Ruckus SZ™ 100 And VSZ E™ Command Line Interface Reference Guide For SmartZone 3.5 Smart Zone (GA) (SZ100/v SZ E) Sz100Vsze 35 CLIGuide20170410
SmartZone 3.5 (GA) Command Line Interface Reference Guide (SZ100/vSZ-E) Sz100Vsze-35-CLIGuide20170410
2017-04-25
User Manual: Ruckus SmartZone 3.5 (GA) Command Line Interface Reference Guide (SZ100/vSZ-E)
Open the PDF directly: View PDF .
Page Count: 381
Download | ![]() |
Open PDF In Browser | View PDF |
Ruckus Wireless SmartZone 100 and Virtual SmartZone Essentials ™ ™ Command Line Interface Reference Guide for SmartZone 3.5 Part Number 800-71293-001 Published April 2017 www.ruckuswireless.com Copyright Notice and Proprietary Information Copyright © 2017. Ruckus Wireless, Inc. All rights reserved. No part of this documentation may be used, reproduced, transmitted, or translated, in any form or by any means, electronic, mechanical, manual, optical, or otherwise, without prior written permission of Ruckus Wireless, Inc. (“Ruckus”), or as expressly provided by under license from Ruckus. Destination Control Statement Technical data contained in this publication may be subject to the export control laws of the United States of America. Disclosure to nationals of other countries contrary to United States law is prohibited. It is the reader’s responsibility to determine the applicable regulations and to comply with them. Disclaimer THIS DOCUMENTATION AND ALL INFORMATION CONTAINED HEREIN (“MATERIAL”) IS PROVIDED FOR GENERAL INFORMATION PURPOSES ONLY. RUCKUS AND ITS LICENSORS MAKE NO WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, WITH REGARD TO THE MATERIAL, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT AND FITNESS FOR A PARTICULAR PURPOSE, OR THAT THE MATERIAL IS ERROR-FREE, ACCURATE OR RELIABLE. RUCKUS RESERVES THE RIGHT TO MAKE CHANGES OR UPDATES TO THE MATERIAL AT ANY TIME. Limitation of Liability IN NO EVENT SHALL RUCKUS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL OR CONSEQUENTIAL DAMAGES, OR DAMAGES FOR LOSS OF PROFITS, REVENUE, DATA OR USE, INCURRED BY YOU OR ANY THIRD PARTY, WHETHER IN AN ACTION IN CONTRACT OR TORT, ARISING FROM YOUR ACCESS TO, OR USE OF, THE MATERIAL. Trademarks Ruckus Wireless, Ruckus, the bark logo, ZoneFlex, FlexMaster, ZoneDirector, SmartMesh, Channelfly, Smartcell, Dynamic PSK, and Simply Better Wireless are trademarks of Ruckus Wireless, Inc. in the United States and other countries. All other product or company names may be trademarks of their respective owners. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 2 Contents About This Guide Document Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 Related Documentation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 Documentation Feedback . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14 1 Introduction to the Controller Command Line Interface Overview of the Controller Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16 Accessing the Command Line Interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16 What You Will Need . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16 Connect the Administrative Computer to the Controller . . . . . . . . . . . . . . . . . . . . . . . 16 Start and Configure the SSH Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17 Using SSH Connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18 Using Serial Connection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 19 Log On to CLI . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22 2 Configuration Commands (a - d) config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 26 ad-service. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 27 admin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 29 admin-radius. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 31 ap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 34 ap-auto-approve. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 47 ap-auto-tagging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 49 ap-cert-check . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50 ap-certificate-reset . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 ap-control-mgmt-tos . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 51 ap-heartbeat . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 app-denial-policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 52 app-port-mapping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 53 cert-store . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 55 changepassword . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 57 clock. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 58 cluster-ip-list . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 3 cluster-name. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60 cluster-redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60 dns-server-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 63 do. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64 dp-group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 65 3 Configuration Commands (e-r) encrypt-mac-ip . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68 encrypt-zone-name . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 68 eth-port-validate-one-trunk . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69 end . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69 event . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 70 event db-persistence . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71 event email . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72 event snmp-notification. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 73 event-email . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 74 event-threshold. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 75 exit . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76 ftp-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 76 ftp-test . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78 help . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 78 hostname . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79 identity-provider . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 79 interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 93 ip . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 98 ip control-nat . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99 ip name-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99 ip name-server-ipv6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100 ip route . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 100 ip route-ipv6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101 ipsec-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 101 lbs-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 107 ldap-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 108 license . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 111 license cloud. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112 license export . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 112 license import . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113 license local . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 113 license sync-now . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 4 lineman . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 114 localdb-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 115 logging console. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 116 lwapp2scg . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 117 mgmt-acl . