I am testing the virtual smart zone product to replace our legacy ZoneDirector3050. I will provide details below of testing.
Subject: R600 AP unable to successfully join Virtual SmartZone 6.1.2 - ZD to SZ migration
--- Environment ---
Controller: Virtual SmartZone Essentials 6.1.2.0.1071 (KVM/Proxmox)
Control Plane Software: 6.1.2.0.1018
AP Zone Firmware: 5.2.2.0.2122 (AP Patch scg-ap-5.2.2.0-2122.patch applied)
AP Zone Name: gclab-r600
Test AP: Ruckus R600
- MAC: F0:3E:90:32:8A:40
- Serial: 171603502066
- Current Firmware: 110.0.0.0.675 (SmartZone standalone)
- IP: 192.168.29.101/24
- Gateway: 192.168.29.1
- Management VLAN: 29
Network: AP is on VLAN 29 (192.168.29.0/24), vSZ control interface is on public subnet xxx.xxx.xxx.xxx/24. Inter-VLAN routing is confirmed working — AP can reach vSZ and vice versa.
Background: We are migrating from an end-of-life ZoneDirector 3050 managing 56 APs (50x R600, 3x R710, 3x T300). This is a test with a single R600 before production migration.
--- Attempt 1: ZD firmware AP connecting to vSZ (AP firmware 9.13.1.0.11) ---
- AP was running ZoneDirector firmware 9.13.1.0.11
- Set controller IP via SSH: set scg ip xxx.xxx.xxx.xxx
- AP discovered the vSZ and was approved
- vSZ rejected the AP with event code 2003: "ZD-AP [F0:3E:90:32:8A:40] / [171603502066] model [R600] is not being upgraded with Virtual SmartZone AP firmware because of ACL setting."
- This repeated continuously despite creating an AP registration rule for subnet 192.168.29.0/24 pointing to the legacy-r600 zone
--- Attempt 2: After applying AP Patch and configuring lwapp2scg ---
- Applied AP patch scg-ap-5.2.2.0-2122.patch to the vSZ
- Configured lwapp2scg policy to accept via CLI
- Added AP MAC to lwapp2scg ACL
- AP discovered, was approved, and connected (event code 312)
- vSZ initiated ZD AP migration — event code 2001: "ZD-AP upgrading with Virtual SmartZone AP firmware version - [5.2.2.0.2064]"
- AP lost heartbeat (event code 314) and disconnected (event code 303)
- AP appeared to enter a boot loop — ping from monitoring station showed AP dropping off every ~60 seconds and returning, suggesting repeated reboot cycles
- AP never successfully reconnected after firmware push
--- Attempt 3: Pre-flashed SZ firmware on AP ---
- Factory reset the AP
- Manually flashed AP with SmartZone standalone firmware 110.0.0.0.675 via AP web UI
- Confirmed firmware via SSH: get version shows 110.0.0.0.675
- Configured AP: IP 192.168.29.101, gateway 192.168.29.1, management VLAN 29
- Set lwapp2scg policy to accept-all on vSZ
- Disabled ap-cert-check on vSZ
- Created new zone gclab-r600 with AP firmware 5.2.2.0.2122
- Set controller via SSH: set scg ip xxx.xxx.xxx.xxx
- AP state cycles between DISC_REQ_STATE and JOIN_REQ_STATE
- Reached CONN_GET_ADDR_STATE once briefly, then fell back to DISC_REQ_STATE
- AP never fully connects or appears as managed in vSZ
- No events appearing in vSZ event log for this attempt
--- vSZ Configuration ---
- Profile: Essentials (single NIC)
- lwapp2scg policy: accept-all
- AP certificate check: disabled
- L3 ACL: default-deny with permit rules for xxx.xxx.xxx.xxx/24 (DNS), 192.168.29.0/24 (AP network), plus DNS (port 53) and DHCP (port 67)
- AP auto-approval: disabled
- AP registration: rule removed (relying on lwapp2scg accept-all)
--- Questions ---
- Is there a firmware compatibility issue between AP firmware 110.0.0.0.675 and vSZ 6.1.2? Should the AP be running a specific 5.2.2.x standalone image to match the zone firmware?
- What is the correct procedure to migrate an R600 from ZoneDirector firmware to SmartZone on vSZ 6.1.2?
- Are there specific ports beyond TCP 9100 that need to be open between the AP and vSZ for the join process to complete?
- Is the R600 fully supported on vSZ Essentials 6.1.2, or only on specific earlier versions?
Any guidance on getting this R600 to successfully join the vSZ would be greatly appreciated. We need to validate R600 compatibility before proceeding with the full production migration of 56 APs.