Configuration wizard – Internet Service Provider
- Last Updated: September 16, 2026
- 2 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
After you select the Internet Service Provider template, the wizard guides you through all the necessary initial settings. The system uses these values for relevant detection method parameters. Follow the wizard's instructions to help configure the system correctly and improve anomaly detection accuracy.
Initial configuration
Click Start to begin configuration and apply the template for an Internet Service Provider environment.
Customer segment configuration
After the system applies the template, enter customer segments (IP ranges/subnets or IP addresses). You can enter individual IP addresses or ranges using the notation described in the user guide in chapter 2.3.11 Filters (for example, 10.0.0.0/24, 10.0.0.[1-10], 172.16.*.1, or 192.168.{1,3,20}.1).
You can edit the list of segments at any time using either:
- The configuration wizard
- The ADS configuration section directly (Settings > Processing > Filters)
Internal IP configuration
After you enter all segments, define the internal IP ranges/subnets or IP addresses by selecting displayed filters (named groups of IP ranges). If any IP ranges are missing, add them using:
- The previous wizard step
- The ADS configuration section (Settings > Processing > Filters)
External services configuration
Enable external services to update:
- Blacklists
- Behavior patterns used to detect malicious network communications and anomalies
- Access to public lookup services for additional information (such as WHOIS, IPVoid, and others)
Select Yes if your system has Internet access.
Completing the configuration
Flowmon ADS is now configured. The system has loaded all your entered data into filters and event detection methods. Click Exit Wizard to finish the configuration wizard. Your next step is to configure data feeds.