<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Access points — RUCKUS Networks Community</title>
        <link>https://community.ruckuswireless.com/en/</link>
        <pubDate>Fri, 25 Sep 2026 01:00:40 +0000</pubDate>
        <language>en</language>
            <description>Access points — RUCKUS Networks Community</description>
    <atom:link href="https://community.ruckuswireless.com/en/discussions/tagged/access-points/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Understanding Client Roaming in a Multi-AP Wi-Fi Network</title>
        <link>https://community.ruckuswireless.com/en/discussion/115592/understanding-client-roaming-in-a-multi-ap-wi-fi-network</link>
        <pubDate>Thu, 24 Sep 2026 16:07:49 +0000</pubDate>
        <category>Access Points - Indoor and Outdoor</category>
        <dc:creator>juliaanderson</dc:creator>
        <guid isPermaLink="false">115592@/en/discussions</guid>
        <description><![CDATA[<p>One thing I have been thinking about more in AP Wi-Fi setups is how devices switch between access points.</p><p>A network can have coverage everywhere and still feel unpredictable if devices do not move between access points properly. A phone or computer might stay connected to an access point after getting closer to another one, which can sometimes cause slower speeds or a weaker connection.</p><p>This issue seems obvious in bigger offices, schools, hotels, and other places where people are always moving around.</p><p>The way clients behave is also a factor. Different phones, computers, and smart devices make their decisions about when to switch access points, so just adding more access points does not always fix the problem.</p><p>Things like signal strength, where the access points are placed, how channels are set up, how much power they send out, and the settings for roaming can all impact the experience. It also seems helpful to check what the actual devices are doing, assuming every problem is caused by the access point.</p><p>For anyone who manages a wireless setup, I would like to know how you usually find out why a client stays connected to an access point that is far away.</p><p>Do you mainly check the strength of the client, the roaming events, the access point settings, or the device itself?</p>]]>
        </description>
    </item>
    <item>
        <title>Smartzone SZ144 6.1.0.0.935 Correct Upgrade Path</title>
        <link>https://community.ruckuswireless.com/en/discussion/115589/smartzone-sz144-6-1-0-0-935-correct-upgrade-path</link>
        <pubDate>Tue, 22 Sep 2026 03:07:56 +0000</pubDate>
        <category>SmartZone and Virtual SmartZone</category>
        <dc:creator>vauxhard</dc:creator>
        <guid isPermaLink="false">115589@/en/discussions</guid>
        <description><![CDATA[<p>Hello,<br /><br />
I am new to Ruckus environment. I am using Smartzone SZ144 with v6.1.0.0.935. I found that this version is already so old and obsolete.<br /><br />
I wanna know the safest and correct upgrade path for Smartzone I am using.</p><p></p><p>Any assistance would be so much appreacited.</p><p></p><p>Thanks</p>]]>
        </description>
    </item>
    <item>
        <title>Ruckus and our Xfinity router</title>
        <link>https://community.ruckuswireless.com/en/discussion/115575/ruckus-and-our-xfinity-router</link>
        <pubDate>Fri, 11 Sep 2026 21:41:46 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>Janet</dc:creator>
        <guid isPermaLink="false">115575@/en/discussions</guid>
        <description><![CDATA[<p>The modem and router are not communicating with each other.  We have unplugged all a couple of times.  The Xfinity person came out and we have a strong wi-fi signal.  Pretty sure it is the Ruckus.  There are 3 green lights on it and no red ones.  We are seniors and really need basic instructions on this or if more technical, my son and grandson can help.     We typically call someone to look at things if not working, but in this case there is no one to call. I appreciate any help I can get. Thank you.</p>]]>
        </description>
    </item>
    <item>
        <title>Converting R850 to unleashed</title>
        <link>https://community.ruckuswireless.com/en/discussion/115516/converting-r850-to-unleashed</link>
        <pubDate>Mon, 17 Aug 2026 18:09:52 +0000</pubDate>
        <category>Access Points - Indoor and Outdoor</category>
        <dc:creator>PBI</dc:creator>
        <guid isPermaLink="false">115516@/en/discussions</guid>
        <description><![CDATA[<p>Hello, I am looking to purchase a used R850 with the 901-R850-NC00 product node, so it is not unleashed. I want to convert it to unleashed.</p><p>To that end, I have already downloaded the unleased version R850_200.19.7.112.238.bl7 file.</p><p>Article number 000005720 <span data-embedjson="{&quot;body&quot;:&quot;Article Number: 000005720&quot;,&quot;url&quot;:&quot;https:\/\/community.ruckuswireless.com\/en\/home\/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fsupport.ruckuswireless.com%2Farticles%2F000005720&quot;,&quot;embedType&quot;:&quot;link&quot;,&quot;name&quot;:&quot;Convert Standalone\/SZ\/ZD managed AP to Unleashed Code | Knowledge Base | Ruckus Wireless Support&quot;,&quot;faviconUrl&quot;:&quot;https:\/\/ruckus-support.s3.amazonaws.com\/images\/apple-icons\/touch-icon-iphone.png&quot;,&quot;embedStyle&quot;:&quot;rich_embed_inline&quot;}">
    <a href="https://community.ruckuswireless.com/en/home/leaving?allowTrusted=1&amp;target=https%3A%2F%2Fsupport.ruckuswireless.com%2Farticles%2F000005720" rel="nofollow noopener ugc">
        https://support.ruckuswireless.com/articles/000005720
    </a>
</span>
 lists the procedure for just this, but it was last updated in March 2021. </p><ul><li>Is this still valid?</li><li>The current device that I am looking to purchase was purchased in Aug 2025, and I do not know the current firmware on it.</li><li>Does it matter what the current non unleashed firmware version is on it?</li></ul><p>This is the first time I am dealing with Ruckus products, and I want to make sure the educated / experienced community here says that I am ok to proceed with the purchase on these grounds.</p><p></p><p>Thank you.</p>]]>
        </description>
    </item>
    <item>
        <title>Ruckus Unleashed Guest Access – Grace Period Reconnection Failure</title>
        <link>https://community.ruckuswireless.com/en/discussion/115557/ruckus-unleashed-guest-access-grace-period-reconnection-failure</link>
        <pubDate>Sun, 30 Aug 2026 22:11:02 +0000</pubDate>
        <category>Unleashed</category>
        <dc:creator>chapal</dc:creator>
        <guid isPermaLink="false">115557@/en/discussions</guid>
        <description><![CDATA[<p>Environment</p><p>AP: Ruckus R720<br />
Role: Master AP<br />
Unleashed Firmware: 200.15.6.212.27<br />
Guest SSID: Open authentication / No encryption<br />
Guest Authentication: Enabled<br />
Guest Access: Captive portal authentication<br />
Additional AP: Ruckus R650, same firmware<br />
Guest Authentication Methods:<br />
Unique password for each guest<br />
Single shared password among all guests</p><p><br />
Issue Summary<br />
We are experiencing a reproducible Guest Access authentication failure when "Allow users to reconnect without re-authentication for" (Grace Period) is enabled.</p><p>Initial Guest SSID authentication works normally. The client completes the Guest Access/captive portal process and receives network access.</p><p>However, after disconnecting from Wi-Fi and reconnecting within the configured Grace Period, the client briefly connects and then immediately disconnects.</p><p>The client does not reach DHCP and does not receive an IP address.</p><p>This is reproducible using a single AP, so it is not dependent on roaming.</p><p>Grace Period Testing<br />
Tested Grace Period values:<br />
10 minutes<br />
1440 minutes<br />
14400 minutes<br />
43200 minutes</p><p><br />
Grace Period Disabled<br />
When "Allow users to reconnect without re-authentication" is disabled, the client reconnects normally and proceeds through the expected Guest Access authentication/captive portal process.</p><p>Grace Period Enabled</p><p>After the client has successfully authenticated, disconnects, and reconnects within the Grace Period:</p><p>Client associates/connects to the Guest SSID.<br />
Client immediately disconnects.<br />
No DHCP transaction occurs.<br />
No IP address is assigned.<br />
Client cannot reach the captive portal/network access stage.<br />
If the Grace Period expires, the client can reconnect normally and authenticate again.<br />
The same behavior occurs with both "Unique password per guest" and "Single shared password."</p><p>Client Testing</p><p>Reproduced with:</p><p>Apple iPhone<br />
Android phone<br />
Private/randomized MAC address<br />
Device MAC address<br />
The behavior is independent of client OS and MAC-address mode, making a client-specific issue unlikely.<br />
Troubleshooting / Configuration Checks</p><p>The following were tested or eliminated as likely causes:</p><p>Restricted Subnet Access: Private IP pool entries removed during testing.<br />
Walled Garden: Private IP pool and other relevant entries added; no change.<br />
ACLs: No ACL applied to the AP port or relevant VLANs.<br />
802.11r / Fast BSS Transition: Not enabled/not applicable for this Guest SSID.<br />
802.11v: Not enabled/not shown as applicable.<br />
802.11k: Enabled.<br />
802.11d: Enabled.<br />
Wireless Client Isolation: Disabled during testing; no change.<br />
DHCP: Failure occurs before DHCP.<br />
VLAN/ACL configuration: No change when modified/tested.<br />
Roaming Eliminated</p><p><br />
The issue can be reproduced using one AP only:</p><p>Connect phone to Guest SSID.<br />
Complete Guest Access authentication.<br />
Confirm connectivity.<br />
Disconnect Wi-Fi.<br />
Reconnect to the same SSID on the same AP within the Grace Period.<br />
Client connects briefly and immediately disconnects.<br />
Therefore, the issue does not require:<br />
AP-to-AP roaming<br />
Mobility between APs<br />
Inter-AP guest-state synchronization<br />
The issue was also reproduced between APs, but roaming is not required to trigger the failure.</p><p><br />
R720 vs. R650 Testing</p><p>The issue is not specific to the R720.</p><p>It was reproduced on a Ruckus R650 running Unleashed 200.15.6.212.27:</p><p>R650 as part of an Unleashed deployment<br />
R650 tested separately<br />
The behavior remained the same.<br />
When testing between APs in an Unleashed deployment, the issue also occurred regardless of which AP the client initially connected to or subsequently connected to.</p><p>802.11 Events</p><p>During the failed reconnect attempt, the following events are observed:</p><p>802.11 Disassociation — Reason Code 1: Unspecified<br />
802.11 Deauthentication — Reason Code 5: Disassociation due to AP busy<br />
802.11 Deauthentication — Reason Code 6: Received class 2 frame from non-auth STA<br />
No DHCP transaction occurs after the failed reconnect.<br />
Firmware Upgrade Path</p><p>The current R720-Master Unleashed cluster does not report 200.19 as an available/valid upgrade path.</p><p>Although newer Unleashed releases may exist for some Ruckus AP platforms, the R720-Master cluster reports no available upgrade to 200.19.</p><p>Therefore, upgrading to 200.19 is not currently an available remediation path for this deployment unless Ruckus confirms a supported upgrade path.</p><p>Expected Behavior</p><p>When a previously authenticated Guest Access client reconnects within the configured Grace Period, it should:</p><p>Be allowed to reconnect without re-authentication.<br />
Remain associated.<br />
Obtain an IP address through DHCP.<br />
Receive normal network access according to the Guest Access configuration.<br />
Actual Behavior<br />
