If you spend your day jumping between the WiFi from home, the office, the university or your mobile phoneManually changing IP, DNS, VPN, and other settings is a pain and a source of errors. The good news is that today you can make your laptop, mobile phone, or even your corporate network automatically manage your IP address, DNS, VPN, and other settings. They automatically adapt their settings according to the WiFi network you connect to., applying the appropriate level of security, firewall or VPN at any given time.
All of this revolves around the network and WiFi profilesThese are preconfigured parameter sets that are activated based on the SSID, network type, or location. From basic Windows options to tools like NetSetMan, Easy Net Switch, or centralized management with Microsoft Intune, as well as firewall profiles and routers with IPsec, there are many ways to ensure your computer is "fitted" for each network without you having to do anything.
What is a network profile and why is it worth using?
A network profile is a set of settings that are automatically applied to a connection or to a group of connections when certain conditions are met: connecting to a specific SSID, using a particular interface, moving to a location, etc. These settings include IP (static or DHCP), DNS servers, routes, firewall behavior, VPN usage, printers, shared folders, or even custom scripts.
In Windows, the foundation of everything is user profiles. public network and private networkThe first time you connect to a Wi-Fi or LAN network, the system asks if it's a trusted network. If you answer yes, it's marked as private; if you say no, or if it's an open network, it's treated as public and stricter restrictions are applied.
On a network marked as privateWindows operates on the premise that you control who connects and that LAN devices are trusted. This allows share files, printers, multimedia, discover other devices and use features like streaming to a Smart TV or workgroups. The firewall opens more internal services because the environment is considered relatively secure.
When you indicate that the network is actThe system assumes the opposite: that you don't control who connects, as in the Wi-Fi of a bar, airport, or public square. In this case, Windows It blocks device detection, file sharing, and printer sharing. and other services that could expose you to attacks on the same network. You can continue browsing, but your computer is much more isolated from other devices. This is the recommended option for open networks which can be a magnet for attackers.
The problem arises when you use the same laptop to move around several networks with completely different requirementsIn one situation you need a static IP address, in another you use DHCP, at work you need a proxy and VPN, at home you don't, in an industrial network there are very specific firewall rules, etc. Manually adjusting each setting every time is impractical and very easy to break, so these other solutions come into play. Advanced profiles that change everything at once depending on the network to which you connect.
Network profiles in Windows: public, private, and basic management
By default, every time Windows detects a new network, it asks if you want to other devices on that network can find your deviceThat simple question determines whether the profile is marked as public or private, and based on that, the main firewall rules and resource sharing are configured.
If you choose that the network is from private trustThe system assumes an environment similar to your home or a small office where you know all the users. You'll find it easier to View shared printers, use network folders, discover NAS devices, or send content to a Smart TVIt's the logical choice when you know who controls the router and connected devices.
If you mark the network as actYou're telling Windows that any type of device can be connected and that you don't trust them. In that case, it It disables the visibility of the device, file sharing, and printer sharing. and firewall rules are tightened. This is the recommended option for WiFi in hotels, cafes, airports, or open networks that can be a magnet for attackers.
On laptops that frequently switch between multiple networks, this difference is crucial: a single device can have multiple network profiles that are selected according to the network used And on top of these, you can add more advanced layers (VPN, scripts, IP changes, etc.) with specific tools that we will see later.
Automate the setup when changing WiFi networks
Windows allows a certain degree of customization per profile (public/private) and per connection, but It is not designed to change IP, DNS, proxy, VPN and firewall all at once. each time you connect to a different SSID. To achieve this level of automation, the system's built-in features are usually supplemented with specialized software or centralized management in corporate environments.
In some systems, especially in Solaris-type environments, a distinction is made between reactive and fixed network profilesA reactive profile is usually called “Automatic” and its typical logic is: it first attempts to establish a wired connection and, if that fails, it falls back to a wireless interface. A fixed profile, often called “DefaultFixed,” defines a set of static interfaces and configurations that do not change automatically unless modified using command-line tools.
These profiles control what interfaces can be activated or deactivated at any timeOn a laptop with Ethernet and WiFi, for example, you might want the system to always use the cable when available and turn off WiFi for security, or just the opposite in an environment where the cable is unreliable.
