Browsing security as an ISP service
The subscriber's access point decides what goes through, by DNS, TLS/SNI and HTTP. Your team applies the policy across the whole fleet from the dashboard, with no new appliance in the traffic path.
No commitment. The technical team answers.
What already lands on an ISP's desk
Blocking orders in volume
In 2026, through September, Brazil's Ministry of Finance ordered 57,691 illegal betting addresses to be blocked. In September alone there were 10,590. The provider is the one that carries out the block.
Source: Estado de Minas, 25/09/2026
DNS blocking has a known limit
At a hearing in the Chamber of Deputies, Anatel pointed to VPNs, domain changes and the number of providers as limits of the blocking done today.
Source: Telesíntese, December 2025
Access alone does not sustain the margin
Abrint points to services such as managed Wi-Fi and network security as the next revenue layer for regional ISPs.
Source: Telesíntese, August 2026
What changes in the ISP's operation
The decision moves down to the access point and management moves up to the dashboard. The rest of your network stays as it is.
Policy applied on the AP
The DNS query, the SNI of the TLS handshake and HTTP are read on the access point itself. Whatever matches the policy is dropped there, before it uses the link.
Bypass blocked
NetExperience documents the blocking of encrypted DNS and bypass VPNs, which are the most common ways around DNS-only filtering.
Managed Wi-Fi as a service
Policy per customer and per SSID, an ISP portal to manage all customers, and a separate portal for each customer to follow their own network.
Events and crowded venues, with the radio profile sized in the project
Radio profiles, automatic channel management and profile-based deployment, to set up and tear down a network quickly.
The whole fleet in one dashboard
Inventory, alarms, firmware, metrics and licenses for every access point in the same place.
Diagram of the path of a request. The dashboard defines the policy and receives the events; the decision happens on the access point.
Questions for this segment
Does this replace the DNS blocking we do today?
It complements it. DNS filtering is still useful, but it stops working when the device uses another resolver or encrypted DNS. On the access point, the decision also uses the destination declared in the TLS handshake.
Can I sell it as a service to my subscribers?
Yes. The policy is defined per customer and per SSID, and each customer can have access to their own portal. Pricing and how the service is framed are up to the ISP.
What about the log retention rules of the Marco Civil?
Article 14 of Brazil's Marco Civil da Internet forbids connection providers from keeping application access logs. The gateway's activity report is optional per profile. When off, the blocks keep working and browsing is not logged. The configuration for your case is defined in the project.
Which equipment goes into the project?
Certified Edgecore access points, supplied by Padtec. Today they are the EAP101, EAP102 and EAP105, for indoor use with Wi-Fi 6 and Wi-Fi 7, and the OAP101, for outdoor use.
Start with the technical assessment.
Tell us how many points you need to cover and what the scenario is. We return the sizing and a sample of what would be blocked at the edge.
Browsing security as an ISP service
The subscriber's access point decides what goes through, by DNS, TLS/SNI and HTTP. Your team applies the policy across the whole fleet from the dashboard, with no new appliance in the traffic path.
No commitment. The technical team answers.
What already lands on an ISP's desk
Blocking orders in volume
In 2026, through September, Brazil's Ministry of Finance ordered 57,691 illegal betting addresses to be blocked. In September alone there were 10,590. The provider is the one that carries out the block.
Source: Estado de Minas, 25/09/2026
DNS blocking has a known limit
At a hearing in the Chamber of Deputies, Anatel pointed to VPNs, domain changes and the number of providers as limits of the blocking done today.
Source: Telesíntese, December 2025
Access alone does not sustain the margin
Abrint points to services such as managed Wi-Fi and network security as the next revenue layer for regional ISPs.
Source: Telesíntese, August 2026
What changes in the ISP's operation
The decision moves down to the access point and management moves up to the dashboard. The rest of your network stays as it is.
Policy applied on the AP
The DNS query, the SNI of the TLS handshake and HTTP are read on the access point itself. Whatever matches the policy is dropped there, before it uses the link.
Bypass blocked
NetExperience documents the blocking of encrypted DNS and bypass VPNs, which are the most common ways around DNS-only filtering.
Managed Wi-Fi as a service
Policy per customer and per SSID, an ISP portal to manage all customers, and a separate portal for each customer to follow their own network.
Events and crowded venues, with the radio profile sized in the project
Radio profiles, automatic channel management and profile-based deployment, to set up and tear down a network quickly.
The whole fleet in one dashboard
Inventory, alarms, firmware, metrics and licenses for every access point in the same place.
Diagram of the path of a request. The dashboard defines the policy and receives the events; the decision happens on the access point.
Questions for this segment
Does this replace the DNS blocking we do today?
It complements it. DNS filtering is still useful, but it stops working when the device uses another resolver or encrypted DNS. On the access point, the decision also uses the destination declared in the TLS handshake.
Can I sell it as a service to my subscribers?
Yes. The policy is defined per customer and per SSID, and each customer can have access to their own portal. Pricing and how the service is framed are up to the ISP.
What about the log retention rules of the Marco Civil?
Article 14 of Brazil's Marco Civil da Internet forbids connection providers from keeping application access logs. The gateway's activity report is optional per profile. When off, the blocks keep working and browsing is not logged. The configuration for your case is defined in the project.
Which equipment goes into the project?
Certified Edgecore access points, supplied by Padtec. Today they are the EAP101, EAP102 and EAP105, for indoor use with Wi-Fi 6 and Wi-Fi 7, and the OAP101, for outdoor use.
Start with the technical assessment.
Tell us how many points you need to cover and what the scenario is. We return the sizing and a sample of what would be blocked at the edge.