With Grace Period enabled:</p><p>Initial authentication → disconnect → reconnect within Grace Period → brief association → immediate disconnect → no DHCP/IP address.</p><p>With Grace Period disabled, or after the Grace Period expires, the client reconnects and proceeds through normal Guest Access authentication successfully.</p><p>Assessment</p><p>The failure appears specifically associated with:</p><p>Guest Access → Allow users to reconnect without re-authentication for (Grace Period)</p><p>Testing has largely eliminated:</p><p>Client OS/device-specific behavior<br />
Private/randomized MAC addressing<br />
Device MAC addressing<br />
DHCP<br />
VLAN ACLs<br />
Walled Garden<br />
Restricted Subnet Access<br />
Wireless Client Isolation<br />
AP-to-AP roaming<br />
R720-specific hardware<br />
A single defective AP<br />
The failure occurs before DHCP and is reproducible across multiple client platforms and AP hardware.<br />
Operational Impact</p><p>Due to this Guest Access Grace Period issue, we are currently using DPSK (Dynamic Pre-Shared Key) as an alternative guest-access method.</p><p>The Ruckus DPSK implementation provides a per-usage option, which is relevant to our guest-user requirements and differs from the DPSK implementation currently available in Ubiquiti UniFi.</p><p>Resolving the Guest Access Grace Period issue is therefore important for determining whether the Ruckus Guest Access workflow can meet our desired guest authentication model without requiring users to repeatedly authenticate.</p><p>Request to Ruckus / TAC</p><p>Can anyone confirm whether this is a known issue/software defect in Unleashed 200.15.6.212.27 involving:</p><p>Guest Access → Allow users to reconnect without re-authentication for (Grace Period)</p><p>Specifically:</p><p>Why is a previously authenticated Guest Access client being disconnected when reconnecting during the Grace Period instead of being permitted to reconnect without authentication?<br />
Is this a known issue in 200.15.6.212.27?<br />
Is there a firmware release containing a fix that is actually supported as an upgrade path for an Unleashed cluster with an R720 as Master?<br />
Is any additional configuration required for Guest Access Grace Period functionality?<br />
What debug commands, support logs, or packet captures are required by Ruckus TAC?<br />
Are 802.11 Reason Codes 1, 5, and 6 expected consequences of a Guest Access Grace Period failure, or do they indicate a separate AP/client state-machine issue?<br />
Are there known limitations with Grace Period and either:<br />
Unique password for each guest<br />
Single shared password among all guests?<br />
Minimal Reproduction</p><p><br />
Configuration:</p><p>Ruckus R720<br />
Unleashed 200.15.6.212.27<br />
Guest SSID: Open / No Encryption<br />
Guest Authentication: Enabled<br />
Captive Portal<br />
Authentication method: Unique password per guest OR Single shared password<br />
Grace Period: Enabled<br />
Steps:<br />
Connect client to Guest SSID.<br />
Complete Guest Access authentication.<br />
Confirm connectivity.<br />
Disconnect Wi-Fi.<br />
Reconnect within the configured Grace Period.<br />
Observe brief connection followed by immediate disconnect.<br />
Confirm that no DHCP address is obtained.</p><p><br />
Reproduced with iPhone and Android, using both private/randomized MAC and device MAC, and on both R720 and R650 hardware.</p>]]>
        </description>
    </item>
    <item>
        <title>How to Remediate TLS/SSL Vulnerabilities on SmartZone 144 Version 6.1.2.0.404</title>
        <link>https://community.ruckuswireless.com/en/discussion/115585/how-to-remediate-tls-ssl-vulnerabilities-on-smartzone-144-version-6-1-2-0-404</link>
        <pubDate>Mon, 21 Sep 2026 09:07:22 +0000</pubDate>
        <category>ZoneDirector</category>
        <dc:creator>Jerayuth</dc:creator>
        <guid isPermaLink="false">115585@/en/discussions</guid>
        <description><![CDATA[<p>The following vulnerabilities were identified:<br />
1. Weak TLS/SSL Ciphers<br />&#13;
2. TLS 1.3 Not Supported<br />&#13;
3. TLS 1.0 Enabled</p>]]>
        </description>
    </item>
    <item>
        <title>Verification process for purchasing a R850 (private sale)</title>
        <link>https://community.ruckuswireless.com/en/discussion/115520/verification-process-for-purchasing-a-r850-private-sale</link>
        <pubDate>Wed, 19 Aug 2026 17:45:20 +0000</pubDate>
        <category>Access Points - Indoor and Outdoor</category>
        <dc:creator>PBI</dc:creator>
        <guid isPermaLink="false">115520@/en/discussions</guid>
        <description><![CDATA[<p>Hello,</p><p>I am looking to purchase an R850 as a private sale. The seller states that this is brand new in box, and it does appear to be. I want to walk through what I did as testing before I walked away because I was not able to reach the management page. The product code was a 901 and not a 9U1, so at least at factory it is NOT an unleashed firmware (although I will eventually convert to unleashed)</p><ul><li>I used a PoE+ switch port (my mistake, I thought this would be sufficient)</li><li>The switch I took for testing was a basic PoE+ switch.</li><li>I powered the 850, it came up, and it with a Connect.me wlan</li><li>It asked for a security key which was the serial number, and it worked</li><li>I connected to it successfully from my laptop, but never got an IP, and thus was never able to browse to either 192.168.0.1 or to unleashed.ruckuswireless.com</li><li>when I tried to use the app, my phone was never able to connect to the connect.me network</li></ul><p>My basic troubleshooting has led me to this:</p><ul><li>Since I was on lower power, the 1Gig port never activated</li><li>However, I was under the impression that Mode 0 should have been enables as the witch port was supplying max 30W per switch port</li><li>Since this test network was just the Layer 2 poe+ switch (802.3at), my laptop and the R850 (I don't know what mode), there was no dhcp server to hand out IP Addresses</li><li>As a reult of this, IP addresses were never assigned, and there could be no browsing to the management address.</li></ul><p>I should have posted this before I went to meet the seller, but such is life. I walked away thinking there was something wrong with the unit.</p><p></p><p>I do want this, but my PoE switch at home does not support this kind of power draw. I intend to get the Ruckus power injector.</p><p>My questions:</p><ul><li>Is my analysis above correct? or should I have been able to  browse to a web site.</li><li>If I just get the power injector and no dhcp server, will I be able to browse to 192.168.0.1 at least? or will I need a dhcp server for even that first  step?</li><li>Is the R850 on unleashed or controller based or stand alone mode?</li><li>Should I lug a router / dhcp server next time I go to test during a sale?</li></ul><p>Thank you for going through this and any recommendations are helpful</p><p>Also, does it matter if I connect powe+ switch port &gt; 60W Power injector &gt; R850 PoE port?</p>]]>
        </description>
    </item>
    <item>
        <title>Wifi not working, received new ATT fiber gateway, but wifi to tv&#39;s, phones, ring not connecting</title>
        <link>https://community.ruckuswireless.com/en/discussion/115573/wifi-not-working-received-new-att-fiber-gateway-but-wifi-to-tvs-phones-ring-not-connecting</link>
        <pubDate>Fri, 11 Sep 2026 14:19:05 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>ryannandjames</dc:creator>
        <guid isPermaLink="false">115573@/en/discussions</guid>
        <description><![CDATA[<p>We have been in our Lennar home for 6 years and have never had many issues with our Ruckus. Wifi started being slow roughly 6 months ago, ATT replaced our gateway with one better suited for fiber. Now wifi is worse unless we are on the ATT gateway. We need the Ruckus and AP points to reach our tv's, phones, ring, etc in our home. Not a technical person and need help to get this fixed and don't know who to call.</p>]]>
        </description>
    </item>
    <item>
        <title>Could the ICX have booted into SPR (Routing Code) instead of SPS (Switching Code) after the power ou</title>
        <link>https://community.ruckuswireless.com/en/discussion/115572/could-the-icx-have-booted-into-spr-routing-code-instead-of-sps-switching-code-after-the-power-ou</link>
        <pubDate>Thu, 10 Sep 2026 18:53:09 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>los305</dc:creator>
        <guid isPermaLink="false">115572@/en/discussions</guid>
        <description><![CDATA[<p>I have a Lennar home with a <strong>RUCKUS ICX 7150-C12P</strong> switch and RUCKUS access points. Everything worked normally until a recent power outage.</p><p></p><p>Since the outage, the RUCKUS Wi-Fi has severe intermittent packet loss. Internet sometimes works normally and then becomes extremely slow or stops responding.</p><p></p><p>Troubleshooting already completed:</p><p></p><ul><li>AT&amp;T gateway connection is approximately <strong>1 Gbps up/down</strong>.</li><li>When connected directly to the <strong>AT&amp;T gateway Wi-Fi</strong>, I get <strong>0% packet loss</strong>.</li><li>Through the <strong>RUCKUS Wi-Fi</strong>, a 100-packet test to 8.8.8.8 showed <strong>59% packet loss</strong>.</li><li>More importantly, a 100-packet test directly to my local AT&amp;T gateway (<code spellcheck="false" tabindex="0">192.168.1.254</code>) showed <strong>81% packet loss</strong>, so the problem appears to be inside the local RUCKUS network.</li><li>Wi-Fi signal to the RUCKUS AP is strong (approximately <strong>-49 dBm</strong>).</li><li>I have already power-cycled the ICX/APs.</li><li>I also performed the ICX 7150-C12P physical recovery procedure by powering it off, holding Reset while reconnecting power, waiting for the LEDs to flash amber, and releasing Reset. The problem remains.</li><li>The ICX switch powers up normally and the APs come online.</li></ul><p></p><p><strong>Switch:</strong> RUCKUS ICX 7150-C12P / ICX7150-C12P-2X1G</p>]]>
        </description>
    </item>
    <item>
        <title>Significant internet delay from access points</title>
        <link>https://community.ruckuswireless.com/en/discussion/115569/significant-internet-delay-from-access-points</link>
        <pubDate>Tue, 08 Sep 2026 12:48:26 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>Nandrican</dc:creator>
        <guid isPermaLink="false">115569@/en/discussions</guid>
        <description><![CDATA[<p>I have the ICX 7150-C129 switch with 2 access points. 2 days ago I started experiencing significant delay in connection through the access points. I  confirmed I have adequate internet access to the switch and access points and power cycled both my router and the switch several times to no avail. This is impacting internet access and connection for ring cameras, baby monitor cameras and connected garage doors. Has anyone experienced anything similar? Any feedback on how to troubleshoot?</p>]]>
        </description>
    </item>
    <item>
        <title>Ruckus AP showing red PWR LED</title>
        <link>https://community.ruckuswireless.com/en/discussion/115543/ruckus-ap-showing-red-pwr-led</link>
        <pubDate>Sun, 23 Aug 2026 21:52:16 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>aaronbudig</dc:creator>
        <guid isPermaLink="false">115543@/en/discussions</guid>
        <description><![CDATA[<p>I’ve tried to power cycle the device, factory reset, etc. The AP does not ever transition to green LEDs like my other AP in my house. I live in a Lennar home and this system was installed as part of the house build. How can I get support fixing or replacing the device? </p>]]>
        </description>
    </item>
    <item>
        <title>Ruckus Wifi Access point is not working ...</title>
        <link>https://community.ruckuswireless.com/en/discussion/115556/ruckus-wifi-access-point-is-not-working</link>
        <pubDate>Sun, 30 Aug 2026 20:12:34 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>Rags</dc:creator>
        <guid isPermaLink="false">115556@/en/discussions</guid>