In those types of systems there is a dialog box for Network preferences It offers several views: one displays the current status of connections, another the list of available network profiles, and another the properties of each connection (IPv4/IPv6 addresses, favorite wireless networks, etc.). From there, you can see which profile is active, which interfaces belong to each profile, and adjust the detailed settings.
In addition to the profiles, in some environments work is done network locations These settings group name service configurations (DNS, LDAP, etc.) and security policies (IP firewall, IPsec). Each location can be activated manually or according to rules (for example, use an "Office" location if you get an IP address within a certain range, and a "Home" location if the IP address is from your home network). There can only be one active location at a timeand changing location involves applying a different set of policies.
Programs to create automatic profiles based on the WiFi network
When you want to go beyond what Windows offers by default, there are several utilities that allow you to Create complete network profiles that apply when changing SSIDs or by detecting a specific adapter. Many of them are compatible from Windows XP to Windows 11 and include everything from simple IP changes to very advanced automation.
Easy Net Switch
Easy Net Switch is a paid tool for Windows that boasts a huge number of network configuration optionsIts interface is quite reminiscent of Windows XP, but it works well with virtually all modern versions: from XP to Windows 11, and offers both a graphical interface and a command-line mode for advanced users.
With Easy Net Switch you can define profiles that control virtually anything you can think of: IP address, subnet mask, gateway, DNS, WINS, NetBIOS, MAC address spoofing, WiFi, VPN, proxy, firewall, default printer, network drives, static routesScript execution, hosts file modification, and more. Each parameter is optional, so you can set up anything from a minimalist profile to a highly detailed enterprise configuration.
Profile creation is done with a wizard accessible from the “New” button, and then you can Refine each section to your likingIn the “Network” tab, you choose whether the IP address and DNS are obtained via DHCP or defined statically. In the “Advanced” section, you can configure WINS, NetBIOS, change the network card's physical MAC address, clear the DNS cache, and other technical settings. When you apply the profile, the program displays a Summary of changes and notification of any errors that has occurred.
In the wireless realm, Easy Net Switch allows you to create WiFi profiles linked to specific SSIDsYou can scan for nearby networks or manually enter the name, and configure both the pre-shared key (PSK) and advanced authentication with RADIUS and EAP protocols. This way, when you detect the corporate SSID, the program automatically prepares the appropriate authentication, keys, and, if necessary, activates the associated VPN.
Furthermore, it easily manages the settings of Corporate proxy, dial-up connections, VPN It also includes integrated diagnostic tools like ping and traceroute. It even features a desktop widget to view the current IP address. Among its global options, you can configure it to... Run at Windows startup, minimize to the system trayDisable WiFi auto-detection or protect access with a password so that no one can change profiles without permission.
TCP/IP Manager
TCP/IP Manager is an application free and open source Although it hasn't been updated in a while, it still works flawlessly on recent versions of Windows. It's designed to create unlimited network profiles that allow for quick switching between them. IP configuration, subnet mask, gateway, DNS, proxy, workgroup name, and MAC address of the card.
One of its advantages is that it can import the current system configuration To create a profile based on what you already have, you don't have to manually enter each parameter. Instead, you start with what's working and save it as a profile. You can also associate batch files (BAT) with each profile so that, when activated, additional commands are executed, such as mounting network drives or launching your VPN client.
Switching between profiles can be done from the interface itself or via keyboard shortcutsThis is very convenient if you frequently switch between different networks (office, lab, home, client, etc.). The program includes a web-based update system, so when a new version is released, it downloads automatically without you having to search for it.
IP Shifter
IP Shifter falls into the category of lightweight tools: it Free, simple and compatible from Windows XP to Windows 11It is designed for users who only need to change a few things, but do so quickly and without restarting.
Its main function is to allow you Toggle IP, subnet mask, gateway, and DNS settings of network adapters without restarting the system. It supports multiple adapters (Ethernet and WiFi) and can manage proxy settings for browsers like Edge or Firefox. Additionally, it integrates a basic ping command and is capable of detect devices on the LAN and display the public IP address of your connection.
It doesn't have as much depth as Easy Net Switch or NetSetMan, but for switch between two or three simple scenarios (for example, a static IP address on a work network and DHCP at home) is usually more than enough.
