New in This Document

Information has been added or updated to reflect new FastIron features or enhancements to existing FastIron features.

For commands introduced since Release 08.0.01, a history table is included with each command to provide details about the modifications to that command. For commands introduced prior to Release 08.0.01, a history table is not provided, unless the command has been modified in recent releases.

Note: In addition to commands that are new or modified for this release, commands for existing FastIron features may have been added that were previously described only in FastIron configuration guides.

New Commands for FastIron 09.0.10j_cd4

No new commands have been added (new for this release).

Modified Commands for FastIron 09.0.10j_cd4

The following command has been modified (updated for this release).

  • static-port-ip-mapping

Deprecated Commands for FastIron 09.0.10j_cd4

No commands have been deprecated in this release.

New Commands for FastIron 09.0.10j

The following commands have been added (new for this release):

  • bsicloud enable
  • ip ssh delete-known-host-key
  • ip ssh encryption
  • ip ssh host-key-method
  • ip ssh stricthostkeycheck ask

Modified Commands for FastIron 09.0.10j

The following commands have been modified (updated for this release).

  • crypto key generate
  • ip ssh key-exchange-method
  • snmp-server user

Deprecated Commands for FastIron 09.0.10j

Command Replaced By Replacement Notes
ip ssh encryption aes-only No replacement This function is no longer supported.

New Commands for FastIron 09.0.10h

The following commands have been added (new for this release).

Re-Introduced Commands for FastIron 09.0.10h

The following commands have been re-introduced in this release.

  • aaa authentication login privilege-mode

Modified Commands for FastIron 09.0.10h

The following commands have been modified (updated for this release).

  • manager connect
  • manager disconnect
  • manager query
  • manager registrar-query-restart
  • manager reset

Re-Introduced Commands for FastIron 09.0.10f

The following commands have been re-introduced in this release.

  • snmp-server community community-string view

Re-Introduced Commands for FastIron 09.0.10e

The following commands have been re-introduced in this release.

  • enable strict-password-enforcement

New Commands for FastIron 09.0.10e

No new commands have been added (new for this release).

Modified Commands for FastIron 09.0.10e

The following commands have been modified (updated for this release).

  • management access
  • show manager status

Deprecated Commands for FastIron 09.0.10e

The following command have been deprecated in this release.

Deprecated Commands for FastIron 09.0.10e

Command Replaced By Replacement Notes
ip dhcp-server arp-ping-timeout No replacement. This function is no longer supported.
snmp-server community community-string ro | rw acl-name | acl-num | ipv6 ipv6-acl-name management access src-ip ipv4-address | src-ipv6 ipv6-address { allow |deny { snmp-server community | name } } The same functionality can be achieved by having the replaced management access command.
snmp-server group groupname v1|v2c|v3 {auth | noauth | priv }access standard-ACL-id | ipv6 ipv6-ACL-name management access src-ip ipv4-address | src-ipv6 ipv6-address { allow |deny { snmp-server group | name } } The same functionality can be achieved by having the replaced management access command.
snmp-server user user-name group-name v3 access acl-num management access src-ip ipv4-address | src-ipv6 ipv6-address { allow |deny { snmp-server user | name } } The same functionality can be achieved by having the replaced management access command.
snmp-server community community-string view string No replacement The fuctionality is not working for 09.0.10e release and is supported from FastIron release 09.0.10f.

New Commands for FastIron 09.0.10d

The following commands have been added (new for this release).

  • dynamic-bootp
  • extend vlan-range (VXLAN)
  • failure-detection (VXLAN)
  • ip dhcp-server bootp ignore
  • ip dhcp-server use-port-name
  • map vlan-range (VXLAN)
  • static-port-ip-mapping
  • vxlan-riot

Modified Commands for FastIron 09.0.10d

The following commands have been modified (updated for this release).

  • cfg-archive revert-option
  • show arp
  • show ip cache
  • show overlay-gateway
  • show tech-support
  • site (VXLAN)
  • vrf forwarding

Deprecated Commands for FastIron 09.0.10d

No commands have been deprecated in this release.

Re-Introduced Commands for FastIron 09.0.10c

The following commands have been re-introduced in this release.