        <description><![CDATA[<p></p><p>Hi </p><p></p><p>We moved into the new house and I am unable to use the Ruckus Wifi System in the house. I am new this system and donot know how to reset this wifi access point. </p><p></p><p></p><p>Thanks Raghu</p>]]>
        </description>
    </item>
    <item>
        <title>Connecting R600 APs to Virtual Smart Zone</title>
        <link>https://community.ruckuswireless.com/en/discussion/115521/connecting-r600-aps-to-virtual-smart-zone</link>
        <pubDate>Wed, 19 Aug 2026 19:35:11 +0000</pubDate>
        <category>SmartZone and Virtual SmartZone</category>
        <dc:creator>kransom</dc:creator>
        <guid isPermaLink="false">115521@/en/discussions</guid>
        <description><![CDATA[<p>I am testing the virtual smart zone product to replace our legacy ZoneDirector3050. I will provide details below of testing. <br /></p><p>Subject: R600 AP unable to successfully join Virtual SmartZone 6.1.2 - ZD to SZ migration</p><p>--- Environment ---</p><p>Controller: Virtual SmartZone Essentials 6.1.2.0.1071 (KVM/Proxmox)<br />
Control Plane Software: 6.1.2.0.1018<br />
AP Zone Firmware: 5.2.2.0.2122 (AP Patch scg-ap-5.2.2.0-2122.patch applied)<br />
AP Zone Name: gclab-r600</p><p>Test AP: Ruckus R600</p><ul><li>MAC: F0:3E:90:32:8A:40</li><li>Serial: 171603502066</li><li>Current Firmware: 110.0.0.0.675 (SmartZone standalone)</li><li>IP: 192.168.29.101/24</li><li>Gateway: 192.168.29.1</li><li>Management VLAN: 29</li></ul><p>Network: AP is on VLAN 29 (192.168.29.0/24), vSZ control interface is on public subnet xxx.xxx.xxx.xxx/24. Inter-VLAN routing is confirmed working — AP can reach vSZ and vice versa.</p><p>Background: We are migrating from an end-of-life ZoneDirector 3050 managing 56 APs (50x R600, 3x R710, 3x T300). This is a test with a single R600 before production migration.</p><p>--- Attempt 1: ZD firmware AP connecting to vSZ (AP firmware 9.13.1.0.11) ---</p><ol><li>AP was running ZoneDirector firmware 9.13.1.0.11</li><li>Set controller IP via SSH: set scg ip xxx.xxx.xxx.xxx</li><li>AP discovered the vSZ and was approved</li><li>vSZ rejected the AP with event code 2003: "ZD-AP [F0:3E:90:32:8A:40] / [171603502066] model [R600] is not being upgraded with Virtual SmartZone AP firmware because of ACL setting."</li><li>This repeated continuously despite creating an AP registration rule for subnet 192.168.29.0/24 pointing to the legacy-r600 zone</li></ol><p>--- Attempt 2: After applying AP Patch and configuring lwapp2scg ---</p><ol><li>Applied AP patch scg-ap-5.2.2.0-2122.patch to the vSZ</li><li>Configured lwapp2scg policy to accept via CLI</li><li>Added AP MAC to lwapp2scg ACL</li><li>AP discovered, was approved, and connected (event code 312)</li><li>vSZ initiated ZD AP migration — event code 2001: "ZD-AP upgrading with Virtual SmartZone AP firmware version - [5.2.2.0.2064]"</li><li>AP lost heartbeat (event code 314) and disconnected (event code 303)</li><li>AP appeared to enter a boot loop — ping from monitoring station showed AP dropping off every ~60 seconds and returning, suggesting repeated reboot cycles</li><li>AP never successfully reconnected after firmware push</li></ol><p>--- Attempt 3: Pre-flashed SZ firmware on AP ---</p><ol><li>Factory reset the AP</li><li>Manually flashed AP with SmartZone standalone firmware 110.0.0.0.675 via AP web UI</li><li>Confirmed firmware via SSH: get version shows 110.0.0.0.675</li><li>Configured AP: IP 192.168.29.101, gateway 192.168.29.1, management VLAN 29</li><li>Set lwapp2scg policy to accept-all on vSZ</li><li>Disabled ap-cert-check on vSZ</li><li>Created new zone gclab-r600 with AP firmware 5.2.2.0.2122</li><li>Set controller via SSH: set scg ip xxx.xxx.xxx.xxx</li><li>AP state cycles between DISC_REQ_STATE and JOIN_REQ_STATE</li><li>Reached CONN_GET_ADDR_STATE once briefly, then fell back to DISC_REQ_STATE</li><li>AP never fully connects or appears as managed in vSZ</li><li>No events appearing in vSZ event log for this attempt</li></ol><p>--- vSZ Configuration ---</p><ul><li>Profile: Essentials (single NIC)</li><li>lwapp2scg policy: accept-all</li><li>AP certificate check: disabled</li><li>L3 ACL: default-deny with permit rules for xxx.xxx.xxx.xxx/24 (DNS), 192.168.29.0/24 (AP network), plus DNS (port 53) and DHCP (port 67)</li><li>AP auto-approval: disabled</li><li>AP registration: rule removed (relying on lwapp2scg accept-all)</li></ul><p>--- Questions ---</p><ol><li>Is there a firmware compatibility issue between AP firmware 110.0.0.0.675 and vSZ 6.1.2? Should the AP be running a specific 5.2.2.x standalone image to match the zone firmware?</li><li>What is the correct procedure to migrate an R600 from ZoneDirector firmware to SmartZone on vSZ 6.1.2?</li><li>Are there specific ports beyond TCP 9100 that need to be open between the AP and vSZ for the join process to complete?</li><li>Is the R600 fully supported on vSZ Essentials 6.1.2, or only on specific earlier versions?</li></ol><p>Any guidance on getting this R600 to successfully join the vSZ would be greatly appreciated. We need to validate R600 compatibility before proceeding with the full production migration of 56 APs.</p>]]>
        </description>
    </item>
    <item>
        <title>New home w/ 510 ruckus system.  How do I connect to new wifi network?</title>
        <link>https://community.ruckuswireless.com/en/discussion/115551/new-home-w-510-ruckus-system-how-do-i-connect-to-new-wifi-network</link>
        <pubDate>Fri, 28 Aug 2026 04:21:32 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>spillman242421</dc:creator>
        <guid isPermaLink="false">115551@/en/discussions</guid>
        <description><![CDATA[<p>just bought a new home where Ruckus 510 is already established.  Setup new wifi with xfinity.  How do I reset or troubleshoot ruckus system so I can connect access points via new wifi network?</p>]]>
        </description>
    </item>
    <item>
        <title>Unleashed is broken when use R770 as master with 370 members.</title>
        <link>https://community.ruckuswireless.com/en/discussion/115561/unleashed-is-broken-when-use-r770-as-master-with-370-members</link>
        <pubDate>Wed, 02 Sep 2026 04:00:01 +0000</pubDate>
        <category>Unleashed</category>
        <dc:creator>SmallPotato</dc:creator>
        <guid isPermaLink="false">115561@/en/discussions</guid>
        <description><![CDATA[<p>Hi all,</p><p></p><p>We found a tricky issue. </p><p></p><p>We were using 2 x R770 as the 1st and 2nd preferred masters, not in dedicated mode. </p><p></p><p>About 35 member APs (R370) here. If we created more than one SSID (the default one), the R370 rebooted and looped in "Kernel panic".</p><p></p><p>Moreover, if we disconnect both R770s from the PoE switch, no R370 became as a new master of Unleashed, and the whole WIFI was dead.</p><p></p><p></p><p>WE are using 200.19.7.112.238.</p><p></p><p>If we reset all APs and only put 370 to online as master and member, everything is working well.</p><p></p><p>Does anyone know how we can fix this?</p>]]>
        </description>
    </item>
    <item>
        <title>Ruckus R550 Configuration issue</title>
        <link>https://community.ruckuswireless.com/en/discussion/115547/ruckus-r550-configuration-issue</link>
        <pubDate>Tue, 25 Aug 2026 13:20:09 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>ruckusabhimanyu</dc:creator>
        <guid isPermaLink="false">115547@/en/discussions</guid>
        <description><![CDATA[<p>Dear team,</p><p>I have Purchase new Ruckus R550 and i try to configure 1st i configure that put poe cable from poe switch to Ap POE Port and from that Same Poe Switch to my laptop and i put one from ip from the same ip segment of the ruckus that is 192.168.0.122 and gateway 192.168.0.1 but it was not pinging 192.168.0.1 the default ip after that i was tryint to connect its Configure.Me. it was asking password and i checked behind there is no SSID-Password Mention it was frusted with this AP that no able to ping on lan and dont know the default ssid password can u please help me in that</p>]]>
        </description>
    </item>
    <item>
        <title>No lights AP</title>
        <link>https://community.ruckuswireless.com/en/discussion/115531/no-lights-ap</link>
        <pubDate>Thu, 20 Aug 2026 21:36:58 +0000</pubDate>
        <category>Access Points - Indoor and Outdoor</category>
        <dc:creator>Swampthang_2000</dc:creator>
        <guid isPermaLink="false">115531@/en/discussions</guid>
        <description><![CDATA[<p>R510 Access has lights but no light to the PoE connector at the access point or the AP? How do I get connectivity? Thank you.</p>]]>
        </description>
    </item>
    <item>
        <title>Access Port No Worky</title>
        <link>https://community.ruckuswireless.com/en/discussion/115532/access-port-no-worky</link>
        <pubDate>Fri, 21 Aug 2026 00:55:18 +0000</pubDate>
        <category>Access Points - Indoor and Outdoor</category>
        <dc:creator>Swampthang_2000</dc:creator>
        <guid isPermaLink="false">115532@/en/discussions</guid>
        <description><![CDATA[<p>IcX 7150 Switch to R510 Access Point No green light. PoE connector at R510 AP no lights connected. 7150 Switch not green either. Unit power up. Reset non functional. The access point believed to be nonfunctional. How to proceed. Break. </p>]]>
        </description>
    </item>
    <item>
        <title>NO Power on Access Points and ICX-7150-C12P Switch with Yellow and GREEN lights on SYST &amp; PWR</title>
        <link>https://community.ruckuswireless.com/en/discussion/110518/no-power-on-access-points-and-icx-7150-c12p-switch-with-yellow-and-green-lights-on-syst-pwr</link>
        <pubDate>Fri, 24 Oct 2025 14:47:49 +0000</pubDate>
        <category>RUCKUS Support for Lennar Homes</category>
        <dc:creator>Afofrancozola</dc:creator>
        <guid isPermaLink="false">110518@/en/discussions</guid>
        <description><![CDATA[<p><span>Hi, My switch is ICX 7150-C12P. I experienced a power outage and on restoration of power, the switch is showing Amber/Orange light on "SYST" and Green light on "PWR" &amp; NO lights on the 2 access points. </span></p><p><span>I have tried to repower the switch and doing a reset with the reset button but the issue still persist.</span></p><p><span>Kindly assist.&nbsp;</span></p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/16498iA0D4EF13867C5D8A/image.jpg" role="button" title="Afofrancozola_0-1761317211462.jpeg" alt="Afofrancozola_0-1761317211462.jpeg" /></span><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/16499iCA20D20C90368D02/image.jpg" role="button" title="Afofrancozola_1-1761317227712.jpeg" alt="Afofrancozola_1-1761317227712.jpeg" /></span><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/16500i15299B3D6C5A31FB/image.jpg" role="button" title="Afofrancozola_2-1761317254671.jpeg" alt="Afofrancozola_2-1761317254671.jpeg" /></span></p><p>&nbsp;</p>]]>
        </description>
    </item>
    <item>
        <title>v/SZ - High retransmission rates | How can I tell in Wireshark if a frame is retransmitted?</title>
        <link>https://community.ruckuswireless.com/en/discussion/57731/v-sz-high-retransmission-rates-how-can-i-tell-in-wireshark-if-a-frame-is-retransmitted</link>
        <pubDate>Thu, 27 Apr 2023 19:54:50 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>Orlando_Elias</dc:creator>
        <guid isPermaLink="false">57731@/en/discussions</guid>
        <description><![CDATA[<p>When troubleshooting performance issues in a wireless network, taking care of the different&nbsp;<u>frame flows</u> over the air, will help us mitigate the <strong>majority</strong> of the issues.</p><p>One of the frame's flows that affect the overall performance of the wireless network is the <strong>retransmission rate</strong>&nbsp;(a frame is retransmitted when the delivery was not acknowledged or it's reported as corrupted), excessive frame retransmission forces the client-AP to negotiate lower <strong>data rates</strong> for the communications, causing greater <strong>delay</strong>&nbsp;and higher <strong>airtime utilization</strong>.</p><p><span style="font-size: large;"><u>How can I tell if the retransmission rate is&nbsp;</u></span><span style="font-size: large;"><u>high?</u></span></p><ul><li><strong>From the AP support log.&nbsp;</strong></li></ul><p>&nbsp;</p><pre><code>----------------------- Host/Target Tx Stats ----------------------
