 9 Gbps
- You add a second product line (VOD, catch-up, live sport) and demand jumps 30 %+
Full 10G port spec here. Real SFP+ optics, LACP to 20/40G if you need a bridge before jumping to 25G.
Tier 2 — 25 Gbit/s. The workhorse.
Who this is for:
- IPTV panels 30,000 to 100,000 active lines
- Tube sites at 100k+ daily uniques
- Mid-CDN origins serving 5–8 PB/month
- Regional streaming platforms, game-server clusters
- Anyone who's outgrown a 10G box but doesn't have 100G workload yet
Napkin math example: A national tube site with 180k DAU, avg session 12 min, avg bitrate 3.8 Mbps (mixed 720p/1080p), 22 % peak concurrency = 180k × 0.22 × 3.8 × 1.25 = 188 Gbps peak. Wait — that's way past 25G. So a single 25G box is undersized for that scale. Two 25G in LACP → 50G aggregate covers it with headroom.
Real customer numbers (LATAM streaming panel, ~50k active lines):
- Nightly peak: 18.2 Gbps
- World Cup final: 24.9 Gbps (99 % port utilisation, one 25G port)
- Post-event: moved to a 2×25G LAG for the next season
The 25G tier is where most operators SHOULD live for years — the price/performance curve is the flattest here. But it's also the tier operators skip because they read "100G" on a competitor's homepage and think they need it.
When it stops working:
- Peak crosses 22 Gbps regularly (85 % utilisation)
- You're serving multiple regions and need multi-PoP origin bandwidth
- Live-event windows push you past 25 Gbps repeatedly
25G port spec here. SFP28 optics, LACP to 50/100G if you're bridging to 100G.
Tier 3 — 100 Gbit/s. The heavy tier.
Who this is for:
- IPTV panels 100k+ active lines
- National-scale streaming, live-event origins
- Large CDN origins (10 PB+ monthly)
- File-hosting operators pushing bulk-download traffic
- Multi-region operators consolidating on one origin box
Napkin math example: A 120k-line panel × 42 % peak (higher because of high-engagement audience) × 5.2 Mbps avg × 1.25 = 328 Gbps at peak. Even 100G isn't enough — need 4×100G LAG (400G aggregate) or move to dedicated 400G.
Real customer numbers (MENA IPTV panel, 85k active lines):
- Steady-state peak: 71 Gbps
- Champions League final 2024: 119 Gbps (needed LAG'd second 100G port)
- DDoS Saturday incident: 240 Gbps SYN flood absorbed by scrubbing, legit traffic dropped from 89→22 Gbps until filtered
When 100G is right (not overkill and not undersized):
- Peak concurrent between 12k and 20k HD streams
- Monthly egress 8–25 PB
- You need multi-PoP replication and 100G matches your inter-PoP transit capacity
- Live events regularly push above 60 Gbps
100G port spec here. QSFP28 LR4 / SR4 transceivers, 4×100G LAG for 400G aggregate available.
Tier 4 — 400 Gbit/s. The super-PoP.
Who this is for:
- IPTV / OTT operators past 200k concurrent viewers on a single origin
- Live-event broadcasters (World Cup, Champions League, F1)
- CDN aggregators feeding downstream POPs
- Game update distribution (AAA patch drops)
- Multi-Tbit/s DDoS scrubbing fabrics (our own network uses 400G internally)
Napkin math example: 100k concurrent HD subscribers on a single origin at 4 Mbps = 400 Gbps exactly. One 400G port replaces a rack of 16 25G boxes and eliminates the load-balancer layer entirely.
When 400G is right:
- Single-origin architecture serving 100k+ concurrent HD viewers
- Backup / DR replication moving 100 TB+ datasets across continents in under an hour
- Bulk data transfer (scientific, ML training set sync) at PB-scale
- You need the port for internal fabric (backbone, scrubbing) rather than customer-facing
When 400G is overkill:
- Any peak below 200 Gbps
- You could distribute the load across 4×100G with LB (usually cheaper)
- You don't have 400G upstream/downstream to actually use it end-to-end
400G is a super-PoP tool. If you're not sure you need it, you don't. But when you do — a single 400G on QSFP-DD DR4 replaces a switch chassis and half your ops overhead.
400G port spec here. Custom-quoted per project, jumbo frames end-to-end, dedicated scrubbing capacity in front.