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 119 no ad-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 120 no admin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121 no admin-radius . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 121 no ap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122 no ap auto-approve . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 122 no ap auto-tagging . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123 no ap-cert-check . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123 no ap-control-mgmt-tos . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124 no ap-group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 124 no block-client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 no bonjour-fencing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 no bonjour-fencing-policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 125 no bonjour-gateway . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 126 no bonjour-policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127 no cert-store . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 127 no control-plane . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 128 no data-plane . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 128 no device-policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129 no diffserv . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 129 no dns-server-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 130 no dp-group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 130 no encrypt-mac-ip . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131 no encrypt-zone-name . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131 no ethernet-port-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 132 no event . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 132 no ftp-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133 no guest-access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 133 no hotspot . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134 no hotspot20-venue-profile. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 134 no hotspot20-wlan-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 135 no identity-provider . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 135 no interface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136 no ip . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 136 no ipsec-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 137 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 5 no l2-acl . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138 no lbs-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 138 no ldap-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139 no lineman . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 139 no logging. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 140 no oauth-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 140 no operator-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 141 no osu-portal-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 141 no outbound firewall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 142 no proxy-aaa . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 142 no report. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 142 no role . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 143 no sci-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 143 no snmp-notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 144 no snmp-v2-community . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 144 no snmp-v3-user . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146 no snmp-v2-community . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 146 no snmp-v3-user . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147 no subpackages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 147 no user-agent-blacklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148 no user-group. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 148 no user-role . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149 no user-traffic-profile. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 149 no vlan-pooling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150 no web-authentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 150 no wlan. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151 no wlan-group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 151 no wlan-scheduler . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 152 no zone . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 152 northbound-authtype . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 153 northbound-portal. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 153 ntp-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154 oauth-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 154 operator-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 156 outbound-firewall . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 158 proxy-aaa . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 160 rebalance-aps. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 163 report . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 164 rks-gre . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 168 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 6 role . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 169 4 Configuration Commands (s-z) sci-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 172 sci-setting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 174 sms-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 175 smtp-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 176 snmp-notification . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179 snmp-v2-community. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179 snmp-v3-user . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 181 soft-gre. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183 subpackages . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 186 support-admin . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 187 syslog-server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 188 user-agent-blacklist . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 191 user-group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 193 user-role . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 194 user-traffic-profile . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 196 vlan-pooling . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 200 zone . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 201 zone-template. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 275 5 Debug Commands debug . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 278 ap-subnet-discovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 278 apcli . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 279 data-plane . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 280 diagnostic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 281 do. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 283 dp-customized-config. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 283 end . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 284 exit . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 284 export log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 285 help . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 285 no ap-subnet-discovery . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 286 no dp-customized-config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 286 no output-format. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 287 no save. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 287 no schedule . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 288 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 7 no screen-pagination . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 288 no strict-wfa-compliance. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 289 no sha1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 289 no tlsv1. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 290 no web-backdoor . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 290 no web-debug . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 291 output-format . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 291 reindex-elasticsearch-all . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 292 screen-pagination . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 292 sha1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 293 show ap-subnet-discovery-status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 294 show dp-customized-config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 294 show sha1-state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 295 show strict-wfa-compliance-state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 295 show tlsv1-state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296 strict-wfa-compliance-state. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 296 tlsv1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 297 6 Setup Commands rbd . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298 rbddump. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 298 setup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 300 7 Show Commands show admin-activity . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 304 show alarm . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 305 show ap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 305 show ap-certificate-status. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 306 show ap-stats. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 306 show backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 310 show backup-config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 310 show backup-config-state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 311 show backup-network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 311 show backup-schedule. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 312 show backup-state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 312 show backup-upgrade-state. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 313 show client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 313 show clock . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 314 show cluster . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 8 show cluster-node . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 315 show cluster-state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 316 show control-plane-stats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 316 show counter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 318 show cpuinfo . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 319 show dhcp-relay-stats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320 show diskinfo . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 320 show event . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 321 show history . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 321 show interface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 322 show ip. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 323 show license . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 324 show logs-filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 325 SZ100# show logs-filter client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 325 show md-stats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 326 show meminfo . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 327 show ntp . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 328 show radius-proxy-stats . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 328 show report-result. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 329 show rogue-aps . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 330 show run cluster-redundancy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 331 show running-config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 331 show run sci-profile. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 336 show run sci-setting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 337 show run user-group . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 337 show run zone . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 338 show run zone-template . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339 show service. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 339 show upgrade-history . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 340 show upgrade-state . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 341 show version. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 341 show zone . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 342 8 System Commands ?. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . backup config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . backup network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . backup schedule . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 344 345 345 346 346 9 backup-upgrade . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 347 cluster in-service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 348 config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 348 copy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 349 copy ap-certificate-request . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 350 copy backup. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 350 copy backup-config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 351 copy backup-network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 351 copy client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 352 copy report-result . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 353 copy ftp-url . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 353 delete backup . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 354 delete backup-config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 354 delete backup-network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 355 delete client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 355 diagnostic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 356 enable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 359 enable. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 359 exit . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 360 help . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 360 logout . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 361 log-diagnostic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 361 no service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 362 patches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 362 ping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 363 ping6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 364 reload . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365 reload ap . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 365 reload now . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 366 remote ap-cli . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 366 restore . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 367 restore config . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 367 restore local . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 368 restore network. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 368 service restart . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 369 service start . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 369 set-factory . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 370 shutdown . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 372 shutdown now . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 372 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 10 snapshot disk . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 373 traceroute . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 373 traceroute6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 375 upgrade . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 376 upload ap-certificate-status . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 376 Index SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 11 About This Guide This SmartZone™ (SZ) 100 and Virtual SmartZone Essentials (vSZ-E) Command Line Interface Reference Guide contains the syntaxes and commands for configuring and managing the SZ-100/vSZ-E (collectively referred to as “the controller” throughout this guide) from the command line interface. This guide is written for service operators and system administrators who are responsible for managing, configuring, and troubleshooting Ruckus Wireless devices. Consequently, it assumes a basic working knowledge of local area networks, wireless networking, and wireless devices. NOTE If release notes are shipped with your product and the information there differs from the information in this guide, follow the instructions in the release notes. Most user guides and release notes are available in Adobe Acrobat Reader Portable Document Format (PDF) or HTML on the Ruckus Wireless Support Web site at https://support.ruckuswireless.com/contact-us. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 12 Document Conventions Document Conventions Table 1 and Table 2 list the text and notice conventions that are used throughout this guide. Table 1. Text conventions Convention Description monospace Represents information as it [Device name]> appears on screen monospace bold Represents information that [Device name]> set you enter ipaddr 10.0.0.12 default font bold Keyboard keys, software buttons, and field names On the Start menu, click All Programs. italics Screen or page names Click Advanced Settings. The Advanced Settings page appears. Table 2. Example Notice conventions Notice Type Description NOTE Information that describes important features or instructions CAUTION! Information that alerts you to potential loss of data or potential damage to an application, system, or device WARNING! Information that alerts you to potential personal injury Related Documentation For a complete list of documents that accompany this release, refer to the Release Notes. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 13 Documentation Feedback Documentation Feedback Ruckus Wireless is interested in improving its documentation and welcomes your comments and suggestions. You can email your comments to Ruckus Wireless at: docs@ruckuswireless.com When contacting us, please include the following information: • Document title • Document part number (on the cover page) • Page number (if appropriate) For example: • SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5 • Part number: 800-71293-001 • Page 88 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 14 Introduction to the Controller Command Line Interface 1 In this chapter: • Overview of the Controller Command Line Interface • Accessing the Command Line Interface SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 15 Overview of the Controller Command Line Interface What You Will Need Overview of the Controller Command Line Interface The Controller command line interface (CLI) is a software tool that enables you to configure and manage the controller. Using the command line interface, you can issue commands from an operating system prompt, such as the Microsoft Windows command prompt or a Linux operating system terminal. Each command performs a specific action for configuring device settings or returning information about the status of a specific device feature. Accessing the Command Line Interface The controller has a built-in command line interface (CLI) that you can use to configure controller settings and manage access points. This section describes the requirements and the procedure for accessing the controller’s CLI. What You Will Need To access the controller CLI, you will need the following: 1 A computer that you want to designate as administrative computer 2 A network connection to the controller (if you want to use an SSH connection) or an RS-232 serial to RJ45 cable (if you want to use a serial connection) 3 An SSH (secure shell) client Connect the Administrative Computer to the Controller Connect the administrative computer to the controller either through the network or directly using an RS-232 serial to RJ45 cable. 1 If you want to use an SSH connection, connect the administrative computer to the same subnet or broadcast domain as the Management (Web) interface of the controller. 2 If you want to use a serial connection, make sure that both the administrative computer and the controller are both powered on. And then, do the following: • Connect the RJ45 end of the cable to the port labeled |O|O| (console port) on the controller. See Figure 1 for the location of the console port. • Connect the RS-232 end of the cable to a COM port on the administrative computer. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 16 Accessing the Command Line Interface Start and Configure the SSH Client Figure 1. Location of console port Start and Configure the SSH Client Before starting this procedure, make sure that the SSH client is already installed on the administrative computer. NOTE: The following procedure describes how to use PuTTY, a free and open source telnet/SSH client, to access the controller CLI. If you are using a different SSH client, the procedure may be slightly different (although the connection settings should be the same). For more information on PuTTY, visit www.putty.org. See the following sections depending on your connection method: • Using SSH Connection • Using Serial Connection SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 17 Accessing the Command Line Interface Start and Configure the SSH Client Using SSH Connection If you have connected the administrative computer to the same subnet or broadcast domain as the Management (Web) interface of the controller, follow these steps to start and configure the SSH client. 1 Start PuTTY. The PuTTY configuration dialog box appears, showing the Session screen as seen in Figure 2. 2 In Connection type, select SSH. Figure 2. Selecting SSH as a connection type 3 Enter the IP address of the Management (Web) interface of the controller in the Host Name (or IP address) field as seen in Figure 2. 4 Click Open. The PuTTY console appears and displays the login prompt. See Figure 6. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 18 Accessing the Command Line Interface Start and Configure the SSH Client Using Serial Connection If you have connected the administrative computer to the console port on the controller using an RS-232 serial to RJ45 cable, follow these steps to start and configure the SSH client. 