Port Profile Overview

A port profile enables ICX devices to dynamically configure a port by using predefined profiles based on the connected end device.

Feature Overview

When a device is connected to an ICX port, the profile that is mapped to that device is applied to the port. By using port profiles, you do not need to manually configure the port, which simplifies the deployment of RUCKUS APs and other end devices such as VoIP phones, CCTV cameras, and printers.

Key Features

There are two methods for applying the port configuration using the port profile:

  • Static port profile: The port profile configuration can be applied manually to a specific port using the CLI. When a static profile configuration is applied on a port, the configuration remains even if the device is disconnected. Ports that have been assigned a static profile allow additional configurations to be added, thereby permitting per-port customization. Any changes made to the port attributes are reflected on the port when the configurations are applied using the CLI.
  • Dynamic port profile: The port profile configuration is applied automatically to a port based on the connected end device. The ICX device detects the Link Layer Discovery Protocol-Type Length Value (LLDP-TLV) or the MAC-Organizationally Unique Identifier (MAC-OUI) of the end device and applies the predefined profiles automatically. The port configured with a dynamic profile allows configuration changes only through that profile. Any changes made to the attributes of a dynamic profile are applied to all the ports where the profile is applied. When the device is disconnected from the port, the profile is automatically removed.

Port profile exclusions can be managed at two levels to prevent specific ports from being modified by dynamic assignments:

  • Profile level: Use the exclude-ports command in port-profile configuration mode to prevent that profile from being applied to certain ports. Refer to Configuring a Dynamic Port Profile for more information.
  • Interface level: Use the exclude port-profile command in interface configuration mode to globally exclude a port (such as a critical uplink) from participating in any dynamic port-profile assignments, regardless of the number of profiles defined on the device. Refer to Excluding an Interface from Dynamic Port-Profile Assignments for more information.

Port profiles can be classified into two functional areas:

  • Device identification
  • Profile management (and applying the profile to a matching device)

Device Identification: The port profile feature uses a LLDP-TLV or the MAC-OUI to identify the connected devices.

The Type Length Value (TLV) is a way of storing data to facilitate quick parsing of that data. For device identification, the port profile feature first looks for an LLDP-TLV. If a matching device and profile are found, the corresponding profile configuration for the device is applied to the port. LLDP-TLV device identification takes priority. If the LLDP-TLV lookup fails, the MAC-OUI information is used to find the matching profile.

An Organizationally Unique Identifier (OUI) is the first three octets of a MAC address. For example, F8-E7-1E is the RUCKUS proprietary MAC-OUI. Once the device is connected to the port, the MAC-OUI can be mapped to preconfigured profiles. If the device MAC-OUI matches the mapped MAC-OUI, the respective profile is applied to the port.

Profile Management: With port profiles, you can define a set of port attributes that can be used by multiple interfaces. Once created, a port profile can be assigned to specific interfaces or to a port group. You can create, update, and delete the port profiles using the CLI. Only one port profile can be applied to an interface. When a device is connected to a port with no predefined profile or if profile matching is not found, the port operates as a regular data port.

  • Port Profile Flowchart

Requirements

Port profiles are supported on RUCKUS ICX 7550, RUCKUS ICX 7650, RUCKUS ICX 7850, and RUCKUS ICX 8200 devices.

The port profile supports the following configurable attributes:

  • VLANs (tagged and untagged)
  • PoE granular setting
  • ACL
  • Authentication method (IEEE 802.1x, MAC, and so on)
  • Port security
  • Protected port (Optional)
  • Speed (Optional)
  • DHCP snooping (Optional)
  • BPDU guard (Optional)

By default, RUCKUS APs are set up for dynamic port configuration. This includes pre-provisioning the necessary data (LLDP TLV, MAC OUI) for identification. The LLDP TLV provides information about the device, while the MAC OUI is used for unique identification. Hence, with minimal configurations, RUCKUS APs can be supported by port profiles by default.

Configurations applied by dynamic port profiles are not saved by the write memory command (ensuring that dynamically applied configurations are not retained after a reboot, preserving the intended behavior of port profiles).

To view configurations applied by port profiles, use the show port-profile-config command only; port-profile-based configurations are intentionally excluded from the show running-config command output.

Beginning with FastIron 10.0.20a, you can enable the port profile feature on breakout ports.

Note: If a port is currently a member of the default VLAN as an untagged port, applying a port‑profile can move the port directly to a user VLAN as untagged. However, if the port is already associated with a user VLAN as an untagged port, the port‑profile will not move the port to another VLAN in untagged mode. In this case, the port must first be reassigned to the default VLAN before applying the port‑profile.
Note: Port profiles can be applied only to physical Ethernet interfaces. They are not supported on Link Aggregation Group (LAG) virtual interfaces, LAG member ports, or management ports.
Note: It is recommended that you use LLDP-based port profiles instead of MAC-OUI-based port profiles for Inter-Switch Link (ISL) ports (MSTP or RSTP core ports) in Rapid Spanning Tree Protocol (RSTP) or Multiple Spanning Tree Protocol (MSTP) environments. MAC-OUI-based port profiles depend on MAC address entries and are sensitive to MAC flush events caused by topology changes.