RKS stats magic: cafe0001
421200 MSDUs success(msdus_success)
4582766 MPDUs success(mpdus_success)
632 tx completions delivered(comp_delivered)
7828618 Tx HW queued(hw_queued)
7828618 Tx HW reaped(hw_reaped)
188 Tx MAC underrun(underrun)
1424910 Tx HW paused(hw_paused)
3290623 Tx seq posted(seq_posted)
740 Tx mu seq posted(mu_seq_posted)
72066 Tx seq failed(seq_failed_queueing)
1342284 MPDUs requed(mpdu_requed)
5925004 MPDUs tried(mpdu_tried)
2748 MPDUs sw_flush(mpdus_sw_flush)
19468 MPDUs truncated(mpdus_truncated)
1324450 MPDUs block ack_failed(mpdus_ack_failed)
568 MPDUs expired(mpdus_expired)
2654643 excess retries(tx_xretry) ------------------------&gt; very high 'tx_xretry'
902025741 sched self trig(self_triggers)
116763 ampdu retry failed(sw_retry_failure)</code></pre><p>&nbsp;</p><p>Excessive retries can be directly related to PHY errors:</p><p>&nbsp;</p><pre><code>------------ Host/Tgt Rx Stats ------------
34066065 PPDUs Rx from HW(htt.ppdu_recvd)
31502324 MPDUs Rx OK(htt.mpdu_cnt_fcs_ok)
2602746 MPDUs Rx Err(htt.mpdu_cnt_fcs_err)
2696712 MPDUs dropped in FW ring(htt.fw_ring_mpdu_drop)
2599042 local mgmt Rx(pdev_local_buffer_stats.local_reaped)
63379830 Rx PHY errors(rx_phyerr) ---------------------------------&gt; very high 'rx_phyerr'
34073621 Rx MPDU errors(rxdesc_err_att)
2599027 Rx MPDU FCS errors(rxdesc_err_fcs)</code></pre><p>&nbsp;</p><ul><li><strong>From Wireshark.</strong></li></ul><p>Collect a packet capture on the specified wireless interface of the AP by selecting the AP and then click 'More'&gt;Packet Capture.</p><p>In the Packet capure page, select the appropiae radio you want to monitor and the option 'save to file'. Click 'Start' to begin to capture and then 'Stop' to stop the capture. When the file is ready, the 'Download' option will appear for you to download the file.</p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/6087i9563654473ED8672/image.png" width="558" height="321" role="button" title="Orlando_Elias_1-1682624313109.png" alt="Orlando_Elias_1-1682624313109.png" /></span></p><p>Once you have got the pcap file, then you can look for the 'Retry' flag on the 802.11 information of the frame.</p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/6088i00B1E3DC45D88191/image.png" width="735" height="215" role="button" title="Orlando_Elias_2-1682624538940.png" alt="Orlando_Elias_2-1682624538940.png" /></span></p><p>Right click and 'Apply as Filter&gt;Selected to fiter out the all the retransmitted frames:</p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/6089iF78FA7B4B76E05B9/image.png" width="738" height="382" role="button" title="Orlando_Elias_3-1682624676297.png" alt="Orlando_Elias_3-1682624676297.png" /></span></p><p>This is the wireshark filter for the retry flag in the frames.</p><p>&nbsp;</p><pre><code>wlan.fc.retry == 1</code></pre><p>&nbsp;</p><p>Check the total amount of packets in the file vs. the number of packets displayed and then you will have a meassure of the retransmission rate of the packets captured in the specific lapse. In our example, we have a 10% of retransmission rate.</p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/6090iE1AD2286A864B27D/image.png" role="button" title="Orlando_Elias_4-1682624837573.png" alt="Orlando_Elias_4-1682624837573.png" /></span></p><p>We can see, for our example, the probe response from the AP was retrasmitted many times, which means&nbsp; -most likely- the client never received it. This could have ended on a client unable to connect to the wireless network or maybe just connecting to the next available AP -no usually the closest one-.</p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/6092iA60DAE98C13C874A/image.png" width="765" height="173" role="button" title="Orlando_Elias_6-1682625159080.png" alt="Orlando_Elias_6-1682625159080.png" /></span></p><p><u>What are the causes of high retransmission rates and how can I address them?</u></p><ol><li><strong>non-wifi interference</strong>. Identify the source of the interference and shut it down -if it's under your administration- or relocate the AP if the interference cannot be disabled.</li><li><strong>wifi interference (co-channel or adjacent channel).</strong> Review the channel plan and choose a channel selection option that best services your enviroment.</li><li><strong>hidden nodes.</strong> Reduce the cell size or relocate the AP.</li><li><strong>poor signal to noise ratio.</strong> Identify the sources of the most noise signals and reduce/disable them -if it's under you administration- or relocate the AP if the interence cannot be reduced.</li><li><strong>bad coverage configuration.</strong> Relocate the APs, add more APs or increase the cell size.</li></ol>]]>
        </description>
    </item>
    <item>
        <title>Ruckus AP LED indicator meaning</title>
        <link>https://community.ruckuswireless.com/en/discussion/67848/ruckus-ap-led-indicator-meaning</link>
        <pubDate>Tue, 12 Sep 2023 18:22:12 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>MariaC862</dc:creator>
        <guid isPermaLink="false">67848@/en/discussions</guid>
        <description><![CDATA[<p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">In this article, we will delve into the meaning behind these LED indicators and explain the behaviors they may exhibit. The LED lights on Ruckus access points (APs) play an important role in providing information about the AP's current status. Whether during the installation process or when troubleshooting, understanding these LED indicators is essential for:</span></p><ul><li><span style="font-size: medium; font-family: arial,helvetica,sans-serif;"><span>Network connectivity issues</span></span></li><li><span style="font-size: medium; font-family: arial,helvetica,sans-serif;"><span>Master AP election problems&nbsp;</span></span></li><li><span style="font-size: medium; font-family: arial,helvetica,sans-serif;"><span>Potential hardware failures</span></span></li><li><span style="font-size: medium; font-family: arial,helvetica,sans-serif;"><span>Assessing controller connection status&nbsp;</span></span></li></ul><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">It's important to note that the presence and functionality of LED lights on a Ruckus AP can vary depending on the specific model and series. However, most Ruckus APs feature the following five LED indicators: PWR, CTL, AIR, 2.4G, and 5G.</span></p><p><strong><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">PWR (Power Indicator):</span></strong></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Solid RED: Bootup in progress.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Flashing Green: AP firmware image booted. No routable IP received or assigned.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Solid Green: Routable IP address received.</span></p><p><strong><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">CTL/DIR (Control/Direction Indicator):</span></strong></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Off: AP is a RUCKUS Unleashed member AP.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Slowly Flashing Green (every 2 sec): RUCKUS Unleashed Master AP discovery in progress.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Fast Flashing Green (twice a sec): Receiving configuration or image upgrade.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Solid Green: AP is the RUCKUS Unleashed Master.</span></p><p><strong><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">AIR (Mesh indicator:)</span></strong></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Off: AP is operating in standalone or Root or non-Mesh AP&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Solid Green: AP is functioning as Mesh AP (MAP)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Blinking Solid Green (2 Hz): AP is functioning as Mesh AP (MAP)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Blinking Solid Green (0.5 Hz): &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p><p><strong><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">2.4G (WLAN Service Indicator):</span></strong></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Off: The WLAN service is down.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Green: The WLAN is up, and at least one client is associated.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Amber: The WLAN is up, but no clients are associated.</span></p><p><strong><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">5G (WLAN Service and Mesh Downlink Indicator):</span></strong></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Off: The WLAN service is down.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Green: The WLAN is up, and at least one client is associated. No downlink MAPs are connected.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Slow Flashing Green (one flash every two seconds): The WLAN is up, and at least one downlink MAP is connected. No clients are associated.</span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">Fast Flashing Green (two flashes every second): The WLAN is up, at least one downlink MAP is connected, and at least one client is associated.</span></p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/8748iB170A1BDD7ECDEF4/image.png" role="button" title="image.png" alt="image.png" /></span><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/8749i8110A8686BAD412F/image.png" role="button" title="image.png" alt="image.png" /></span><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/8750i67FC85E55E3E37BE/image.png" role="button" title="image.png" alt="image.png" /></span></p><p><span style="font-size: medium; font-family: arial,helvetica,sans-serif;">More info about the LEDs can be found here: <a href="https://docs.commscope.com/bundle/unleashed-200.10-troublshootingref/page/GUID-738984DA-2A47-4E71-A690-B6DF9023AA50.html" target="_blank" rel="noopener noreferrer nofollow">https://docs.commscope.com/bundle/unleashed-200.10-troublshootingref/page/GUID-738984DA-2A47-4E71-A690-B6DF9023AA50.html</a></span></p>]]>
        </description>
    </item>
    <item>
        <title>Wireless Client Troubleshooting using the Unleashed Diagnostic Tools</title>
        <link>https://community.ruckuswireless.com/en/discussion/99518/wireless-client-troubleshooting-using-the-unleashed-diagnostic-tools</link>
        <pubDate>Fri, 15 Nov 2024 20:41:56 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>Vásquez_Fer</dc:creator>
        <guid isPermaLink="false">99518@/en/discussions</guid>
        <description><![CDATA[<p>This is a brief demonstration of how to use Unleashed tools to troubleshoot a basic connectivity issue on the network on end devices.</p>
<h1 id="toc-hId-481769755"><span style="font-size: medium;">1. Client Connection Troubleshooting</span></h1>
<p>Link as reference <a href="https://docs.commscope.com/bundle/unleashed-200.16-troublshootingref/page/GUID-5BBF52D0-939D-416F-B696-FABB12AC5EE9.html" target="_blank" rel="noopener noreferrer nofollow">https://docs.commscope.com/bundle/unleashed-200.16-troublshootingref/page/GUID-5BBF52D0-939D-416F-B696-FABB12AC5EE9.html</a></p>
<p>This is a demonstration for the client troubleshooting.</p>
<p>Select Clients, and then click the Troubleshooting button.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14384i944C24192588032A/image.png" role="button" title="Vsquez_Fer_0-1731702964233.png" alt="Vsquez_Fer_0-1731702964233.png" /></span></p>
<p><strong>Figure 1</strong>: Clients Tab</p>
<p>Here, we can enter the MAC address of the client device in the specified format to begin troubleshooting process. If the device is already connected to the network, simply click on it, and the troubleshooting process will begin automatically.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14383i8E91B87CA7BB8C55/image.png" role="button" title="Vsquez_Fer_1-1731702964235.png" alt="Vsquez_Fer_1-1731702964235.png" /></span></p>
<p><strong>Figure 2</strong>: Troubleshooting button.</p>
<p>Identify the MAC Address: Obtain the MAC address of the client device you want to analyze. Ensure you have this information handy as it will be used to filter the capture.</p>
<p>Input the MAC address of the client device into the designated filter.</p>
<p>Click the Start button to begin the troubleshooting.</p>
<p>In this demonstration I will use the following Mac-address for one of my Wireless clients <strong>62:b6:b1:eb:09:89</strong></p>
<p><strong>&nbsp;</strong></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14382iB177243515022152/image.png" role="button" title="Vsquez_Fer_2-1731702964236.png" alt="Vsquez_Fer_2-1731702964236.png" /></span></p>
<p><strong>Figure 3</strong>: Start Troubleshooting Process</p>
<p>Once you click Start, no data will be displayed initially because the device has not yet connected to the network or attempted to connect to any of the AP's SSIDs.</p>
<p>&nbsp;</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14387i06AFDE95A4BCDE4D/image.png" role="button" title="Vsquez_Fer_3-1731702964238.png" alt="Vsquez_Fer_3-1731702964238.png" /></span></p>
<p><strong>Figure 4</strong>: Troubleshooting Process</p>
<p>In this example, I will attempt to connect my end client to the SSID of the Access Point and intentionally use an incorrect password.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14386i11DEED0F38ED2C72/image.png" role="button" title="Vsquez_Fer_4-1731702964240.png" alt="Vsquez_Fer_4-1731702964240.png" /></span></p>
<p><strong>Figure 5</strong>: Initial Packet Capture View</p>
<p>First, we will analyze what we are observing firsthand during this test. We can identify which Access Point the end device is connecting to, the band it is using (whether 2.4 GHz or 5 GHz), and in this case, it is 5 GHz on channel 157. Additionally, we can observe the environmental SNR and the timestamp of the events according to the Access Point's log.</p>
<p>Now we will analyze the packets exchanged between the end client and the Access Point.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14385iC8604DBB1B8BD81F/image.png" role="button" title="Vsquez_Fer_5-1731702964245.png" alt="Vsquez_Fer_5-1731702964245.png" /></span></p>
<p><strong>Figure 6</strong>: Analysis of Packet Exchange Between Client and Access Point</p>
<p>The client device initiates the connection by sending authentication and association requests, which the AP responds to. During the 4-way handshake, each attempt fails repeatedly, suggesting there is an issue. After multiple failures, the AP deauthenticates the client, ending the connection attempt.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14389i1D7A500539B8383C/image.png" role="button" title="Vsquez_Fer_6-1731702964249.png" alt="Vsquez_Fer_6-1731702964249.png" /></span></p>
<p><strong>Figure 7</strong>: Final Analysis - Client Failed Handshake</p>
<p>When the Information button on the error is pressed, it often provides a suggested error code and status, which can also be copied for reference. In this example, the tool indicates an "invalid passphrase" error, accurately reflecting the intentional use of an incorrect password for testing purposes. This tool is highly effective for troubleshooting connectivity issues, as it provides insights into client behavior during the authentication process, in roaming scenarios, and across various other network situations.</p>
<h1 id="toc-hId-1369273436"><span style="font-size: medium;">2.&nbsp;&nbsp;&nbsp; Capturing Remote Packets</span></h1>
<p>Remote packet capture enables one or more APs to operate in packet sniffer mode, allowing them to capture wireless packets on the network. These packets can either be saved locally on the device or streamed in real time to a packet analysis tool, such as Wireshark, for detailed inspection and troubleshooting. This feature is valuable for diagnosing connectivity issues and monitoring network performance by analyzing the captured packet data.</p>
<p>Link as reference <a href="https://docs.commscope.com/bundle/unleashed-200.16-onlinehelp/page/GUID-FE747C7C-8F63-409B-A423-63F898CA8331.html" target="_blank" rel="noopener noreferrer nofollow">https://docs.commscope.com/bundle/unleashed-200.16-onlinehelp/page/GUID-FE747C7C-8F63-409B-A423-63F898CA8331.html</a></p>
<p>Go to Admin &amp; Services &gt; Administration &gt; Diagnostics &gt; Packet Capture.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14390iD68E372CE52834B5/image.png" role="button" title="Vsquez_Fer_7-1731702964252.png" alt="Vsquez_Fer_7-1731702964252.png" /></span></p>
<p><strong>Figure 8</strong>: Packet capture tab</p>
<p>In this section, we will find the Access Points in our network, along with their model, device name, and corresponding IP address.</p>
<p>To troubleshoot the client connectivity issue, select the desired APs, and then choose Add to Capture. This action will move the APs to the Capture APs table.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14388i03419BF1167819EC/image.png" role="button" title="Vsquez_Fer_8-1731702964254.png" alt="Vsquez_Fer_8-1731702964254.png" /></span></p>
<p><strong>Figure 9</strong>: Selecting the Access Point for the Packet Capture</p>
<p>For Radio, select either 2.4 GHz or 5 GHz/6 GHz. In this case, since we are working with a 5 GHz connection, select the 5 GHz option.</p>
<p>You can Select Local Mode or Streaming Mode as the capture mode:</p>
<p>+To capture a limited snapshot on each AP, select <strong>Local Mode</strong>.<br />+To stream the captured packets directly to Wireshark for real-time analysis, select <strong>Streaming Mode</strong>.</p>
<p>In this example we are going to select <strong>Local Mode</strong>.</p>
<p>In this example, since the MAC address of the problematic device is known, enter it to filter the capture data specifically for that client. Click <strong>Start</strong> to begin capturing packets. At this stage, reproduce the issue. Once the issue has been reproduced, click <strong>Stop</strong> to end the capture.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14391i265B55612419D493/image.png" role="button" title="Vsquez_Fer_9-1731702964255.png" alt="Vsquez_Fer_9-1731702964255.png" /></span></p>
<p><strong>Figure 10: </strong>Initiate the Packet Capture</p>
<p>Then click <strong>Save</strong> to store the packet capture as a local file for later analysis.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/14392iCF983697C50F7522/image.png" role="button" title="Vsquez_Fer_10-1731702964258.png" alt="Vsquez_Fer_10-1731702964258.png" /></span></p>
<p><strong>Figure 11</strong>&nbsp;: Downloaded PCAP from the Unlashed UI.</p>
<p>Once the file is downloaded, it will be saved in the <strong>Downloads</strong> folder. Extract the contents, and you’ll find folders containing the PCAP files. These files include detailed information on the association process for the end client , which will help you investigating if there is any incidents.</p>
<p>Note : Remember to remove the AP from the capture list and disable packet capture after completing this process.</p>
<p>By analyzing the packet exchange during the connection process, you can pinpoint where the failure occurs and take appropriate corrective actions. This method provides valuable insights into the interaction between client devices and APs in real time.</p>
<p>&nbsp;</p>]]>
        </description>
    </item>
    <item>
        <title>Unleashed Overview</title>
        <link>https://community.ruckuswireless.com/en/discussion/76913/unleashed-overview</link>
        <pubDate>Wed, 13 Mar 2024 15:12:55 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>Vásquez_Fer</dc:creator>
        <guid isPermaLink="false">76913@/en/discussions</guid>
        <description><![CDATA[<p>This provides a concise summary of the Unleashed network's operation, outlining essential requirements and handy commands for configuration.</p>
<p><strong>Unleashed Overview</strong></p>
<p><span>In an Unleashed network, a RUCKUS Unleashed 'Master' Access Point acts similarly to a controller, managing all control functions. These settings are then propagated to the other APs in the network. If the Master AP go offline, a 'Member' AP will automatically take on the role of the Unleashed Master, assuming control and maintaining network operations.</span></p>
<p><strong>Unleashed Support</strong></p>
<p>-Bridge mode 128 APs and 2,048 clients.</p>
<p>-Gateway mode supports up to 25 APs and 512 clients.</p>
<p>-<a href="https://docs.commscope.com/bundle/unleashed-200.15-onlinehelp/page/GUID-AB82AF31-39CA-48EA-9486-B0B8AFE3C55E.html" target="_blank" rel="noopener noreferrer nofollow">Dedicated Master </a></p>
<p><a href="https://docs.commscope.com/bundle/unleashed-200.15-onlinehelp/page/GUID-586B59E7-7349-4B65-BE81-FA220DC0F772.html" target="_blank" rel="noopener noreferrer nofollow">Overview Limitations from Zone Director </a></p>
<p>-IPv6 is not supported.</p>
<p>-No interface to communicate with SmartCell Insight analytics engine or SPoT location.</p>
<p>-No Northbound Interface to pass client authentication responsibility to an external entity.</p>
<p>-No WLAN groups.</p>
<p><strong>What are the necessary conditions or prerequisites for an access point to successfully connect to an existing Unleashed network?</strong></p>
<p>Connect the Member Access Point (AP) to the network, ensuring it is on the same VLAN as the Master AP. Upon powering up, the Member AP will engage in an election to determine if a Master already exists. It's important that the Member AP either matches or has a lower firmware version than the Master.</p>
<p>Additionally, it must be able to ping the Master AP and share the same country code setting.</p>
<p><strong> Commands to check if a member Access Point is not joining to the Unleashed Network.</strong></p>
<ul>
<li>&nbsp;ping &lt; Master_AP&gt;</li>
<li>&nbsp;get version&nbsp;</li>
<li>&nbsp;get boarddata : Display hardware version and system board information</li>
<li>&nbsp;get discovery-agent: Check if LLWAP protocol is enable.</li>
<li>get countrycode :</li>
<li>get director : show Master AP information.</li>
<li>get election: shows the status of all Unleashed APs</li>
<li>get syslog log</li>
</ul>
<p>The same information can be collected on the Master AP.</p>
<ul>
<li>Ping &lt;Member_IP&gt;</li>
<li>get version&nbsp;</li>
<li>get countrycode&nbsp;</li>
<li>get boarddata&nbsp;</li>
<li>get election&nbsp;</li>
</ul>
<p>Ruckus CLI on unleashed when SSH to the Access Points.</p>
<p>The '<strong>ruckus&gt;</strong>' CLI prompt indicates you are logged into the 'Master' Access Point. From here, you can navigate through various configuration modes to manage settings and preferences.</p>
<p><strong> Enable:</strong></p>
<p><strong> ruckus#</strong></p>
<p>Under enable mode we can go to different modes example:</p>
<p><strong>ap-mode</strong>: Note under this mode you can run set-get commands.</p>
<p><strong>ruckus(ap-mode)#</strong></p>
<p>&nbsp;</p>
<p><strong> Config</strong></p>
<p><strong> ruckus(config)# </strong></p>
<p>Under config there are some different modes</p>
<p>+<strong>Admin: </strong></p>
<p>ruckus(config-admin)#</p>
<p>+<strong>System:</strong></p>
<p>ruckus(config-sys)#</p>
<p>+<strong>Using the Mac-address of the AP</strong>:&nbsp;</p>
<p>ruckus(config)# ap d4:bd:4f:01:bc:10<br />The AP 'd4:bd:4f:01:bc:10' has been loaded. To save the AP, type 'end' or 'exit'.<br />ruckus(config-ap)#</p>
