Busymate DevTools · dashboard how-to
When a device routes traffic through an external proxy and that proxy can't be applied, one of two things happens: the device goes dark or it leaks its real IP. You now choose which — per device, from the dashboard — and the panel shows you, live, which one is happening.
01 · Where it lives
02 · The control
The segmented control decides what the PAC serves when the device's external proxy can't be applied. The line under it always tells you how the choice resolved for this device.
Picks the safe side for you: a device with an external proxy configured fails closed — its real IP must never show — while every other device fails open and stays online.
Always hold egress: the device gets a no-egress PAC, never DIRECT. The real IP cannot leak — but the device has no internet while the proxy is down.
Always stay online: the device falls back to DIRECT while the proxy is down. Best uptime — but the real IP is briefly exposed, and the panel says so in red.
03 · The live state
The panel doesn't just set the behavior — it shows which behavior is happening right now, next to the last socket IP the proxy actually saw.
Traffic is going through the proxy and the source IP is in the allowlist. Nothing to do.
The external proxy is unavailable and the device is safely holding — no traffic, no leak. It comes back on its own when the proxy does. Amber means "working as intended, but the device is off the air".
An external proxy is configured but not applied — the device is on DIRECT and its real IP is exposed right now. Only possible on Open (or legacy no-posture) devices. Fix the proxy, or switch the device to Closed/Auto.
04 · One rename, worth knowing
The panel formerly called "Egress IPs" lists the IPs the device connects from — the addresses admitted into the proxy's CONNECT allowlist (ingress). It is not the IP a target server sees; that comes from the external proxy and is shown separately.
05 · Automation
The same posture is readable and writable from any MCP client (BusyBro included), so fleet-wide policy can be scripted: