Troubleshooting ICX-to-SmartZone or ICX-to-RUCKUS One Connectivity

Basic Validation to Attempt First for ICX Connections to SmartZone or RUCKUS One

Validate Troubleshoot Check Recover
UFI loaded
ICX# show version | include UFI
Image filename followed by "(UFI)" If UFI is not present in the output, reload the UFI.
Upgrade successful
ICX# show hmon client status all-clients 

Oper. State: Up for these processes:

nginx

wmsgi

PySzAgtSrv.py

nats_client

collectd

netconfd-pro

netconfd_svc

cfg_sync

slam_server.py

If any of the processes is not present, re-upgrade.

If any of the processes is not up, reload the ICX device.

Clock correct
ICX# show clock 
Clock time correct Set the system clock or configure NTP.
Certificate installed

Verify hardware and version:

ICX# show version | include HW 

Check for certificate and possible key corruption:

ICX# dm verify-device-certs 

Hardware model

Presence of certificate

Valid key

For all ICX models (TPM devices), you must create an RMA if the certificate is not valid.

ICX Switch Not Registering with SmartZone or RUCKUS One

Validate Troubleshoot Check Recover
Switch registrar is configured.
ICX# show running-config | include registrar 
"manager registrar" in command output If no configuration exists, configure the registrar.
DNS is configured.
ICX# show running-config | include dns
ip dns server-address x.x.x.x If no configuration exists, configure a DNS server.
DNS is reachable.
ICX# ping x.x.x.x (DNS server IP address) 
Response to ping If there is no response to ping, debug with the show manager status command and show manager log command (see next row).
Switch registrar status
ICX# show manager status | include registrar
Registrar host is present (typically,

sw-registrar.ruckuswireless.com).

Discovery retry count

Host resolve failure count

If the DNS is not reachable (host resolve failure count >0), try these options:

Configure a different DNS server.

Remove the registrar and configure the SmartZone IP address:

ICX(config)# no manager registrar 

ICX(config)# manager active-list x.x.x.x

If the registrar is unreachable (discovery retry count >0), try these options:

Check network settings.

ICX# traceroute x.x.x.x (registrar IP address) 

SZ agent state
ICX# show manager status 

SZ agent makes these transitions:

Init: Initializing

Query: Trying to reach SmartZone and register

Connecting: Registration complete. Establishing connection.

Connected: Session with SmartZone established.

NATS Tunnel status is "NATS CONNECTED."

If SZ agent state is "Query" and does not change, go to SZ Agent Stuck in Query State.

If SZ agent state is "Connecting" and does not change, contact RUCKUS Support.

SZ Agent Stuck in Query State

Validate Troubleshoot Check Recover
Output from the show manager status command is unchanged.
ICX# show log | include management 
"Failed to connect to management device at ip_address" with an HTTP error code.

Make sure the IP address listed is the address to which the switch should connect.

For wrong IP address, remove the registrar, and configure the SmartZone IP address:

ICX(config)# no manager registrar 

ICX(config)# no manager active-list

ICX(config)# manager active-list x.x.x.x

HTTP Error Code 400 - Authentication Verify the device certificate. If the certificate is corrupted on the non-tpm device, use the following command to delete the certificate and key, and reload:
ICX(config)# crypto device-key-zeroize 
HTTP Error Code 401 - Unauthorized switch (switch not recognized by SZ or not pre-approved) Move the ICX switch manually from the default group, or create a rule for SmartZone to automatically add the switch to an existing group.
HTTP Error Code 403 - Switch registration rejected by SZ due to license capacity Add licenses on SmartZone, or reconfigure the ICX switch to use another SmartZone device.
HTTP Error Code 409 - Switch is online already

Try the following steps for on-premises SmartZone:

ICX(config)# manager disable 
Delete the switch from the switch group on SmartZone.
ICX(config)# no manager disable 

Try these steps for RUCKUS One:

ICX# manager disconnect 
In the RUCKUS One GUI, delete the switch, and add it back.
ICX# manager connect 

HTTP Error Code 500 - SZ server encountered an unexpected condition that prevented it from fulfilling the request Make sure SmartZone is up and running without errors.
HTTP Error Code 503 -

The volume of switches is over system capacity, or switch was deleted.

Follow the same steps used to handle a 409 error. Or reconfigure the ICX switch to use another SmartZone device.

Miscellaneous Issues

Issue Recover
"User authentication issue" displayed on screen Disconnect and reconnect ICX-Management:

ICX(config)# manager disable 

ICX(config)# no manager disable 

If the issue affects service, reload the ICX device as a last resort.

ICX information not displayed correctly
ICX backups fail