<p>The '<strong>rkscli</strong>:' prompt indicates that you are logged into a 'Member' Access Point. In this CLI, you can execute 'get' or 'set' commands to retrieve or configure the Access Point settings. For example:</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/11030iFF915AAB6400D6CD/image.png" role="button" title="Vsquez_Fer_0-1710342089483.png" alt="Vsquez_Fer_0-1710342089483.png" /></span></p>
<p>Best Regards&nbsp;</p>
<p>Fernando Vasquez&nbsp;</p>]]>
        </description>
    </item>
    <item>
        <title>802.1x authentication with NPS policies- Windows Server 2016</title>
        <link>https://community.ruckuswireless.com/en/discussion/62773/802-1x-authentication-with-nps-policies-windows-server-2016</link>
        <pubDate>Wed, 12 Jul 2023 16:55:45 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>Vásquez_Fer</dc:creator>
        <guid isPermaLink="false">62773@/en/discussions</guid>
        <description><![CDATA[<p>This a demo for essential configuration steps to authenticate wireless clients using 802.1x-&nbsp;Unleashed by configuring NPs policy on a Windows server.</p>
<p>1- Make sure the server has the necessary basic features installed.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7442i266F973DDA9828F1/image.png" role="button" title="Vsquez_Fer_0-1689180226617.png" alt="Vsquez_Fer_0-1689180226617.png" /></span></p>
<p>&nbsp;</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7444i1EB72218DE29BF47/image.png" role="button" title="Vsquez_Fer_1-1689180226621.png" alt="Vsquez_Fer_1-1689180226621.png" /></span></p>
<p>&nbsp;</p>
<p>2-Navigate to the Network Policy Server tab, access NPS (local), and choose the 'Radius server for 802.1x' option for both wireless and wired connections. Finally, select 'Configure 802.1x'</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7443i18FF0896126AE2AC/image.png" role="button" title="Vsquez_Fer_2-1689180226625.png" alt="Vsquez_Fer_2-1689180226625.png" /></span></p>
<p>3-In this step, select 'Secure wireless connections' and customize the policy name to your preference. In this case, append 'DEMO' at the end of the policy name.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7447i7D7A72E8CAB9C3FC/image.png" role="button" title="Vsquez_Fer_3-1689180226627.png" alt="Vsquez_Fer_3-1689180226627.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7445i2B8BA03EF1D19FE6/image.png" role="button" title="Vsquez_Fer_4-1689180226629.png" alt="Vsquez_Fer_4-1689180226629.png" /></span></p>
<p>4-In this step, you need to configure the Radius Client by providing a friendly name, entering the IP address of the master Access Point, and optionally setting a password or using a password generation tool. Remember to save this configuration as it will be used in <strong>Step 9</strong>.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7446iE4737D4B39B40F49/image.png" role="button" title="Vsquez_Fer_5-1689180226630.png" alt="Vsquez_Fer_5-1689180226630.png" /></span></p>
<p>5-In this step, choose 'Microsoft Protect EAP (PEAP)' as the network access method</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7448iA512A27F8F7B14F4/image.png" role="button" title="Vsquez_Fer_6-1689180226631.png" alt="Vsquez_Fer_6-1689180226631.png" /></span></p>
<p>6- Next, leave the remaining options at their default settings, and conclude the configuration by clicking on the 'Finish' button.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7450iC05E2D85C92F3D0E/image.png" role="button" title="Vsquez_Fer_7-1689180226632.png" alt="Vsquez_Fer_7-1689180226632.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7449iAB43BF184F9BB130/image.png" role="button" title="Vsquez_Fer_8-1689180226633.png" alt="Vsquez_Fer_8-1689180226633.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7452i38BD3F67CC0A0C1D/image.png" role="button" title="Vsquez_Fer_9-1689180226635.png" alt="Vsquez_Fer_9-1689180226635.png" /></span></p>
<p>7-<strong>Configure the “Connection Request Policies”</strong></p>
<p>To configure the connection request policy, navigate to the 'Policies' section. Then, access the 'Connection Request Policy' folder and locate the policy is created with the same name. Double-click on it to access its properties. In the 'Properties' window, navigate to the 'Conditions' tab. Remove the 'Current' condition and any others if present. Add the 'Time' condition and select 'Permit all time'. Finally, click 'Apply' and then 'OK' to save the changes.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7451i4C994A9B3F0252B7/image.png" role="button" title="Vsquez_Fer_10-1689180226637.png" alt="Vsquez_Fer_10-1689180226637.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7453i057646EC13AF1A9E/image.png" role="button" title="Vsquez_Fer_11-1689180226638.png" alt="Vsquez_Fer_11-1689180226638.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7454i05E4FFB11E31123A/image.png" role="button" title="Vsquez_Fer_12-1689180226640.png" alt="Vsquez_Fer_12-1689180226640.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7456iE2EB871A3DB786D0/image.png" role="button" title="Vsquez_Fer_13-1689180226642.png" alt="Vsquez_Fer_13-1689180226642.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7455i55D2B8B57AD422BB/image.png" role="button" title="Vsquez_Fer_14-1689180226643.png" alt="Vsquez_Fer_14-1689180226643.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7458i6F6091DDA78786B7/image.png" role="button" title="Vsquez_Fer_15-1689180226644.png" alt="Vsquez_Fer_15-1689180226644.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7457i5E0291338CCBF9A6/image.png" role="button" title="Vsquez_Fer_16-1689180226648.png" alt="Vsquez_Fer_16-1689180226648.png" /></span></p>
<p>8-<strong>Configure Network policies</strong></p>
<p>To configure the Network Policies access to “Network Policy” folder and locate the policy is created on the folder and locate the policy is created with the same name. Double-click on it to access its properties. In the 'Properties' window for this example, I choose to ignore the user properties dial and proceed to the 'Conditions' section. Here, I add the 'User Groups' option to use the Active Directory users.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7459iE4AD26E5C61E4EC0/image.png" role="button" title="Vsquez_Fer_17-1689180226652.png" alt="Vsquez_Fer_17-1689180226652.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7462i374E86575ECF8FC2/image.png" role="button" title="Vsquez_Fer_18-1689180226654.png" alt="Vsquez_Fer_18-1689180226654.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7461i4C8914CB6E49D0B7/image.png" role="button" title="Vsquez_Fer_19-1689180226655.png" alt="Vsquez_Fer_19-1689180226655.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7460iB594CD61F70900AC/image.png" role="button" title="Vsquez_Fer_20-1689180226658.png" alt="Vsquez_Fer_20-1689180226658.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7465i4217BA700C93006F/image.png" role="button" title="Vsquez_Fer_21-1689180226661.png" alt="Vsquez_Fer_21-1689180226661.png" /></span></p>
<p>In this part, you have the option to either use an existing group and its users or create a new group along with its users.</p>
<p>Optional step</p>
<p><strong>How to create a group and users </strong></p>
<p>Open Active Directory Users and Computers, then select the domain used in this case, <em data-start="152" data-end="165">cslab12.com</em>. Navigate to the 'Users' folder, right-click on it, and choose 'New' &gt; 'Group.' Finally, enter the required information</p>
<p>Reference :&nbsp;<a href="https://docs.commscope.com/bundle/sz-700-accessservicesguide-sz300vsz/page/GUID-D9E129C3-A6AF-433F-ABA3-81BD8A1CCA91.html" target="_blank" rel="noopener noreferrer nofollow">https://docs.commscope.com/bundle/sz-700-accessservicesguide-sz300vsz/page/GUID-D9E129C3-A6AF-433F-ABA3-81BD8A1CCA91.html</a></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7463i01545088D5DB6086/image.png" role="button" title="Vsquez_Fer_22-1689180226665.png" alt="Vsquez_Fer_22-1689180226665.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7464iEA41220098A50322/image.png" role="button" title="Vsquez_Fer_23-1689180226666.png" alt="Vsquez_Fer_23-1689180226666.png" /></span></p>
<p><strong>How to create an user </strong></p>
<p>Navigate to the Active Directory of users and computers, then left-click on it. Next, select 'New,' followed by 'user’, and proceed to fill in the required information (username and password ).</p>
<p>In this case, we need to edit the 'Member of' properties of this user. Since I want this user to belong to the earlier created 'DEMO' group, we navigate to the user's properties, specifically the 'Member of' section. Subsequently, we add the group and configure it as the primary group.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7468i33D391BAFDEFEB55/image.png" role="button" title="Vsquez_Fer_24-1689180226670.png" alt="Vsquez_Fer_24-1689180226670.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7466i754185EE6BC1CA94/image.png" role="button" title="Vsquez_Fer_25-1689180226670.png" alt="Vsquez_Fer_25-1689180226670.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7467i40877DEA1FDD0DA2/image.png" role="button" title="Vsquez_Fer_26-1689180226671.png" alt="Vsquez_Fer_26-1689180226671.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7470iA90EFC7867E6B0ED/image.png" role="button" title="Vsquez_Fer_27-1689180226676.png" alt="Vsquez_Fer_27-1689180226676.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7469iE8BD1D230C56DD6E/image.png" role="button" title="Vsquez_Fer_28-1689180226677.png" alt="Vsquez_Fer_28-1689180226677.png" /></span></p>
<p>Continue with the network policies configuration next, we will select the desired group and proceed to the 'Constraints' tab. Here, we will add CHAP as the authentication method.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7471i3009B4DDD490AFEF/image.png" role="button" title="Vsquez_Fer_29-1689180226680.png" alt="Vsquez_Fer_29-1689180226680.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7472i989E8E374EAD5F0A/image.png" role="button" title="Vsquez_Fer_30-1689180226682.png" alt="Vsquez_Fer_30-1689180226682.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7474i47FD7BFA64D437C9/image.png" role="button" title="Vsquez_Fer_31-1689180226684.png" alt="Vsquez_Fer_31-1689180226684.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7473iF88293E53F57936B/image.png" role="button" title="Vsquez_Fer_32-1689180226687.png" alt="Vsquez_Fer_32-1689180226687.png" /></span></p>
<p><strong>9-Unleashed Configuration</strong></p>
<p>In the Unleashed configuration, navigate to 'Admin and Services' and then 'Services.' Click on the plus (+) sign to add the RADIUS server and fill in the information based on the configuration we completed in Step 4. Ensure that the IP address points to the RADIUS server.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7475i4578BBF3B6908642/image.png" role="button" title="Vsquez_Fer_33-1689180226689.png" alt="Vsquez_Fer_33-1689180226689.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7476i175B316708E257AA/image.png" role="button" title="Vsquez_Fer_34-1689180226691.png" alt="Vsquez_Fer_34-1689180226691.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7477i8ED5858CBA033216/image.png" role="button" title="Vsquez_Fer_35-1689180226695.png" alt="Vsquez_Fer_35-1689180226695.png" /></span></p>
<p>10- WLAN Creation</p>
<p>Navigate to 'Wi-Fi Networks' and select the tab for creating a wireless network. Fill in the necessary information accordingly. In this step, the only addition is to include the server that we created in <strong>Step 9</strong> as the authentication server.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7479iB99CE563FA7320AA/image.png" role="button" title="Vsquez_Fer_36-1689180226698.png" alt="Vsquez_Fer_36-1689180226698.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7478i7D8C6B6CFFD8CAFE/image.png" role="button" title="Vsquez_Fer_37-1689180226701.png" alt="Vsquez_Fer_37-1689180226701.png" /></span></p>
<p><strong>11-Wireless Client</strong></p>