  • clear rmon statistics
  • rmon alarm
  • rmon event
  • rmon history
  • show rmon
  • system-max rmon-entries
  • relative-utilization
  • show relative-utilization

New Commands for FastIron 09.0.10c

The following commands have been added (new for this release).

  • macsec delay-protection

Modified Commands for FastIron 09.0.10c

No commands have been modified (updated for this release).

Deprecated Commands for FastIron 09.0.10c

No commands have been deprecated in this release.

New Commands for FastIron 09.0.10b

The following commands have been added (new for this release).

  • authentication-algorithm (MKA)
  • crypto openssl default-encoding
  • keychain mka
  • mka-keychain
  • vni-counters

Modified Commands for FastIron 09.0.10b

The following commands have been modified (updated for this release).

  • clear overlay-gateway
  • ip ssh key-exchange-method
  • show dot1x-mka config
  • show dot1x-mka sessions
  • show keychain
  • show overlay-gateway

Deprecated Commands for FastIron 09.0.10b

No commands have been deprecated in this release.

Note: FastIron releases 09.0.00, 09.0.00a, and 09.0.10 are no longer available for download due to the discovery of a critical defect.

 

This is a protected line.

Refer to TSB 2022-001 – FastIron 09.0.00 and 09.0.10 - Risk of Filesystem Corruption on the Technical Support Bulletins page for more details.

This is a protected line.
 

RUCKUS recommends upgrading to FastIron release 09.0.10a or later for all ICX switches currently running any of the afore-mentioned releases.

This is a protected line.
 

All the software features supported in FastIron release 09.0.00, 09.0.00a, and 09.0.10 remain available and supported in FastIron release 09.0.10a and later releases unless specifically noted.

This is a protected line.
 

For completeness, the feature descriptions for all changes introduced in the unavailable releases; that is, FastIron 09.0.00, 09.0.00a, and 09.0.10, are included in this section.

New Commands for FastIron 09.0.10a

The following commands have been added (new for this release).

  • accept-register
  • block unknown-unicast
  • ccep-up-delay
  • cfg-archive management archive-size
  • cfg-archive management cancel-comparison
  • cfg-archive management compare-archives
  • cfg-archive management compare-running-config
  • cfg-archive management compare-startup-config
  • cfg-archive management copy
  • cfg-archive management copy-running-config
  • cfg-archive management delete
  • cfg-archive management delete-unsaved-cfg
  • cfg-archive management list
  • cfg-archive management reload-with-archive
  • cfg-archive management rename
  • cfg-archive management show-archive-content
  • cfg-archive management show-current-config
  • cfg-archive management show-unsaved-cfg
  • cfg-archive revert
  • cfg-archive revert-option
  • clear dlogger logs
  • cli timeout
  • copy scp certificate-data-file
  • copy scp client-certificate
  • copy scp client-private-key
  • copy scp ssh-pub-key-file
  • copy scp ssl-private-key-file
  • copy scp trust-certificate
  • dlogger module
  • dlogger redirect
  • flexlink backup
  • flexlink preemption delay
  • flexlink preemption mode
  • icl-fwd-delay (MCT)
  • interface cpu active
  • ip dhcp snooping verify mac-address
  • ip igmp access-group
  • ip multicast edge-port
  • ip multicast flood-unregistered
  • ip multicast mvr
  • ip multicast static-mcache profile
  • ip options drop
  • ip ssh enable
  • ip tftp blocksize
  • ipv6 deny-undetermined-transport
  • ipv6 drop routing-type
  • ipv6 mld access-group
  • ipv6 multicast flood-unregistered
  • ipv6 options drop
  • jp-policy
  • keychain tcp
  • logging enable tcp-ao
  • logmgr help
  • logmgr hierarchy
  • logmgr monitor
  • logmgr upload
  • management access
  • management source-interface
  • manager ssh-port
  • management vrf
  • multicast mvr
  • multicast sdvoe
  • multicast static-grp-fwd-disable
  • multicast static-mcache profile
  • neighbor ao
  • rate-limit-pps-log
  • register-rate-limit
  • restconf config-sync
  • restconf config-sync-interval
  • restconf enable
  • restconf enable-config-sync
  • securewipe
  • show dlogger logs
  • show dlogger module
  • show flexlink
  • show ip multicast mvr mvlan
  • show ip multicast static-mcache-profile
  • show ip mvr interface
  • show ip mvr mcache
  • show ip mvr setting
  • show ip pim jp-policy
  • show ip tcp vrf
  • show ipv6 pim jp-policy
  • show ipv6 tcp vrf
  • show management access
  • show restconf config
  • show restconf event-counters
  • show restconf running-config
  • show restconf status
  • show uufb enabled-ports
  • snmp-server log-suppress-timer
  • uplink-port (Web Auth)
  • webpage custom-label
  • webpage remove-user-id-label
  • white-list (Web Authentication)

