Overview of ICX Switch Management

Beginning with SmartZone 5.0, the SmartZone administrator can monitor and manage switches and routers in the ICX 7000 series. SmartZone 5.1.1 introduced the capability to configure switches.

SmartZone ICX-Management supports the following ICX switch activities:

  • Registration and authentication
  • Switch inventory (for example, model, firmware version, and last backup)
  • Health and performance monitoring (for example, status, traffic statistics, errors, and clients) with alarms
  • Zero-touch provisioning
  • Configuration changes
  • Port settings
  • Configuration copy
  • Configuration file backup and restore
  • Firmware upgrade
  • Client troubleshooting
  • Remote Ping and Traceroute
  • CLI templates and provisioning

Note: Refer to the Supported ICX Models for more details.

Preparing ICX Devices to be Managed by SmartZone

Technical changes for SZ
SmartZone enables administrators to monitor and manage ICX 7000 series switches. Starting with SmartZone 5.0, you can perform tasks such as registration, authentication, and health monitoring. SmartZone 5.1.1 added the ability for switch configuration. Key features include zero-touch provisioning, firmware upgrades, and client troubleshooting.

ICX devices can be managed by SmartZone. The following items are required to manage ICX devices:

Note: Refer to Supported ICX Models for detailed information on software compatibility requirements and feature availability.

  • The SmartZone IP address must be reachable by the ICX device through the Management interface or through switch or router interfaces.
  • The ICX device must be made aware of the configured SmartZone IP address in one of the following ways:
    • Configure the DHCP server to use DHCP option 43.
    • Issue the following command at the global configuration level:
      ICX(conf)# manager active-list SmartZone_Controller_IP_Address
       
    • Add an entry in the DNS server with the hostname ruckuscontroller or ruckuscontroller.local domain that points to the SmartZone IP address.
  • On ICX 7750 devices, self-signed certificates are used. SmartZone honors these certificates when the non-tpm-switch-cert-validate command is entered on the SmartZone console, as shown in the following example. To check the configuration status of the tpm-switch-cert validation, enter the show running-config non-tpm-switch-cert-validate command.
    SZ# config 
    SZ(config)# non-tpm-switch-cert-validate
    Successful operation
    
    SZ(config)# end
    SZ# show running-config non-tpm-switch-cert-validate
    NonTPM Switch Certificate Validate: Enabled
  • When SmartZone or ICX devices are behind network address translation (NAT), be sure to forward TCP ports 443 and 22 through NAT.
  • Virtual platform requirements for supporting ICX devices are listed in the following table.
    Note: Each unit in a stack is considered a separate switch unit for capacity management purposes.

    Virtual Platform Requirements for Supporting ICX Devices

    Platform Maximum Number of Switches Per Node RAM vCPU Disk Storage
    vSZ-E 200 18 GB 4 100 GB
    vSZ-H 2000 30 GB 12 300 GB

    The scaling limits in the table apply to switch-only deployments. For a mix of APs and switches, the scaling limits vary accordingly. SmartZone supports a 5-to-1 AP-to-switch ratio.

    vSZ-E Example: vSZ-E supports up to 1,000 APs on a single node. If 200 APs are currently managed by SmartZone, there is room for 800 more APs or 160 ICX switches (800 divided by 5).

    vSZ-H Example: vSZ-H supports up to 2,000 ICX switches on a single node. If 500 switches are currently managed, there is room for 1,500 more switches, or 7,500 APs (1500 multiplied by 5).

Note: Onboarding ICX Switches to SmartZone. Using CLI commands to establish and verify switch connectivity to SmartZone.

Click to play video in full screen mode.