NetSetMan and automatic profile switching (AutoSwitch)
NetSetMan is probably the most powerful free option if you're looking for something similar to Easy Net Switch. The free version allows up to eight complete network profilesThe paid Pro edition removes that limit and adds enterprise features. The idea is that you can activate a whole set of settings with a single click.
Among the things that can be configured in each profile are the IP addresses, subnet mask, gateway, DNS, workgroup, default printer, network drives, routing table, SMTP server, PC name, MAC address, network card status and speed, MTU, VLAN And much more. You can also configure VPN servers, launch BAT, VBS, or JS scripts when switching profiles, run other programs, and manage WiFi parameters in detail.
The Pro version adds, among other things, advanced proxy and network domain configurationsThese are designed to integrate with corporate domain environments. However, the free edition cannot be used on Windows Server and limits the number of profiles to eight, something to keep in mind if you manage many locations.
One of the most interesting features of NetSetMan is AutoSwitchwhich allows you to automatically activate profiles based on custom conditions. You can configure, for example, that a profile is activated when detect a specific SSID, a gateway IP, a local IP range or certain network characteristics. You can specify whether all conditions must be met or if only one needs to be met. Profiles are evaluated in order of priority, so those at the top are applied first if their conditions match; this way you can ensure you use the better wireless connection available.
Profiles are evaluated in order of priority, so those at the top are applied first if their conditions match. NetSetMan includes a AutoSwitch panel that uses colors to show which conditions are activeGreen indicates the requirements are met, red indicates they are not, and gray indicates that the status no longer matters because a higher priority profile has been activated. You can also adjust how automatic activation is displayed (countdown window, native Windows notification, or full background activation).
To save resources, NetSetMan doesn't continuously check if you've manually changed anything in the network settings, so if you modify a setting manually, the program won't update it. It doesn't detect it until you reactivate a profile. or change the AutoSwitch conditions.
WiFi profiles and centralized management with Microsoft Intune
In organizations with many devices, it doesn't make sense for each user to have a device for every user. manually configure the corporate WiFi network on your laptop or mobile device. It's very easy to make mistakes, especially on networks with advanced authentication, certificates, and specific policies. To address this, Microsoft Intune allows you to create centralize WiFi profiles and distribute them across multiple platforms.
An Intune WiFi profile is a configuration package that includes SSID, security type, authentication method, keys or certificates and other parameters specific to the wireless network. This profile is assigned to groups of users or devices, and once the devices are synchronized with Intune, the network appears as known and can be connected automatically without user intervention.
To create one of these profiles, you access the Microsoft Intune Admin CenterYou go to the Devices section and create a new configuration policy. You specify the platform (Android, Android Enterprise, Android AOSP, iOS/iPadOS, macOS, Windows 10/11, Windows 8.1, Windows Holographic for Business, etc.) and select the corresponding WiFi profile type or template.
Then you assign a Descriptive name for the profile and, optionally, a description that helps identify it (for example, “Main corporate WiFi”). Next, you define the platform's own parameters: network name, security (WPA2, WPA3, EAP-TLS, etc.), certificate usage, authentication, whether the network is hidden, automatic connection behavior, and other advanced settings.
Intune allows you to filter the application of these profiles by scope labelsThese are very useful for distributing management among different IT teams (for example, one team for each country or region). Finally, you assign the profile to the appropriate user or device groups, and when they synchronize, the devices receive the Wi-Fi configuration ready to connect.
Custom WiFi profiles with PSK and XML using Intune
In addition to standard interface profiles, Intune supports the creation of WiFi profiles based on pre-shared key (PSK) or EAP using custom directives and the WiFi Configuration Service Providers (CSPs) of each operating system. In this case, an XML file describing the wireless profile is sent via a specific OMA-URI path.
PSK networks are very common in domestic environments, small offices, or guest networksWith Intune you can create a "Custom" device configuration policy that contains the complete XML profile and delivers it to the operating system via the appropriate OMA-URI path, both on Android (including Enterprise and Work profile modes) and on Windows.
For it to work, you need to prepare an XML file with all the details: Profile name, SSID (in text and hexadecimal), authentication type, encryption type, key, connection mode (automatic or manual) and whether the network is visible or hidden. This XML can be handwritten or to be exported from a Windows computer that already has the network configured using netsh commands.
