Seatext library / BotRefund evidence

How to Set Up BotRefund for a Company with Multiple Offices and VPNs

You can set up BotRefund for a company with multiple offices and VPNs by creating separate allowlists for each office's IP ranges and configuring the system to handle traffic from each VPN endpoint appropriately....

Built for advertisers who need clear, refund-ready traffic evidence.

Setting up BotRefund for a company with multiple offices and VPNs involves mapping IP ranges, creating allowlists, and configuring detection settings to account for varied traffic sources. This process helps protect ad budgets from bot clicks while ensuring that genuine employees from different locations are not mistakenly flagged.

BotRefund uses behavioral and device fingerprinting to identify bots, but corporate networks and VPNs can produce unusual signals. By configuring the system per office, you maintain accuracy and prevent false positives.

Why Multi-Office Setup Matters for Bot Detection

When a company has offices in different locations, each may use distinct IP ranges or VPN endpoints. Without proper configuration, BotRefund might misclassify traffic from these sources as bot activity. This could block legitimate employees or partners, harming internal workflows and ad campaign performance.

A multi-office setup ensures that BotRefund distinguishes between human users on corporate networks and actual bots. It protects your ad spend by accurately filtering invalid traffic, which is critical since bot clicks can steal up to 20% of Google and Meta ad budgets.

Prerequisites Before You Start

Before configuring BotRefund, gather the following information to streamline the process:

  • Office IP Ranges: List all static IP addresses or CIDR ranges for each office. This includes both public IPs and those used for VPN gateways.
  • VPN Endpoints: Identify the IP addresses or ranges assigned to VPN users connecting to your network. These may change, so note any dynamic patterns.
  • BotRefund Account Access: Ensure you have admin privileges to the BotRefund dashboard to modify settings and create allowlists.
  • Traffic Baseline: Understand typical traffic volumes from each location to help with verification later.

Step 1: Map Office IP Ranges and VPN Endpoints

Start by documenting all IP ranges for your offices. Contact your IT team to obtain this data, as it often resides in network configuration logs. For VPNs, check the settings of your VPN provider or internal server to list assigned IP pools.

Create a spreadsheet with columns for location name, IP range, and VPN status. This will serve as a reference when building allowlists. For example:

  • New York Office: 192.168.1.0/24 (static) and VPN range 10.0.0.0/16
  • London Office: 172.16.0.0/24 (static) and VPN range 10.1.0.0/16

Keep this data updated, especially if VPN endpoints change frequently.

Step 2: Create Custom Allowlists in BotRefund

Log in to your BotRefund dashboard and navigate to the allowlist section. Here, you can create separate lists for each office or VPN group.

  1. Click on "Allowlists" or "IP Management" in the menu.
  2. Create a new allowlist for each office, naming it clearly (e.g., "Office-NY" or "VPN-London").
  3. Add the corresponding IP ranges to each allowlist. Use CIDR notation for ranges (e.g., 192.168.1.0/24).
  4. For VPNs, consider creating a dedicated allowlist to handle dynamic IPs if they fall within known ranges.

BotRefund processes these allowlists to exempt traffic from bot detection. This step ensures that legitimate corporate traffic is not flagged as invalid.

Step 3: Configure Detection Settings per Location

BotRefund allows you to adjust detection sensitivity or rules based on allowlists. For multi-office setups:

  • Review Default Settings: BotRefund uses 106 independent checks, including behavioral analysis like mouse movement and session duration. Ensure these align with your office traffic patterns.
  • Set Exceptions: In the dashboard, link each allowlist to specific detection rules. For example, you might relax behavioral checks for VPN traffic if employees use automated tools.
  • Enable Cross-Checking: BotRefund cross-references signals to avoid false positives. Verify that this feature is active, as it helps handle anomalies from corporate networks.

If certain offices use privacy tools or unusual devices, adjust settings to accommodate them without compromising security.

Step 4: Test and Verify Traffic from Each Office

After configuration, test the setup by simulating traffic from each office and VPN endpoint:

  1. Have team members from different locations access your website or ad landing pages.
  2. Check the BotRefund dashboard for flagged sessions. Look for any false positives where employee traffic is marked as bot activity.
  3. Use the audit logs to review individual signals. BotRefund provides evidence like device fingerprints and behavior metrics.
  4. If issues arise, refine the allowlists or adjust detection rules as needed.

