Skip to main content

Configure Ethernet, VPN, and proxy

ONC uses the same NetworkConfigurations array for Ethernet, VPN, and per-network proxy settings. Add only fields supported by the selected network type and test with a pilot organisational unit.

Ethernet with DHCP​

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{ethernet-company-dhcp}",
"Name": "Company Ethernet",
"Type": "Ethernet",
"IPAddressConfigType": "DHCP",
"NameServersConfigType": "DHCP",
"Ethernet": {
"Authentication": "None"
}
}
]
}

For 802.1X Ethernet, set Authentication to 8021X and add an EAP object using the same identity and certificate planning used for enterprise Wi-Fi.

Static IP​

Use static addressing only when the network owner has reserved the address.

{
"Type": "UnencryptedConfiguration",
"NetworkConfigurations": [
{
"GUID": "{ethernet-company-static}",
"Name": "Company Ethernet Static",
"Type": "Ethernet",
"IPAddressConfigType": "Static",
"NameServersConfigType": "Static",
"StaticIPConfig": {
"Type": "IPv4",
"IPAddress": "192.0.2.20",
"RoutingPrefix": 24,
"Gateway": "192.0.2.1",
"NameServers": [
"192.0.2.53",
"198.51.100.53"
],
"SearchDomains": [
"corp.example"
]
},
"Ethernet": {
"Authentication": "None"
}
}
]
}

The addresses above are documentation examples. Replace every address and domain. For IPv4, RoutingPrefix must be from 1 to 32.

VPN planning​

Set the network Type to VPN, then choose the matching VPN.Type. The ONC reference includes:

  • IPsec
  • L2TP-IPsec
  • OpenVPN
  • WireGuard
  • ThirdPartyVPN

Collect the server host, authentication method, username format, certificate requirements, routes, and auto-connect decision. VPN fields vary considerably; build the object from the matching section in the ONC reference rather than adapting an unrelated VPN example.

For username fields that support expansion, use ${LOGIN_EMAIL} or ${LOGIN_ID}. ${PASSWORD} substitution is documented for VPN.L2TP.Password only and must be the entire field value.

Direct proxy​

Each example below is a valid JSON object containing the ProxySettings property. Merge that property into the relevant Wi-Fi, Ethernet, or VPN NetworkConfiguration object; the example is not a complete ONC document.

{
"ProxySettings": {
"Type": "Direct"
}
}

Manual proxy​

{
"ProxySettings": {
"Type": "Manual",
"Manual": {
"HTTPProxy": {
"Host": "proxy.example",
"Port": 8080
},
"SecureHTTPProxy": {
"Host": "proxy.example",
"Port": 8080
}
},
"ExcludeDomains": [
"localhost",
"*.corp.example",
"192.0.2.0/24"
]
}
}

PAC and WPAD​

{
"ProxySettings": {
"Type": "PAC",
"PAC": "https://proxy.example/proxy.pac"
}
}

For Web Proxy Auto-Discovery, use:

{
"ProxySettings": {
"Type": "WPAD"
}
}

Test PAC availability without the proxy, failover behaviour, HTTPS inspection, certificate trust, and access to update and management services. Authenticated proxy behaviour can differ between browser, system, Android, and virtual machine traffic.

Verify​

  1. Connect a pilot device after sign-in.
  2. Check the assigned address, gateway, DNS servers, and search domains.
  3. Confirm internal and public name resolution.
  4. For VPN, test included and excluded routes and reconnect after restart.
  5. For proxy, confirm the public egress path and bypass rules.
  6. Test FydeOS policy sync and updates through the configured path.
  7. Restore the previous ONC if management connectivity is affected.

What's next​