Modified Commands for FastIron 09.0.10a

The following commands have been modified (updated for this release).

  • aaa authentication enable
  • aaa authentication login
  • aaa authentication snmp-server
  • aaa authentication web-server
  • banner
  • broadcast limit
  • copy disk0 (config)
  • copy disk0 flash
  • copy flash disk0
  • copy flash scp
  • copy https flash
  • copy https startup-config
  • copy running-config scp
  • copy scp flash
  • copy scp running-config
  • copy scp startup-config
  • copy startup-config scp
  • copy tftp flash
  • crypto key client generate
  • crypto key client zeroize
  • crypto key generate
  • enable user
  • forwarding-profile
  • interface ve
  • ip dhcp-client ve
  • ip igmp max-group-address
  • ip ssh idle-time
  • ip ssh key-exchange-method
  • ip ssl min-version
  • ipv6 mld max-group-address
  • led
  • logging buffered
  • logmgr fetch
  • map vlan to vni
  • msdp-peer
  • multicast fast-leave-v2
  • multicast limit
  • multi-stack-port
  • multi-stack-trunk
  • option
  • priority-flow-control enable
  • rconsole
  • rspan destination
  • show acl-on-arp
  • show arp
  • show cluster
  • show ethernet loopback interfaces
  • show ip bgp neighbors
  • show ip bgp vrf neighbors
  • show ip dhcp-client options
  • show ip igmp group
  • show ip igmp interface
  • show ip igmp settings
  • show ip igmp traffic
  • show ip msdp peer
  • show ip multicast cluster mcache
  • show ip multicast mcache
  • show ip multicast vlan
  • show ip ssh
  • show ip ssh sessions
  • show ip ssl
  • show ip ssl device-certificate
  • show ip tcp connections
  • show ip tcp traffic
  • show ip pim error
  • show ip pim sparse
  • show ipv6 bgp neighbors
  • show ipv6 mld settings
  • show ipv6 mld traffic
  • show ipv6 multicast mac-mcache
  • show ipv6 multicast mcache
  • show ipv6 multicast optimization
  • show ipv6 pim error
  • show ipv6 pim sparse
  • show ipv6 tcp connections
  • show keychain
  • show license unit
  • show mac access-lists
  • show manager counters
  • show manager status
  • show memory
  • show running-config
  • show running-config vlan
  • show snmp
  • show tech-support
  • show web
  • show webauth
  • snmp-server disable
  • snmp-server enable mib
  • snmp-server enable traps
  • speed-duplex
  • stack-port
  • stack-trunk
  • supportsave
  • unknown-unicast limit
  • username
  • web-management

Deprecated Commands for FastIron 09.0.10a

The following commands have been deprecated in this release.

