Skip to main content

Troubleshoot managed networks

Work through this sequence before replacing the complete ONC or resetting a device.

1. Protect access​

  • Keep Ethernet, a hotspot, or another known working network available.
  • Test in a pilot organisational unit.
  • Save the current ONC before editing.
  • Do not remove the last working path to Management Cloud.

2. Check scope and timing​

  1. Open Business+ → Network Configuration.
  2. Confirm the selected organisational unit.
  3. Check whether the value is inherited or locally applied.
  4. Confirm the affected user signs in under the expected scope.
  5. Remember that the console states restrictions apply after user login.
  6. Check the device's Last Policy Sync in its details page.

3. Validate the JSON​

Check:

  • Matching {}, [], and quotes.
  • No comments or trailing commas.
  • Unique and stable GUIDs.
  • Correct case for field names and enum values.
  • Required objects for the selected Type.
  • Certificate references defined in the same document.
  • Static IP address, gateway, prefix, and DNS values belong to the same design.

Use the formatter control as a first syntax check, then validate the document with an approved JSON validator that does not upload production secrets.

4. Diagnose by symptom​

SymptomChecks
Network is missingSSID/HexSSID, hidden SSID flag, organisational unit, policy sync
Prompts for a passwordSecurity, Passphrase, EAP Password, exact ${PASSWORD} substitution
802.1X rejects loginouter/inner EAP, identity expansion, RADIUS account, client/server certificate
Connected but no internetDHCP/static IP, gateway, DNS, captive portal, proxy
Internal sites failDNS search domain, VPN routes, proxy bypass list, CA trust
Works before restart onlyauto-connect, saved credentials, certificate availability, policy sync
VPN does not route trafficVPN type, host, included/excluded routes, DNS, firewall
Policy edit disconnects devicerestore the previous ONC using the fallback network

5. Check certificates​

  • Device time is correct.
  • Root and intermediate CAs are present.
  • Certificate validity and key usage match the connection.
  • Server name validation matches the RADIUS, VPN, or proxy host.
  • Client certificate selection finds the intended certificate.
  • Certificate and network policy apply to the same pilot scope.

6. Check proxy and DNS​

  • The PAC URL is reachable before the proxy is active.
  • Manual proxy host and port are reachable.
  • Bypass entries use the expected host/domain format.
  • TLS inspection presents a trusted CA.
  • System, browser, Android, and VM traffic are tested separately.
  • Policy and update endpoints remain reachable.

Roll back​

  1. Reconnect through the fallback network.
  2. Restore the last working complete JSON.
  3. Keep the device online until policy sync.
  4. Sign out or restart only when required.
  5. Confirm connectivity and Last Policy Sync.
  6. Document the failed change and reproduce it only in the pilot unit.

When escalating, provide the organisational unit, affected network type, FydeOS version, last policy sync, expected result, actual result, and a sanitised ONC that contains no credentials or private certificate data.

What's next​