Product capabilities
Designing ASN and ISP Filters with Network Context
ASN and ISP filters turn network attribution into policy, but their broad scope and changing ownership demand careful evidence.
Know which network field you are using
An ASN identifies the autonomous system announcing an address prefix, while an ISP or organization label is an interpreted name from a data provider. Normalize identifiers and retain the underlying number because display names can vary or change.
Resolve the actual visitor address safely
When an edge or proxy sits in front of the router, trust forwarding headers only from controlled infrastructure. Incorrect client-IP extraction makes every later ASN, geography, reputation, and frequency rule operate on the intermediary instead.
Prefer narrow campaign policy
Allow or restrict a network for a stated source, market, or operational requirement rather than imposing an unexplained global rule. Large cloud, carrier, education, and enterprise systems contain mixed users whose behavior cannot be inferred from ownership alone.
Define precedence for network exceptions
Document how an allowlisted partner ASN interacts with an address denylist, proxy signal, country requirement, or ML score. Expose the winning rule in event reasons so operators can diagnose a result without guessing about evaluation order.
Maintain network rules as perishable data
Attach evidence, owner, creation date, and review date to manual entries. Recheck prefix attribution and observed impact periodically, then remove exceptions whose network assignment or business purpose has changed.