<p>After creating the wireless network, it's important to check the connectivity. Connect to the network and when prompted, enter the credentials of the created DEMO-USER along with the corresponding password. If the credentials match, you should be able to connect to the network without any issues.</p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7481i9548A2CE6BB66636/image.png" role="button" title="Vsquez_Fer_38-1689180226715.png" alt="Vsquez_Fer_38-1689180226715.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7482i0A065E739F66E667/image.png" role="button" title="Vsquez_Fer_39-1689180226724.png" alt="Vsquez_Fer_39-1689180226724.png" /></span></p>
<p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/7483i5B836F0ACE6DF224/image.png" role="button" title="Vsquez_Fer_40-1689180226743.png" alt="Vsquez_Fer_40-1689180226743.png" /></span></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>]]>
        </description>
    </item>
    <item>
        <title>AP Discovery - How to configure DHCP option 43 to discover the controller?</title>
        <link>https://community.ruckuswireless.com/en/discussion/65975/ap-discovery-how-to-configure-dhcp-option-43-to-discover-the-controller</link>
        <pubDate>Tue, 15 Aug 2023 01:00:37 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>Orlando_Elias</dc:creator>
        <guid isPermaLink="false">65975@/en/discussions</guid>
        <description><![CDATA[<p><span style="font-size: large;"><strong>The DHCP option 43 is one of many methods for the RUCKUS AP to discover its controller.</strong></span></p><p>This option is configured in the DHCP server and&nbsp;<strong>must be masked</strong>. Also, the vendor code and the length of the IP address must be specified in HEX.</p><p><u><strong>RUCKUS vendor code: </strong></u></p><p>- 06 for SmartZone</p><p>- 03 for Zone Director</p><p>Using&nbsp;<a href="https://shimi.net/services/opt43/" target="_blank" rel="noopener nofollow noreferrer">this website</a>&nbsp;you will quickly mask the IP address from IPV4 to <u>dnsmasq</u> values.&nbsp;&nbsp;</p><p>For example, let's mask the IP address 192.168.0.200 using the website: the final value to enter in your DHCP server is "<span>060d3139322e3136382e302e323030"</span></p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/8254iEDFFFB073C04DC90/image.png" width="717" height="473" role="button" title="Orlando_Elias_1-1692061698341.png" alt="Orlando_Elias_1-1692061698341.png" /></span></p><p>&nbsp;</p><p><span style="font-size: x-large;"><strong>How did they get to such a result?</strong></span>&nbsp;</p><ol><li><p><strong>Divide the IP Address:</strong> Start by splitting the IP address into its four individual parts: A.B.C.D.</p><ol><li>192</li><li>168</li><li>0</li><li>200</li></ol></li><li><p><strong>Mask the decimal values:</strong> For each part, convert the decimal value to its corresponding hexadecimal representation. For instance:</p><ul><li>Decimal 1 becomes "31"</li><li>Decimal 9 becomes "39"</li><li>Decimal 2 becomes "32" ...</li></ul></li><li><p><strong>Add Separators:</strong> Place "2e" (ASCII value for dot) between each pair of translated hex values.</p></li><li><p><strong>Include Vendor Code and Length:</strong> Prefix the vendor code at the beginning (e.g., "06" for RUCKUS). Add the IP address length in bytes (e.g., "0d" for 13 bytes).</p><p><span style="color: #FF0000;"><strong>Note: The length is 13 bytes since each pair of characters equals one byte.</strong></span></p></li><li><p><strong>IP Address Translation:</strong> The IP address "192.168.0.200" transforms into the hexadecimal string "3139322e3136382e302e323030".</p></li><li><p><strong>Combining Elements:</strong> Combine all the translated parts to form the final hexadecimal representation.</p></li></ol><p>Example for the IP address "192.168.0.200":</p><ul><li>Translated octets: "31", "39", "32", "2e", "31", "36", "38", "2e", "30", "2e", "32", "30", "30"</li><li>Vendor code: "06"</li><li>Length: "0d"</li><li>Combined: "060d3139322e3136382e302e323030"</li></ul><p><a rel="nofollow" href="https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-the-APs-discover-the-IP-address-of-the-controller/td-p/65974" target="_blank">Visit this post</a> to learn <strong>other ways</strong> to provision RUCKUS APs with the IP address of their controllers.</p>]]>
        </description>
    </item>
    <item>
        <title>Ruckus unleashed - import CSV of mac addresses to l2 mac address access control?</title>
        <link>https://community.ruckuswireless.com/en/discussion/72761/ruckus-unleashed-import-csv-of-mac-addresses-to-l2-mac-address-access-control</link>
        <pubDate>Thu, 07 Dec 2023 23:08:47 +0000</pubDate>
        <category>Community and Online Support Services</category>
        <dc:creator>bdillard</dc:creator>
        <guid isPermaLink="false">72761@/en/discussions</guid>
        <description><![CDATA[<p>Hello,</p><p>&nbsp;</p><p>I have about 10 APs R550's running the latest firmware with 4 VLANs - we want to put certain people on certain VLANs only and prevent them from logging in otherwise.&nbsp; &nbsp;The first group is about 50 mac addresses, the second is about 100 and the third is about 25 mac addresses.</p><p>&nbsp;</p><p>We'd really prefer to import a mac address list rather than add 175 mac addresses 1 at a time.</p><p>Anyone know a way to import the CSVs?</p><p>&nbsp;</p><p><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/10095i60582A9D481CEC17/image.jpg" role="button" title="Capture1.JPG" alt="Capture1.JPG" /></span></p>]]>
        </description>
    </item>
    <item>
        <title>Things to consider about PoE at a glance, when deploying.</title>
        <link>https://community.ruckuswireless.com/en/discussion/78021/things-to-consider-about-poe-at-a-glance-when-deploying</link>
        <pubDate>Fri, 12 Apr 2024 09:50:30 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>jdryan</dc:creator>
        <guid isPermaLink="false">78021@/en/discussions</guid>
        <description><![CDATA[<p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>By using copper Ethernet cabling to provide DC power, Power over Ethernet (PoE) removes the requirement for distinct power supplies and sockets. It grants increased installation flexibility for Ethernet end devices, although it lacks Ethernet data capabilities. Moreover, with their integration into switches, they can function as both data connection switches and power sourcing equipment (PSE). </span><span>&nbsp;<br /></span><span>However, when working with devices that can deliver PoE, there are a few things to consider.&nbsp;<br /></span></span><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>Let’s take look at them,&nbsp;<br /></span><strong>The total PoE capacity of the PSE / PoE budget of the device and the level of PoE it can deliver.&nbsp;&nbsp;<br /></strong><span>This dictates the total PoE power that the device can deliver and the type of PoE standard it can support.&nbsp;</span><span>&nbsp;</span><span>Most devices can hold up to PoE and PoE+, while there are some that deliver PoE++ or 802.3bt as well.&nbsp;</span><span>&nbsp;<br /></span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>How can we check this?&nbsp;</span><span>&nbsp;</span><span>The data sheet of the device(s) !.<br /></span><span>Let’s consider, <strong>RUCKUS ICX 7150-48P Switch,</strong> which has the following hardware specifications:</span><span>&nbsp;</span></span></p><ul><li><span style="font-size: small; font-family: arial,helvetica,sans-serif;">48× 10/100/1000 Mbps RJ-45 PoE+ ports&nbsp;&nbsp;</span></li><li><span style="font-size: small; font-family: arial,helvetica,sans-serif;">370 W PoE budget&nbsp;&nbsp;</span></li><li><span style="font-size: small; font-family: arial,helvetica,sans-serif;">2× 10/100/1000 Mbps uplink RJ-45 ports&nbsp;&nbsp;</span></li><li><span style="font-size: small; font-family: arial,helvetica,sans-serif;">4× 1/10 GbE uplink/stacking SFP/SFP+ ports&nbsp;</span></li></ul><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span> </span><span>Which shows that,&nbsp;</span><strong>&nbsp;</strong><strong>It has a PoE budget of 370 W and there are 48 ports that can support PoE+ or 802.3at.<br /></strong></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>For more reading, refer : </span><a href="https://www.commscope.com/globalassets/digizuite/61729-ds-icx-7150.pdf" target="_blank" rel="noopener noreferrer nofollow"><span>https://www.commscope.com/globalassets/digizuite/61729-ds-icx-7150.pdf</span></a><span>&nbsp;<br /></span><span>Note that in this example we have considered 7150, but for other models such as 8200, 7550, etc. Please refer to the data sheets for the respective switch families.</span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><strong>Number of devices it can deliver PoE to.&nbsp;&nbsp;<br /></strong></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;">This relates to the PoE budget of the device and the type of Powered Devices (PDs) used. Nowadays, PDs typically come with PoE+ capabilities, although there are still some that support only PoE. The crucial factor is understanding the PD's capability to determine how many of them the switch can accommodate or power up. For instance, consider an Access Point (AP) rated for PoE+. When negotiating for PoE, the device communicates with the switch through the LLDP TLV field, specifying its class and power requirements. Based on this class, the switch allocates power accordingly.</span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span><img src="https://us.v-cdn.net/6038795/uploads/khoros_attachments/11300i31AFC512F1744A0D/image.png" role="button" title="jdryan_0-1712914896074.png" alt="jdryan_0-1712914896074.png" /></span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span><span>The above reference is as per IEEE Documentation for PoE standards 802.3at and 802.3bt.&nbsp;</span></span><span>&nbsp;<br /></span><span>Based on this, considering that the<strong> PD is PoE+ capable</strong>, on RUCKUS ICX 7150-48P that has 370 W PoE budget.</span><span>&nbsp;<br /></span><strong>We can calculate the below:&nbsp;</strong><span><strong>&nbsp;</strong><br /></span><span>PSE's budget = 370W</span><span>&nbsp;<br /></span><span>PD's PoE Class = PoE+ that reserves max. of 30W at PSE&nbsp;</span><span>&nbsp;<br /></span><strong>Number of devices = PSE's PoE budget / PoE Class of the device = 370 / 30 = 12.3333&nbsp;<br /></strong>It can power up to 12 PDs at PoE+ power level. Any additional PDs would not activate due to insufficient remaining power in the budget.</span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>Now the question arises, why not define the power limit manually?&nbsp;</span><span>&nbsp;<br /></span><span>&nbsp; &nbsp; Strict manipulation can indeed bring up more PDs, but it carries a risk. After all PDs are operational and receiving optimal power, reallocating power back to the budget pool is possible. However, if a reload or power cycle of the Power Sourcing Equipment (PSE) occurs unexpectedly, PDs may encounter power-up issues. During the initial power-up or startup phase, the PSE delivers full power to the PDs. Consequently, some connected PDs may experience power shortages and struggle to come online.</span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>Can it be done? And how?&nbsp;</span><span>&nbsp;<br /></span><strong>To configure the power limit manually on a interface based on power limit.&nbsp;</strong><span>&nbsp;<br /></span><span>Please do refer.&nbsp;</span><span>&nbsp;<br /></span><a href="https://docs.commscope.com/bundle/fastiron-08095-managementguide/page/GUID-58622E67-07D7-41E4-B4C6-A9B6F3EA8C74.html" target="_blank" rel="noopener noreferrer nofollow"><span>https://docs.commscope.com/bundle/fastiron-08095-managementguide/page/GUID-58622E67-07D7-41E4-B4C6-A9B6F3EA8C74.html</span></a><span>&nbsp;<br /></span><strong>To configure the power limit manually on a interface based on class of the PD.