Troubleshoot managed networks
Work through this sequence before replacing the complete ONC or resetting a device.
1. Protect access
- Keep Ethernet, a hotspot, or another known working network available.
- Test in a pilot organisational unit.
- Save the current ONC before editing.
- Do not remove the last working path to Management Cloud.
2. Check scope and timing
- Open Business+ → Network Configuration.
- Confirm the selected organisational unit.
- Check whether the value is inherited or locally applied.
- Confirm the affected user signs in under the expected scope.
- Remember that the console states restrictions apply after user login.
- Check the device's Last Policy Sync in its details page.
3. Validate the JSON
Check:
- Matching
{},[], and quotes. - No comments or trailing commas.
- Unique and stable GUIDs.
- Correct case for field names and enum values.
- Required objects for the selected
Type. - Certificate references defined in the same document.
- Static IP address, gateway, prefix, and DNS values belong to the same design.
Use the formatter control as a first syntax check, then validate the document with an approved JSON validator that does not upload production secrets.
4. Diagnose by symptom
| Symptom | Checks |
|---|---|
| Network is missing | SSID/HexSSID, hidden SSID flag, organisational unit, policy sync |
| Prompts for a password | Security, Passphrase, EAP Password, exact ${PASSWORD} substitution |
| 802.1X rejects login | outer/inner EAP, identity expansion, RADIUS account, client/server certificate |
| Connected but no internet | DHCP/static IP, gateway, DNS, captive portal, proxy |
| Internal sites fail | DNS search domain, VPN routes, proxy bypass list, CA trust |
| Works before restart only | auto-connect, saved credentials, certificate availability, policy sync |
| VPN does not route traffic | VPN type, host, included/excluded routes, DNS, firewall |
| Policy edit disconnects device | restore the previous ONC using the fallback network |
5. Check certificates
- Device time is correct.
- Root and intermediate CAs are present.
- Certificate validity and key usage match the connection.
- Server name validation matches the RADIUS, VPN, or proxy host.
- Client certificate selection finds the intended certificate.
- Certificate and network policy apply to the same pilot scope.
6. Check proxy and DNS
- The PAC URL is reachable before the proxy is active.
- Manual proxy host and port are reachable.
- Bypass entries use the expected host/domain format.
- TLS inspection presents a trusted CA.
- System, browser, Android, and VM traffic are tested separately.
- Policy and update endpoints remain reachable.
Roll back
- Reconnect through the fallback network.
- Restore the last working complete JSON.
- Keep the device online until policy sync.
- Sign out or restart only when required.
- Confirm connectivity and Last Policy Sync.
- Document the failed change and reproduce it only in the pilot unit.
When escalating, provide the organisational unit, affected network type, FydeOS version, last policy sync, expected result, actual result, and a sanitised ONC that contains no credentials or private certificate data.
What's next
- Configure network policies, validate and publish ONC safely.
- Manage certificates, prepare trust anchors and client certificates.
- ONC reference, look up schema fields and accepted values.