Cost curve — where the sweet spot lives
Approximate monthly cost per Gbit/s sustained (varies by PoP, colo pricing, upstream mix):
| Tier | Typical dedicated cost | Cost per sustained Gbps |
|---|---|---|
| 1G unmetered | $80/mo | $88 |
| 10G unmetered | $180/mo | $19.60 |
| 25G unmetered | $429/mo | $18.60 |
| 100G unmetered | $1,290/mo | $14.00 |
| 400G unmetered | $4,800/mo | $12.60 |
The interesting thing: 25G is barely more expensive per bit than 100G, and dramatically cheaper than 10G on a per-bit basis. If your workload is between 8 and 20 Gbps, jumping straight to 25G is cheaper long-term than staying on 10G with headroom concerns.
The other lesson: 1G is a trap for anyone doing sustained streaming. Per-bit cost is 4.7× worse than 10G. If a "cheap $80/mo box on 1G" is what fits your budget today, order the 10G box and pay $180/mo — you'll save the difference in support tickets alone.
Migration signals — when to move up
If you can answer YES to two of these three, you should already have ordered the next tier up:
- Peak utilisation > 70 % on 3+ nights per week for the last month
- Buffering complaints from subscribers on Fri/Sat/Sun evenings
- Missed a live event window in the last 90 days (subscribers dropped mid-stream)
Migration windows are also a factor. Moving a 100 TB VOD library and 30k active subscribers off a saturated 25G box takes 4–8 hours coordination. Doing it while port utilisation is at 92 % on a Friday is much harder than doing it on a Tuesday when you're at 40 %.
Order the bigger port when you have 25 % headroom left, not when you have 5 %.
Where operators live (scale table)
| Scale | Active lines / DAU | Port tier | Typical monthly cost |
|---|---|---|---|
| Starter reseller | < 500 lines | 1G shared | $50–90 |
| Growing reseller | 500 – 5,000 lines | Shared 10G / dedicated 10G | $150–250 |
| Established panel | 5,000 – 30,000 lines | Dedicated 10G / 25G | $180–450 |
| National-scale | 30,000 – 100,000 lines | Dedicated 25G / 2×25G LAG | $429–900 |
| Multi-national | 100,000 – 300,000 lines | Dedicated 100G | $1,290–2,500 |
| Live-event / super-PoP | 300,000+ concurrent | Dedicated 400G | $4,800+ |
The jump most operators fear — 10G → 25G — is actually the easiest one. Same PoPs, same racks, often the same box just with a different NIC and optics. Provisioning is 24–48h.
The jump they should fear — 25G → 100G — is where architecture changes. LACP configuration, new switch fabric, upstream BGP sessions if you're bringing your own AS. Plan 2–3 weeks lead time and coordinate with your NOC.
The DDoS layer nobody wants to include
Every calculation above assumes clean traffic. Real ports carry legitimate + attack traffic. If you're a target (and if you're at 25G+ scale, you are), you need port headroom for attack absorption OR upstream scrubbing.
Two real numbers from our customer base:
- Average DDoS traffic across our IPTV customer base in 2025: 3.2 Gbps ambient noise, weekly peaks 25–45 Gbps
- Worst incident absorbed in 2025: 847 Gbps SYN flood at a customer running on 100G — our upstream scrubbing fabric absorbed 812 Gbps, only 35 Gbps of attack reached their box, legit traffic unaffected
You don't buy port headroom for DDoS — you buy scrubbing capacity, because DDoS in 2025–26 is measured in hundreds of Gbps to Tbps, not in Gbps. But your port still needs headroom for the residual that gets through after scrubbing (typically 5–15 %).
What we sell — mapping to port tiers
Same as our other sizing posts — the math above maps directly to what we provision:
- 10G unmetered: from $180/mo on dedicated, 4-hour provisioning
- 25G unmetered: from $429/mo on dedicated, 4-hour provisioning
- 100G unmetered: from $1,290/mo on dedicated, 6-hour provisioning
- 400G unmetered: custom-quoted dedicated 400G, 24–72h provisioning
- All tiers include DDoS scrubbing, IPv4 + IPv6 dual-stack, BGP session on request
Every tier is truly unmetered — port speed IS the limit, no fair-use cap in the footer. If you want to bring your own AS number and announce your own prefixes, that's available on any tier from day one.
TL;DR
- Port need = peak_concurrent × bitrate × ABR × headroom. Add 1.4× minimum for a healthy panel, 1.8× if you don't want to migrate this year.
- 25G is the cheapest per-Gbps tier for most workloads. If you're between 8–20 Gbps, skip 10G and go straight to 25G.
- 100G is the right port when peak is 50–90 Gbps regularly. Not before.
- 400G is a super-PoP tool. If you're not sure you need it, you don't.
- Order the bigger port at 25 % headroom left, not 5 %. Migration under load is painful.
- DDoS traffic doesn't fit into port planning — it fits into scrubbing capacity. Buy both.
If your peak numbers don't fit cleanly into the table above, talk to engineering — we'll size the port with you in a single conversation.