Deprecated Commands for FastIron 09.0.10a

Command Replaced By Replacement Notes
aaa authentication login privilege-mode No replacement. Authentication must take place before entering Privileged EXEC configuration mode. The user is automatically prompted for their user name and password.
all-client management access The same functionality can be achieved by having the following management access rules:
  • management access src-ip <ip address> 255.255.255.255 allow all (for example, management access src-ip < 255.255.255.255> allow all)
  • management access src-ipv6 <x:x::x:x/x> allow all
batch buffer, buffer-profile port-region, buffer-sharing-full, clear ip dhcp-server statistics, clear web-connection, enable cloud-only-password, enable password-min-length, execute batch, flash, hmon client configuration, hmon client statistics, hmon client status, hmon status, ip preserve-acl-user-input-format, ip ssh client, ip ssh permit-empty-password, qos ingress-buffer-profile, radius-server enable, service password-encryption, show batch schedule, show ip dhcp-server statistics, show ip ssh tcp-forwarding, show ipv6 tcp status, show management traffic exclusion, show qd-buffer-profile, show stack link-sync, show transmit-counter, snmp-server max-ifindex-per-module, telnet server suppress-reject-message, telnet login-timeout, telnet login-retries No replacement. This function is no longer supported.
Campus Fabric Commands: max-vlan (SPX), max-vlans-per-pe-port(SPX), module (SPX), multi-spx-lag, multi-spx-port, pe-id, pe-name, rconsole (SPX), show configuration (SPX), show spx, show spx cb-port, show spx connections, show spx csp, show spx debug, show spx lag, show spx mecid, show spx multicast cache, show spx multicast counters, show spx multicast optimization, show spx multicast resource, show spx pe-group, show spx pe-id, show spx pe-port-vlan-resources, show spx ring, show spx zero-touch ipc, show spx zero-touch log, show spx zero-touch status, show spx-mon, show startup-config (SPX), spx allow-pe-movement, spx cb-configure, spx cb-enable, spx interactive-setup, spx pe-enable, spx ping, spx suggested-id, spx unconfigure, spx unit, spx zero-touch-deny, spx-lag, spx-mon enable, spx-port, zero-touch-enable, zero-touch-ports No replacement. These commands are specific to Campus Fabric and were deprecated because Campus Fabric is no longer supported from FastIron release 09.0.10a.
console timeout, ip ssh idle-time, telnet timeout cli timeout  
copy scp license, copy tftp license license install These commands are no longer required since the licenses can be enabled using the license install command.
crypto-ssl certificate, ip ssl cert-key-size, ip ssl certificate No replacement. These commands were deprecated because users are no longer allowed to generate self-signed certificates on ICX devices. For switches that do not have a RUCKUS signed certificate (ICX 7250, ICX 7450), a self signed certificate will be auto-generated during switch boot up. Users also have the option to copy an external certificate.
deploy No replacement. The DHCP server address pool is automatically activated once created. The deploy command is no longer required to activate the DHCP server address pool.
enable aaa console, enable telnet authentication aaa authentication login AAA support for commands can be configured uniformly using the aaa authentication login command.
aaa authentication enable implicit-user No replacement. This command is deprecated because enable access using only a password (without an explicit username) is no longer supported. Enable access must now use username‑based authentication methods, such as those configured with the aaa authentication login command.
enable cloud-only-password No replacement. Cloud-only password strict security is now the default behavior. The strict enforcement previously controlled by the enable cloud-only-password command is always enabled; no replacement command is required.
enable password-display No replacement. The command is deprecated because passwords can not be stored in plain text.
enable strict-password-enforcement No replacement. This command is not supported in releases FastIron 09.0.10a to FastIron 09.0.10d. Support was re-introduced from 09.0.10e and later releases.
enable super-user-password No replacement. From FastIron 09.0.10a, providing a username and password is mandatory to access an ICX switch.
enable telnet password No replacement. This command is deprecated because, from 09.0.10a, a password is always required for telnet.
enable user password-masking No replacement. Passwords are masked by default and cannot be unmasked.
exit-address-family No replacement The exit or end commands can be used to exit ddress‑family configuration mode.
exit-vrf No replacement The exit or end commands can be used to exit configuration mode for a non‑default VRF instance.
ip dhcp-server relay-agent-echo enable No replacement. By default, the DHCP server echoes the relay packets received and this funcationality can no longer be disabled.
