Configuration wizard – company network
- Last Updated: September 16, 2026
- 3 minute read
- Flowmon Products
- Flowmon Anomaly Detection System
- Documentation
After you select the company network template, the wizard guides you through all the necessary initial settings. The system uses these values for relevant detection method parameters. Follow the wizard's instructions to help configure the system correctly and improve anomaly detection accuracy. If you have an existing configuration, review the Configuration impact section of each step to understand how applying that step will affect your current configuration.
Initial configuration
Click Start to begin the configuration by selecting your company's approximate size. You will then need to enter the following information:
- IP addresses of your LAN (in addition to the automatically added private IP ranges)
- Public IP ranges
- IP addresses of local servers
- Specific IP addresses of SMTP, DNS, DHCP, NTP, and proxy servers
You can enter individual IP addresses or ranges using the notation described in the user guide in the Filters section (for example, 10.0.0.0/24, 10.0.0.[1-10], 172.16.*.1, 192.168.{1,3,20}.1).
Server configuration
When entering local servers, add the IP addresses for all servers in your network, including:
- DHCP, DNS, SMTP, and NTP servers
- Monitoring systems such as Zabbix
- Database servers
- Proxy servers
- Other server types
The wizard will prompt you to define specific server types in subsequent steps.
When entering specific server IP addresses (SMTP, DNS, proxy, DHCP, or NTP), include addresses of servers that users can access (for example, public DNS servers like 8.8.8.8 if your company policy allows their use).
Network size configuration
When entering the approximate number of hosts, include all end devices in your network (computers, printers, and other network-connected devices). Flowmon ADS uses this number to set threshold values for detection methods.
External services configuration
External services include updates for blacklists and behavior patterns used to detect malicious network communications and anomalies. These services also include public information lookup services, such as WHOIS, IPVoid, and others. Select Yes if your system has Internet access.
Completing the configuration
Flowmon ADS is now configured. The system has loaded the data you entered into the appropriate filters and event detection methods. Click Exit Wizard to complete the configuration wizard. The next step is to configure data feeds.