This verification step ensures that the configuration works in practice before full deployment.

Step 5: Ongoing Monitoring and Adjustments

Bot detection is not a one-time setup. Monitor traffic regularly to adapt to changes:

  • Review Reports Weekly: Use BotRefund's analytics to track bot detection rates and false positives per location.
  • Update IP Ranges: As offices expand or VPN policies change, update allowlists promptly to maintain accuracy.
  • Coordinate with IT: Stay in touch with your IT team to receive updates on network changes that affect traffic patterns.

Continuous monitoring helps you optimize settings and protect your ad spend effectively.

Common Mistakes and How to Avoid Them

When setting up BotRefund for multiple offices, avoid these pitfalls:

  • Incomplete IP Mapping: Missing IP ranges can lead to legitimate traffic being blocked. Double-check all office and VPN addresses with your IT department.
  • Overlooking VPN Changes: VPN endpoints may shift, so implement a process to update allowlists regularly. Consider using dynamic IP ranges if your VPN provider supports it.
  • Ignoring Behavioral Signals: Corporate networks might trigger behavioral checks due to automated tools. Adjust detection rules to accommodate this without disabling protection entirely.

By addressing these issues upfront, you ensure a smooth setup and reliable bot protection.

Limitations and When to Seek Help

BotRefund's multi-office setup has some limitations:

  • IP-Based Allowlists: If employees use personal devices or non-standard VPNs outside known ranges, they may still be flagged. In such cases, consider additional verification methods.
  • Complex Networks: Large companies with intricate network architectures might require custom configurations. BotRefund offers enterprise support for these scenarios.
  • Real-Time Changes: Dynamic VPN IPs can be challenging to track. Use monitoring tools to detect anomalies and update allowlists proactively.

If your setup becomes too complex, reach out to BotRefund's enterprise sales team for tailored assistance.

Key Facts About BotRefund Setup

Table: BotRefund Configuration Overview

FeatureDescriptionRelevance to Multi-Office Setup
Number of Checks106 independent signals for bot detectionEnsures comprehensive analysis across offices
Accuracy99% accurate due to AI cross-checkingReduces false positives from VPN traffic
Setup TimeAbout one minute for basic installationQuick to deploy, but configuration takes longer for multiple offices
AllowlistsCustom IP range lists to exempt trafficEssential for office and VPN management
Evidence-BasedProvides video proof and logs for each bot clickHelps verify detections during testing

Frequently Asked Questions

How do I handle IP ranges that change frequently, such as for remote employees?

For dynamic IPs, consider using VPN endpoints with fixed ranges or configure BotRefund to use behavioral analysis more heavily. Update allowlists regularly by coordinating with your IT team to track changes.

Can I set different detection rules for each office?

Yes, BotRefund allows you to link specific allowlists to detection settings. Create separate rules for offices with unique traffic patterns, such as those using automated tools.

What if legitimate traffic from an office is still being flagged?

Review the session logs in BotRefund to identify which signals are triggering the detection. Adjust the allowlists or fine-tune behavioral checks to accommodate office traffic.

How does BotRefund differentiate between bots on corporate networks and real employees?

BotRefund cross-checks multiple signals, including browser fingerprints, mouse movements, and session behavior. For corporate networks, it looks for anomalies but requires accurate allowlists to avoid false positives.

Is there a cost associated with configuring multiple offices?

The basic setup is free, but advanced configurations may require an enterprise plan. Contact BotRefund's sales team for pricing details based on your ad spend and needs.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

How BotRefund Can Help with Multi-Office Setups

BotRefund uses over 100 independent checks, including behavioral and device fingerprinting, to detect bots with 99% accuracy by cross-referencing signals. For companies with multiple offices and VPNs, this cross-checking helps avoid false positives from corporate networks. However, accurate IP range data is required for each office to configure allowlists properly, ensuring legitimate traffic is not blocked.
Get a free bot audit