Port Profile Overview
Feature Overview
When a device is connected to an ICX port, the profile that is mapped to that device is applied to the port. By using port profiles, you do not need to manually configure the port, which simplifies the deployment of RUCKUS APs and other end devices such as VoIP phones, CCTV cameras, and printers.
Key Features
There are two methods for applying the port configuration using the port profile:
- Static port profile: The port profile configuration can be applied manually to a specific port using the CLI. When a static profile configuration is applied on a port, the configuration remains even if the device is disconnected. Ports that have been assigned a static profile allow additional configurations to be added, thereby permitting per-port customization. Any changes made to the port attributes are reflected on the port when the configurations are applied using the CLI.
- Dynamic port profile: The port profile configuration is applied automatically to a port based on the connected end device. The ICX device detects the Link Layer Discovery Protocol-Type Length Value (LLDP-TLV) or the MAC-Organizationally Unique Identifier (MAC-OUI) of the end device and applies the predefined profiles automatically. The port configured with a dynamic profile allows configuration changes only through that profile. Any changes made to the attributes of a dynamic profile are applied to all the ports where the profile is applied. When the device is disconnected from the port, the profile is automatically removed.
Port profile exclusions can be managed at two levels to prevent specific ports from being modified by dynamic assignments:
- Profile level: Use the
exclude-portscommand in port-profile configuration mode to prevent that profile from being applied to certain ports. Refer to Configuring a Dynamic Port Profile for more information. - Interface level: Use the
exclude port-profilecommand in interface configuration mode to globally exclude a port (such as a critical uplink) from participating in any dynamic port-profile assignments, regardless of the number of profiles defined on the device. Refer to Excluding an Interface from Dynamic Port-Profile Assignments for more information.
Port profiles can be classified into two functional areas:
Device Identification: The port profile feature uses a LLDP-TLV or the MAC-OUI to identify the connected devices.
The Type Length Value (TLV) is a way of storing data to facilitate quick parsing of that data. For device identification, the port profile feature first looks for an LLDP-TLV. If a matching device and profile are found, the corresponding profile configuration for the device is applied to the port. LLDP-TLV device identification takes priority. If the LLDP-TLV lookup fails, the MAC-OUI information is used to find the matching profile.
An Organizationally Unique Identifier (OUI) is the first three octets of a MAC address. For example, F8-E7-1E is the RUCKUS proprietary MAC-OUI. Once the device is connected to the port, the MAC-OUI can be mapped to preconfigured profiles. If the device MAC-OUI matches the mapped MAC-OUI, the respective profile is applied to the port.
Profile Management: With port profiles, you can define a set of port attributes that can be used by multiple interfaces. Once created, a port profile can be assigned to specific interfaces or to a port group. You can create, update, and delete the port profiles using the CLI. Only one port profile can be applied to an interface. When a device is connected to a port with no predefined profile or if profile matching is not found, the port operates as a regular data port.
Requirements
Port profiles are supported on RUCKUS ICX 7550, RUCKUS ICX 7650, RUCKUS ICX 7850, and RUCKUS ICX 8200 devices.The port profile supports the following configurable attributes:
- VLANs (tagged and untagged)
- PoE granular setting
- ACL
- Authentication method (IEEE 802.1x, MAC, and so on)
- Port security
- Protected port (Optional)
By default, RUCKUS APs are set up for dynamic port configuration. This includes pre-provisioning the necessary data (LLDP TLV, MAC OUI) for identification. The LLDP TLV provides information about the device, while the MAC OUI is used for unique identification. Hence, with minimal configurations, RUCKUS APs can be supported by port profiles by default.
Configurations applied by dynamic
port profiles are not saved by the write memory command (ensuring
that dynamically applied configurations are not retained after a reboot, preserving
the intended behavior of port profiles).
To view configurations applied by
port profiles, use the show port-profile-config command only;
port-profile-based configurations are intentionally excluded from the show
running-config command output.
Beginning with FastIron 10.0.20a, you can enable the port profile feature on breakout ports.