vic115维多利亚·手机平台

Business Support

Technical Support

About Guangxun

About Ainopol

Employees’ Non-Work Internet Browsing: All-Optical Network Intelligent Traffic Control Precisely Governs Internet Behavior
2026-09-30 11:26:02 3

Employees’ Non-Work Internet Browsing: All-Optical Network Intelligent Traffic Control Precisely Governs Internet Behavior

“Our company subscribes to a 200M dedicated line, yet the OA system cannot be opened every afternoon. After troubleshooting, we found one-third of the bandwidth was occupied by employees scrolling short videos and playing online games.”

This is not an isolated case. The addictive content distribution algorithm of short video platforms keeps employees engaged far longer than expected once they open apps such as Douyin. Accumulating one hour of non-work entertainment daily equals nearly 250 working hours lost per year. For roles requiring deep concentration such as R&D and design staff, frequent switching between work and entertainment triggers the attention residue effect: after closing videos, the brain still needs several minutes to refocus.

Bandwidth congestion, reduced productivity and growing security risks — employees’ idle web browsing costs enterprises far more than just network speed.

I. Three Hazards of Employees’ Non-Work Internet Access

Occupying bandwidth for core business and hurting office efficiency
A single user streaming 1080P short videos consumes roughly 5–8 Mbps. Twenty employees watching videos simultaneously eat up 100–160 Mbps of egress bandwidth. When core office applications compete with entertainment traffic, OA responses slow down at best, and critical business sessions timeout or disconnect at worst. An IT director from a medium-sized internet company reported that nearly one-third of bandwidth was consumed by recreational traffic, making the OA system inaccessible during peak hours.

Hidden security risks
Game clients and video apps downloaded by staff come from untrusted sources. Unofficial installers may carry malicious code or ransomware. Some “free” applications secretly upload data in the background, creating data leakage risks. Entertainment platforms can also become attack entry points: attackers send phishing links via private messages on video platforms. Once clicked, trojans get implanted and later spread laterally across the corporate intranet.

Legal compliance liabilities
A manufacturing enterprise once faced legal troubles: an employee used the corporate network to access overseas gambling websites. Public security authorities traced the activity back to the company’s public IP. Although confirmed as individual misconduct, the enterprise spent massive resources assisting investigations, and the IT person-in-charge was held accountable. Employees accessing gambling, pornographic, phishing or pirated resource websites may expose the enterprise to joint legal liability, beyond bandwidth waste.

II. Why Traditional Control Methods Fail

Crude simple rate limiting on routers
Many enterprises restrict non-critical ports or block IP segments. However, modern platforms rely on CDN and P2P transmission with large, dynamically changing IP pools, making manual IP blocking extremely inefficient. One-size-fits-all speed limits often interfere with legitimate business access and lack time-based rules, banning reasonable leisure during lunch breaks and triggering employee resistance.

Multiple bypass methods available to technical employees
Tech-savvy staff can evade controls via mobile hotspots, encrypted VPN tunnels or web-based video platforms. Legacy network solutions have limited countermeasures.

Insufficient refined policy capabilities
Most entry-level enterprise routers offer coarse-grained control. They cannot implement combined policies by user, application, time window and bandwidth. Enterprises need flexible permissions for management staff and strict restrictions for regular employees — a requirement hard to satisfy with traditional tools.

III. How All-Optical Intelligent Traffic Control Achieves Precise Governance

AINOPOL all-optical network deeply embeds application management capabilities inside the all-optical gateway. The EAAS cloud O&M platform supports visualized policy configuration, forming a closed loop of identification, control, audit and optimization without extra dedicated hardware.

Precise identification: see who is using the network and what they access
Built-in DPI + AI deep inspection engine recognizes over 10,000 common applications with a 90% identification rate, covering short videos, online games, live streaming, video portals, instant messaging and social media. The detection engine can penetrate HTTPS encryption and dynamic ports to identify application signatures.

The solution also supports real-name authentication through DingTalk, Enterprise WeCom and SMS verification, binding user, device and account. Administrators can clearly view every user and application on the cloud platform.