</strong><span><strong>&nbsp;</strong><br /></span><span>Please do refer.</span><span>&nbsp;<br /></span><a href="https://docs.commscope.com/bundle/fastiron-08095-managementguide/page/GUID-155FABD5-F3C2-4579-ADBB-CC240997524A.html" target="_blank" rel="noopener noreferrer nofollow"><span>https://docs.commscope.com/bundle/fastiron-08095-managementguide/page/GUID-155FABD5-F3C2-4579-ADBB-CC240997524A.html</span></a><span>&nbsp;<br /></span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;">How does Ruckus address this?<br />Ruckus offers two well-known ways for Power Management methods for ICX line that are PoE capable.<br /><strong>Static Power Management:<br /></strong><span>Power is set aside for each powered device (PD) connected to switch ports when in static PM.<strong> This approach adheres to the previously discussed procedure, wherein the maximum power is set aside according to the linked power device's class</strong>. <strong>If the power reservation is not possible, even when the overall usage is less than the entire power budget, no new PDs will be powered.</strong></span><strong>&nbsp;<br /></strong><span>The ICX devices are configured or made available in this mode for PoE management Out of the Box.</span><span>&nbsp;</span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>To overcome this, we have Dynamic Power management.&nbsp;</span><span>&nbsp;<br /></span><strong>Dynamic Power Management:&nbsp;<br /></strong>Where this helps via <strong>having the power allocation done based on the consumption of the PD that’s connected.&nbsp;</strong><strong>&nbsp;</strong><span><strong>Here power is not set aside for any ports in dynamic PM. Until the overall power consumption is within the ICX device's total power budget,</strong> PDs are turned on automatically.&nbsp;</span><span>&nbsp;<br /></span><span>However here<strong> the switch will immediately shut down any PDs with low priority ports or, if all ports have the same priority, shut down PDs attached to higher-numbered ports in order to keep the total power consumption within the total power budget if the power consumption increases, either by increasing the power consumption of connected PDs or by adding new PDs.</strong></span><strong>&nbsp;<br /></strong></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>How to go about setting this?&nbsp;</span><span>&nbsp;<br /></span><span>Do refer here:&nbsp;</span><span>&nbsp;</span><a rel="nofollow" href="https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-enable-Dynamic-PoE-power-on-the-ICX-switches/m-p/68751" target="_blank"><span>https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/How-to-enable-Dynamic-PoE-power-on-the-ICX-switches/m-p/68751</span></a><span>&nbsp;</span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>There however is a third way, that is<strong> Hybrid Power Management.</strong></span><span>&nbsp;<br /></span><span>This is a mix of the above 2 methods and <strong>can be achieved by configuring static PM for a few of the ports and dynamic PM for a few of the ports. The way this works to differentiate between the two methods is based on the priority that is set for the specific interfaces, priority of 1 dictate that it uses static PM, as priority of 2 or higher dictates it uses dynamin PM.</strong> This priority can be set per interface or globally as well.&nbsp;</span><span>&nbsp;<br /></span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>Under this method, after enabling dynamic poe, below settings are needed enable Hybrid PM,<br /></span><span>(1) to enable Static PM, use "</span><strong><span>inline power ethernet unit/slot/port priority 1"</span></strong><span> on those specific ports.</span><span>&nbsp;<br /></span><span>Example: in config mode,&nbsp;</span><span>&nbsp;<br /></span><span>Inline power ethernet 1/1/1 priority 1</span><span>&nbsp;<br /></span></span><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>(2) to enable Dynamic PM, use a priority of 2 or 3 instead of 1</span><span> on those specific ports.</span><span>&nbsp;<br /></span><span>Example: in config mode,&nbsp;</span><span>&nbsp;<br /></span><span>inline power ethernet 1/1/4 priority 2</span><span>&nbsp;<br /><br /></span><span>Apart from this, there is also <strong>Perpetual PoE and Fast Boot PoE.<br /></strong></span><span><strong>Perpetual PoE,</strong> where PoE power delivery to the equipment is uninterrupted, when the device is rebooting or reloading.&nbsp;</span><span>&nbsp;<br /></span><span><strong>Fast Boot PoE</strong>, where the PoE is delivered as soon as the switch is turned on, where the PD would not have to wait until the system is up.&nbsp;</span><span>&nbsp;<br /></span><span>To enable this, Use “</span><strong><span>inline power poe-ha</span></strong><span>” in interface configuration prompt.&nbsp;</span><span>&nbsp;<br /></span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>For Further reading on PoE features on the ICX line-up,&nbsp;<a href="https://docs.commscope.com/bundle/fastiron-10010-managementguide/page/GUID-36148BA0-4CDB-4551-9463-C1ABD8139CCB.html&nbsp;" target="_blank" rel="noopener noreferrer nofollow">Click here</a>,&nbsp;</span><span>&nbsp;<br /></span></span></p><p><span style="font-size: small; font-family: arial,helvetica,sans-serif;"><span>Abbreviations used:<br /></span><span>PD - Power Device.</span><span>&nbsp;<br /></span><span>PSE - Power Source Equipment also known as Endspan device.</span><span>&nbsp;<br /></span><span>PoE - Power over ethernet.</span><span>&nbsp;<br /></span><span>PoE Injector is also known as Midspan device.</span><span>&nbsp;</span></span></p>]]>
        </description>
    </item>
    <item>
        <title>Information to gather for ICX POE issues</title>
        <link>https://community.ruckuswireless.com/en/discussion/77628/information-to-gather-for-icx-poe-issues</link>
        <pubDate>Thu, 04 Apr 2024 02:34:32 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>josue_jimenez_c</dc:creator>
        <guid isPermaLink="false">77628@/en/discussions</guid>
        <description><![CDATA[<p>Basic list of non-intrusive commands.</p><p><br /><span>show commands:</span><br /><span>1.&nbsp;</span><span>show config</span><br /><span>2.&nbsp;</span><span>show running-config</span><br /><span>3.&nbsp;</span><span>show stack</span><br /><span>4.&nbsp;</span><span>show version</span><br /><span>5.&nbsp;</span><span>show chassis</span><br /><span>6.&nbsp;</span><span>show vlan</span><br /><span>7.&nbsp;</span><span>show inline power</span><span>&nbsp;| inc</span><span>&nbsp;stack/slot/port</span><span>)</span><br /><span>8.&nbsp;</span><span>show interface brief</span><br /><span>9.&nbsp;</span><span>show inline power detail</span><br /><span>10.&nbsp;</span><span>show chassis</span><br /><span>11.&nbsp;</span><span>show lldp</span><br /><span>12.&nbsp;</span><span>show lldp neighbors detail ports all&nbsp;</span><span>(for single port:</span><span>&nbsp;ports ethernet stack/slot/port</span><span>)</span><br /><span>13.&nbsp;</span><span>show fdp</span><br /><span>14.&nbsp;</span><span>show fdp neighbors ethernet stack/slot/port</span><br /><span>14.&nbsp;</span><span>show inline power emesg</span></p><p>&nbsp;</p><p><span><br /><strong>General information to request:</strong><br /><br />What Powered Device (PD) types are connecting to the Power Source Equipment (PSE)<br />i.e. Model number, firmware version, serial number, manufacturer, PoE standard provides up to 15.4 W, PoE+ or PoE plus, provides up to 25.5 W of power?<br />And/or Power over HDBaseT (PoH), ratified in September 2011, extends PoE’s capabilities to deliver up to 95W?</span></p>]]>
        </description>
    </item>
    <item>
        <title>v/SZ - What is the latest SmartZone firmware supported for the AP R600?</title>
        <link>https://community.ruckuswireless.com/en/discussion/57573/v-sz-what-is-the-latest-smartzone-firmware-supported-for-the-ap-r600</link>
        <pubDate>Tue, 25 Apr 2023 00:08:58 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>Orlando_Elias</dc:creator>
        <guid isPermaLink="false">57573@/en/discussions</guid>
        <description><![CDATA[<p>The latest and most recommended version of the virtual/SmartZone controller that supports the AP R600 is 5.2.2.0.1563.</p><p data-unlink="true">https://support.ruckuswireless.com/software&nbsp;</p><p>The advantage of the SZ controller is that if you need to upgrade to <strong>the newest version 6.1.1</strong>, you can still keep the EOL R600 AP on a separate AP Zone with the firmware 5.2.2 for this zone, while the newer APs are managed in zones with the appropriate version for them.</p><p>Need to upgrade de controller? <a rel="nofollow" href="https://community.ruckuswireless.com/t5/RUCKUS-Self-Help/v-SZ-how-to-upgrade-the-controller-easy-upgrade-steps-for/td-p/58284" target="_blank">Follow this step-by-step</a>.</p><p>&nbsp;</p>]]>
        </description>
    </item>
    <item>
        <title>FQDNs and Ports that need to be open in Firewall for Ruckus One</title>
        <link>https://community.ruckuswireless.com/en/discussion/76386/fqdns-and-ports-that-need-to-be-open-in-firewall-for-ruckus-one</link>
        <pubDate>Thu, 29 Feb 2024 11:15:27 +0000</pubDate>
        <category>RUCKUS Self-Help</category>
        <dc:creator>vasanth_edward</dc:creator>
        <guid isPermaLink="false">76386@/en/discussions</guid>
        <description><![CDATA[<p><span>To ensure proper communication between the APs and switches with RUCKUS One, customers must allow some FQDNs and Ports in their Firewall.</span></p>
<p><strong>Customer Environment</strong></p>
<p>APs and Switches deployed behind a firewall and inbound/outbound traffic needs to be allowed for successful communication between RUCKUS network devices and RUCKUS One.</p>
<p><strong>Symptoms</strong></p>
<p>Newly added APs and switches are in Never Contacted Cloud state, not joining RUCKUS One.</p>
<p><strong>Resolution</strong></p>
<p>To allow RUCKUS One to function properly, please configure your firewall to allow for outbound connectivity according to the following guidelines:<br />&nbsp;</p>
<p><strong>Outbound HTTPS (TCP 443) from APs and Switches to</strong>:</p>
<p><a href="https://ap-registrar.ruckuswireless.com" target="_blank" rel="noopener noreferrer nofollow">https://ap-registrar.ruckuswireless.com</a><br /><a target="_blank">https://sw-registrar.ruckuswireless.com</a><br /><a target="_blank">https://ocsp.comodoca.com</a><br /><a target="_blank">https://ocsp.entrust.net</a><br /><a target="_blank">https://ruckus.cloud</a><br /><a target="_blank">https://eu.ruckus.cloud</a><br /><a target="_blank">https://asia.ruckus.cloud</a><br /><a target="_blank">https://device.ruckus.cloud</a><br /><a target="_blank">https://device.eu.ruckus.cloud</a><br /><a target="_blank">https://device.asia.ruckus.cloud</a><br /><a target="_blank">https://storage.googleapis.com<br />http://ocsp.godaddy.com<br /></a></p>
<p><br /><strong>Outbound SSH (TCP 22) from APs and Switches to:</strong></p>
<p><a target="_blank">device.ruckus.cloud</a><br /><a target="_blank">device.eu.ruckus.cloud</a><br /><a target="_blank">device.asia.ruckus.cloud</a></p>
<p><br /><strong>Network Requirements</strong></p>
<p>The following list of firewall ports is required to allow APs to enable Cloud discovery and continued connection with the Cloud</p>
<p>Checking the firewall ports is the first step of troubleshooting if an AP is unable to connect to the Cloud or disconnects from the Cloud.</p>
<p><a href="https://docs.cloud.ruckuswireless.com/ruckusone/userguide/GUID-D00EA4CC-7B8A-4F99-969B-2A5FB5DDB178-low.png" target="_self" rel="noopener noreferrer nofollow">https://docs.cloud.ruckuswireless.com/ruckusone/userguide/GUID-D00EA4CC-7B8A-4F99-969B-2A5FB5DDB178-low.png</a>&nbsp;</p>
<p>If these information helped you in any way, please click on "KUDOs", so you can help other users.</p>]]>
        </description>
    </item>
   </channel>
</rss>