ip multicast disable-flooding, ipv6 multicast disable-flooding ip multicast flood-unregistered, ipv6 multicast flood-unregistered The flooding of unregistered IPv4 and IPv6 multicast frames is now disabled by default. The ip multicast flood-unregistered and ipv6 multicast flood-unregistered commands are introduced to enable the flooding of unregistered multicast frames.
ip ssh authentication-retries   The SSH authentication retries is set to a default of three, as per OpenSSH standards
ip ssh pub-key-file copy tftp flash { ipv4-address | ipv6-address } filename ssh-pub-key-file  
ip ssh strict-management-vrf management access  
ip ssh source-interface management source-interface protocol ssh  
ip ssl certificate-data-file tftp copy tftp flash { ipv4-address | ipv6-address } filename certificate-data-file  
ip ssl client-certificate tftp copy tftp flash { ipv4-address | ipv6-address } filename client-certificate  
ip ssl client-private-key tftp copy tftp flash { ipv4-address | ipv6-address } filename client-private-key  
ip ssl port No replacement. IP Secure Socket Layer (SSL) settings cannot be configured. By default, SSL protocol exchanges occur on TCP port 443.
ip ssl private-key-file tftp copy tftp flash { ipv4-address | ipv6-address } filename ssl-private-key-file  
ip syslog source-interface management source-interface protocol syslog  
ip tacacs source-interface management source-interface protocol tacas  
ip telnet source-interface management source-interface protocol telnet  
ip tftp source-interface management source-interface protocol tftp  
management-vrf management vrf vrf-name strict  
manager source-interface management source-interface protocol manager  
relative-utilization, show relative-utilization   These commands are not supported for 09.0.10a and 09.0.10b.Support was re-introduced for 09.0.10c and later releases.
rmon alarm, rmon event, rmon history, system-max rmon-entries, show rmon   These commands are not supported for 09.0.10a and 09.0.10b. Support was re-introduced for 09.0.10c and later releases.
router-interface   From FastIron 09.0.10a, you can directly start configuring a VE by typing interface ve vlan number. You are no longer required to pre-create the VE using the router-interface ve command under the VLAN. The VE number will be the same as the VLAN number. Users upgrading from prior releases will have the configurations automatically translated to the equivalent commands in FI 09.0.1a.
scp (License) copy scp  
show dot1x, show dot1x configuration, show dot1x ip-acl, show dot1x mac-address-filter, show dot1x mac-filter, show dot1x mac-session, show dot1x sessions, show dot1x sessions detail, show dot1x statistics show authentication session  
show ip static-arp show arp  
show mac access-lists name show mac access-lists  
show mac-authentication configuration, show mac-authentication ip-acl, show mac-authentication sessions, show mac-authentication sessions detail, show mac-authentication statistics show authentication session  
show tech-support acl, show tech-support cluster, show tech-support cpu, show tech-support l2, show tech-support l3, show tech-support license, show tech-support memory, show tech-support multicast, show tech-support multicast6, show tech-support openflow, show tech-support packet-loss, show tech-support poe, show tech-support stack show tech-support Full command output and all details are obtained using the show tech-support command.
snmp-client, ssh access-group, telnet access-group, telnet client management-access  
snmp-server trap-source management source-interface protocol snmp  
source-interface management source-interface protocol ntp  
system-max view No replacement. This command is obsolete because the maximum number of SNMP views depends on the system memory availability..
tacacs-server enable management source-interface protocol tacacs  
terminal logging terminal monitor  
tftp client enable No replacement. TFTP access to specific VLANs is not supported
verify No replacement. Individual binary images do not require verification as they are now bundled into a single package.
web access-group management access  
web client management access  

Beginning with the FastIron 08.0.61 release, Layer 3 features for the RUCKUS ICX 7150 are supported. The following Layer 3 features are not supported for the RUCKUS ICX 7150, and this has been noted where applicable throughout this guide:

  • BGP4
  • BGP4+
  • Multi-VRF
  • Tunnels
  • uRPF

Other Enhancements in FastIron release 09.0.10a

Feature

Description

Location

Unsupported hardware

This release and future releases do not support ICX 7750 devices.

References have been removed throughout the guide.

Unsupported Characters

The CLI does not support certain characters. If these characters are enters, an error message is received.

Unsupported Characters

Unsupported feature This release and future releases do not support Campus Fabric (SPX). References have been removed throughout the guide.

Minor editorial updates

Minor editorial updates were made throughout the Command Reference.

All chapters.

Updates to address defects

Minor updates on commands throughout to address defects.

All chapters.