Export the XML from an already configured WiFi connection
In practice, it's usually more convenient to let Windows generate the XML for you. To do this you can export the existing WiFi profile from a computer where the connection works correctly, following a few very simple steps.
First, create a local folder (for example, C:\WiFi), open a command prompt with administrator privileges, and run netsh wlan show profiles to list the saved wireless profiles. Then you use an export command like this: netsh wlan export profile name=»ProfileName» folder=C:\WiFi, adding the parameter key=clear if you want the WiFi network password appear in plain text within the XML.
The resulting file, usually named something like Wi-Fi-ProfileName.xml, is opened with a text editor to review its contents, make minor adjustments if necessary, and Copy it as the OMA-URI configuration value within Intune. It's important to ensure that the the profile should not have problematic characters, that the The SSID must be correct and special characters (such as &) must be properly escaped in XML.
PSK key rotation and best practices
When managing WiFi networks with PSK in a company, it's not enough to just create a pretty profile in Intune: you have to plan very carefully. periodic password rotationChanging the password abruptly without a strategy can disconnect many devices that rely on that WiFi to communicate with Intune and receive the new settings.
The most sensible way to do this is to make sure that the devices can connect to the Internet via another method During the transition: another temporary Wi-Fi network, a guest network, or mobile data for phones and tablets. This allows them to receive the new profile with the new PSK even when the old one no longer works on the main network.
It also helps a lot to schedule the deployment of the new profiles in off-peak hours (evenings, nights, weekends) and notify users that there may be connectivity outages. During that time, you can monitor for errors, see devices that aren't updating, and, if necessary, repair connections, see devices that are not updating and, if necessary, provide instructions for them to connect to the backup network.
Network connection profiles and firewall rules
Beyond the operating system itself, many security suites include their own layer of network connection profilesA typical example is products that divide protection into Private and Public profiles, and allow you to create custom profiles with specific firewall rules depending on the network you are on.
You will usually see two predefined profiles that cannot be deleted: Private and PublicThe Private profile is used for trusted networks (home or office), where file sharing, printer access, incoming RPC communication, and remote desktop access are permitted. The Public profile is reserved for untrusted networks and blocks resource sharing, making your computer much less vulnerable.
In addition to those basic profiles, it is possible to create custom network connection profilesIn each one you can define a name and description, add specific trusted addresses, mark the connection as trusted (which usually automatically adds the adapter's subnet to the secure zone) and activate features such as "Weak WiFi encryption report" so that the program alerts you when it detects an open network or one with poor encryption.
Each profile in this layer can have its own activators or triggersConditions that must be met for the profile to be applied to a specific network connection (e.g., WiFi SSID, gateway IP address, network type, etc.). Profiles are evaluated according to a priority (up/down), and the first one that matches the conditions is applied.
Advanced management of profiles, connections, and locations in Solaris-like environments
On platforms more geared towards enterprise environments, such as Oracle Solaris, the network profile concept is combined with network configuration units (NCUs), priority groups, and locationsEverything can be managed both from a Network Preferences GUI and from commands such as ipadm, dladm, netcfg and netadm.
The Network Profile view of the GUI shows a List of all available profilesindicating which one is active via a radio button. There are reactive and fixed profiles; system-defined profiles, such as Automatic and DefaultFixed, cannot be edited or deleted, but you can create as many custom reactive profiles as you need.
Each profile groups several network connections (NCUs) that are activated or deactivated when that profile becomes active. From the edit dialog box you can add or remove connections from the profileIf you add a connection, it will be activated along with the profile; if you remove it, it will be deactivated when the profile is in use. For fixed profiles that do not allow editing from the GUI, the ipadm and dladm commands are used to adjust the active network settings.
Interfaces can also be organized into priority groups There are three main types: Exclusive, Shared, and All. An Exclusive group maintains only one active connection at a time, and while there is an active connection in that group, no attempt is made to activate connections in lower-priority groups. In a Shared group, all possible connections are activated, and as long as at least one is active, lower-priority groups are not affected. In an All group, all connections are activated, and if any fail, all connections are deactivated, and the system considers moving to lower-priority groups.
In the default Automatic profile, the highest priority group usually contains all wired interfacesWireless interfaces are placed in a lower priority group. The result: the system always prefers a wired connection when available and only resorts to Wi-Fi if there is no Ethernet connection.