Hierarchical control: shifting from blanket bans to individual policies
Administrators can limit or block games, video streaming, downloads, online shopping and stock trading. During working hours, full access block can be applied to categories such as all online games. For permitted-but-bandwidth-limited applications like video platforms, bandwidth caps protect core business traffic.

The URL filtering system contains more than 3,000 pre-classified URL entries covering dozens of categories including finance, e-commerce, entertainment and social media. Administrators can block or allow entire categories such as shopping or stock websites with one click. Whitelist mode for confidential and finance departments permits only pre-approved domains; blacklist mode allows all websites by default and blocks only prohibited categories.

Intelligent QoS automatically assigns high-priority queues for video conferences, OA and ERP systems, while short video and game traffic fall into low-priority queues. Entertainment bandwidth can be capped tightly during working hours. When office demand drops, unused bandwidth is released automatically and reclaimed instantly when business traffic rises. Entertainment applications can be fully blocked during core working hours and unlocked during lunch breaks.

Time-based control: differentiate lunch-break browsing and work-time learning
Full block of entertainment services during core working hours; access permission enabled during lunch break. Flexible rules for managers and strict controls for ordinary staff can be easily configured.

Dual-stack IPv4/IPv6 hard packet filtering firewall
It forms defense-in-depth together with URL filtering. The L3/L4 packet filter performs the first round of inspection based on IP and ports, while the L7 URL filtering engine delivers the second precise filtering. Even if a malicious website uses a new domain not added to the classification library, access can still be blocked at the IP layer if the IP is marked in threat intelligence.

Audit and traceability: full record of all online activities
All URL access behaviors are fully logged, including timestamp, user identity, target URL/domain, access result, blocking reason and traffic volume. Logs are automatically uploaded to the EAAS cloud platform and stored locally for up to 180 days, complying with the requirement of at least six months of log retention stipulated in Ministry of Public Security Order No.176. Every access event — who, when, which device, what website, blocked or allowed — can be traced, audited and exported.

Ministry of Public Security Order No.176 officially took effect on October 1, 2026. It explicitly lists “public internet service providers” as inspection targets, focusing on user registration information and internet log retention. Inspection methods now include online patrols and remote vulnerability scanning.

AINOPOL’s integrated communication-security solution natively embeds application control, behavior audit and log retention into the all-optical network architecture instead of adding them as external add-ons. The Mengxiang Gateway integrates routing, AC, firewall, audit, authentication and logging functions in one device. Traffic policies and compliance reports form a closed loop within the same hardware, eliminating the need for separate log servers or independent audit systems. Network deployment and compliance baseline completion happen simultaneously.

Employees’ idle web browsing may look like an HR management issue, yet fundamentally it is a network capability problem. Legacy networks lack the ability to judge who is online, what applications they run and whether access should be restricted, forcing IT teams to rely on crude bandwidth caps or manual checks. The all-optical network embeds intelligent traffic control deep into the network foundation: identifying every traffic stream, classifying applications, allocating bandwidth by user and time window, and recording every access event completely. The total bandwidth remains unchanged, but a much larger portion serves core business. Management rules stay the same, yet controls are backed by measurable data.

FAQ

Q: What types of applications can the all-optical network identify?
A: AINOPOL’s DPI + AI engine accurately identifies over 10,000 common applications at 90% accuracy, including short video platforms such as Douyin and Kuaishou, online games, video portals like Youku and iQiyi, live streaming platforms, instant messengers, social media and P2P downloads.

Q: Will legitimate office access be mistakenly blocked?
A: No. The solution supports both whitelist and blacklist modes. Whitelist mode for confidential roles only permits pre-audited domains. Blacklist mode allows all websites by default and intercepts only prohibited categories. Policies can be differentiated by department, user group and time window to guarantee normal office operations.

Q: Is storage sufficient for 180-day log retention?
A: The AINOPOL Mengxiang Gateway with attached hard disk supports local internet log storage. Logs are automatically synced to the EAAS cloud platform for centralized storage. Log fields fully record access time, user identity, target URL, access result, block reason and traffic volume to meet audit requirements of Ministry of Public Security Order No.176.