In addition to profiles, Solaris handles the concept of network locationsThese group configurations for name services and security (IP and IPsec firewall configuration files). There are system locations (Automatic, NoNet, DefaultFixed), manual locations, and conditional locations. Manual locations are activated manually from the Locations dialog box, while conditional locations are triggered based on rules that define specific network conditions.
In the Network Locations dialog box you can Change locations, edit their properties, create new ones, or delete user-created ones.Each location has an activation mode: system-activated, manual, or rule-based. If you choose rule-based activation, a dialog box opens where you specify the circumstances under which the location becomes active. At any given time, there can only be one location active. an active locationso that when a new one is activated, the previous one is automatically deactivated.
IPsec profiles on routers for secure connections between networks
Profiles aren't limited to end devices: many professional routers, such as the Cisco RV160 and RV260, use them. IPsec profiles to define how traffic is encrypted and authenticated in site-to-site VPN tunnels. These profiles group phase I (IKE) and phase II (data) parameters that must match at both ends of the tunnel.
In IPsec Phase I A secure channel is established between the routers using IKE (version 1 or 2). This involves selecting the encryption algorithm (3DES, AES-128, AES-192, AES-256), the authentication method (MD5, SHA1, SHA2-256), the Diffie-Hellman group (e.g., Group 2 of 1024 bits or Group 5 of 1536 bits), and the security association (SA) lifetime. IKEv2 is typically the preferred option due to its greater efficiency and flexibility.
In phase II This is where the actual traffic traveling through the tunnel is encrypted. A decision is made regarding whether to use ESP (encryption and, optionally, authentication) or AH (authentication only, no encryption), the encryption and hashing algorithms are reconfigured, and it is determined whether to enable Perfect Forward Secrecy (PFS) and the IPsec SA lifetime (e.g., 3600 seconds) are set. It is recommended that the lifetime of Phase I be longer than that of phase IIso that the data keys are renewed more frequently.
On an RV160/RV260 interface, access the VPN menu > IPSec VPN > IPSec Profiles to create a new profile, give it a name (for example, “HomeOffice”), select the key creation mode (usually Automatic), choose IKEv1 or IKEv2, define the Phase I and Phase II parameters, enable PFS if applicable, and choose the DH group for each phase. Apply and save the configuration, passing the running configuration to the startup configuration. so that it is not lost when restarting.
It is essential that both ends of the IPsec tunnel share exactly the same profile parameters: encryption and hashing algorithms, DH groups, times to live, PSK, or certificatesIKE version, etc. If there are discrepancies, the negotiation fails and the tunnel is not established, however well one of the sides may seem to be set up.
Extra tip: Keep the same SSID and password when changing carriers
Beyond advanced profiles, there's a very practical trick for Avoid reconfiguring all your WiFi devices When you change internet providers: keep the same network name (SSID) and the same password you had before on the new router.
When you replace one router with another, it usually comes with a different SSID and passwordHowever, all you need to do is go into the WiFi settings of the new router, locate the wireless network configuration section, and Change the SSID and password to the ones you used before.Once you do this and save the changes, all devices that remembered that network will automatically connect, as if nothing had changed.
If your previous provider used insecure or impractical passwords, you might want to take this opportunity to create your own SSID and a strong password from scratch, instead of using the factory defaults. If you do that from day one, and when you switch providers, you reconfigure the new router with that same custom name and password, You avoid having to go device by device. rewriting passwords.
For devices that are close to the router (such as a Smart TV or a game console), you can always opt for a Ethernet cable To bypass Wi-Fi entirely, a wired connection offers lower latency, less interference, and greater stability, ideal for streaming, gaming, or solutions like Steam Link. However, most smart home devices (smart speakers, sensors, light bulbs, cameras, etc.) will still require Wi-Fi.
This entire ecosystem of network profiles, locations, managed WiFi configurations, smart firewalls, and IPsec profiles on routers allows your equipment to practically adapt itself to the network it's on: Choose the appropriate interface, apply the correct security, connect to the correct WiFi network, enable the VPN if necessary, and adjust the firewall to the context.This prevents you from having to manually change settings every time you switch networks. Share this information so that more users know about the topic..