1 Start PuTTY. The PuTTY Configuration dialog box appears, showing the Session screen as seen in Figure 3. 2 In Connection type, select Serial if you are connecting via serial cable. Figure 3. Selecting serial as a connection type 3 Under Category, click Connection > Serial. The serial connection options appear on the right side of the dialog box, displaying PuTTY’s default serial connection settings. See Figure 4. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 19 Accessing the Command Line Interface Start and Configure the SSH Client Figure 4. PuTTy’s default serial connection setting 4 Configure the serial connection settings as follows. See Figure 5. • Serial line to connect to: Type the COM port name to which you connected the RS-232 cable. • Bits per second: 115200 • Data bits: 8 • Stop bits: 1 • Parity: None • Flow control: None SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 20 Accessing the Command Line Interface Start and Configure the SSH Client Figure 5. PuTTY’s serial connection settings for connecting to the controller 5 Click Open. The PuTTY console appears and displays the login prompt as seen in Figure 6. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 21 Accessing the Command Line Interface Log On to CLI Figure 6. PuTTY console displaying the login prompt You have completed configuring the SSH client to connect to the controller CLI. Log On to CLI The following describes the process for log on to the CLI. • Log on to the controller using putty/Xssh (any other application) using the user credentials of login name and password as given. NOTE: You cannot use 'admin' as a password, which is used during the controller installation procedure. • The Ruckus Wireless controller CLI welcome message appears with the CLI prompt as seen in Figure 7. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 22 Accessing the Command Line Interface Log On to CLI Figure 7. Welcome to SmartZone • You are now logged into the controller CLI as a user with limited privileges by looking at the CLI prompt. If you are in limited mode, the prompt appears as ruckus> (with a greater than sign). To view a list of commands that are available at the root level or user mode, enter help or? as seen in Figure 7 and Figure 8. NOTE: To change the CLI prompt to a privileged mode, see step 5. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 23 Accessing the Command Line Interface Log On to CLI Figure 8. Using Show Commands • As a user with limited privileges, you can view a history of commands that were previously executed and ping a device as seen in Figure 9. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 24 Accessing the Command Line Interface Log On to CLI Figure 9. Using the Ping command • If you want to run more commands, you need to switch to privileged mode by entering enable and the password at the root prompt as seen in Figure 10. The prompt changes from ruckus> to ruckus# (with a pound sign) as seen in Figure 10. Refer to enable command for details. Figure 10. Changing to privileged mode SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 25 2 Configuration Commands (a - d) This chapter describes the commands that you can use to configure, enable, and disable various controller components. The following table lists the commands. NOTE: For easy access and reading, the configuration chapter has been split into three chapters based on the alphabetical order of commands. Table 3. Configuration commands config ad-service admin admin-radius ap-autoapprove ap-autotagging ap-cert-check ap-certificate- ap-control-mgmtreset tos ap-heartbeat cert-store changepasswo clock rd cluster-ip-list cluster-name clusterredundancy dns-serverservice dp-group do ap config To execute commands in configuration mode, you need to change the mode to: ruckus(config)# Example SZ100-Node1# SZ100-Node1# config SZ100-Node1(config)# SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 26 Configuration Commands (a - d) ad-service ad-service To create or update the active directory service configuration, use the following command: ruckus(config)# ad-service Once you enter the config-admin context, you can configure the rest of the administrator’s profile (see example below). Syntax Description This command uses the following syntax: name: Active service directory name Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# ad-service ads SZ100-Node1(config-ad-service)# Related Commands Table 5 lists the related ad-service configuration commands. Table 4. Commands related to ruckus(config-ad-service) Syntax and Type Parameters (if any) ruckus(config-ad-service)# admin- domain-name Type: Privileged ruckus(config-ad-service)# admin- password Type: Privileged ruckus(config-ad-service)# description Description Sets the administrator domain name. This field is applicable on executing the group attribute command. Sets the administrator domain password. This field is applicable on executing the group attribute command. Sets the description Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 27 Configuration Commands (a - d) ad-service Table 4. Commands related to ruckus(config-ad-service) Syntax and Type Parameters (if any) ruckus(config-ad-service)# do Description Executes the do command. Type: Privileged ruckus(config-ad-service)# email Sets the user’s email details. Type: Privileged ruckus(config-ad-service)# end Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-ad-service)# exit Exits from the EXEC. Type: Privileged ruckus(config-ad-service)# friendly-name Sets friendly name for the active service directory. Type: Privileged ruckus(config-ad-service)# global- catalog Enables the global catalog support Type: Privileged ruckus(config-ad-service)# group- : Group attrs attribute value Type: Privileged Sets the user traffic profile mapping. : User Role ruckus(config-ad-service)# help Displays help. Type: Privileged - Sets the primary server IP address Sets the primary service IP address. Sets the active directory service name. ruckus(config-ad-service)# no Disables the commands. Type: Privileged ruckus(config-ad-service)# port ruckus(config-ad-service)# ipaddress Type: Privileged ruckus(config-ad-service)# name Type: Privileged Sets the primary server port. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 28 Configuration Commands (a - d) admin Table 4. Commands related to ruckus(config-ad-service) Syntax and Type Parameters (if any) Description ruckus(config-ad-service)# windows-domain-name Example: dc=domain, dc=ruckuswireless, dc=com Sets the windows domain name Sets the user’s job title. Type: Privileged ruckus(config-ad-service)# title Type: Privileged admin To create or update the administrator’s profile (including the email address, login ID and password), use the following command: ruckus(config)# admin Once you enter the config-admin context, you can configure the rest of the administrator’s profile (see example below). Syntax Description This command uses the following syntax: name: Administrator user name Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# admin joe SZ100-Node1(config-admin)# email joe@company.com SZ100-Node1(config-admin)# password admin!234 SZ100-Node1(config-admin)# phone 22870001 SZ100-Node1(config-admin)# real-name "Joe Admin" SZ100-Node1(config-admin)# title CTO SZ100-Node1(config-admin)# radius radius-1 SZ100-Node1(config-admin-radius)# ip 1.1.1.1 SZ100-Node1(config-admin-radius)# port 1813 SZ100-Node1(config-admin-radius)# realm tw1 SZ100-Node1(config-admin-radius)# shared-secret 11 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 29 Configuration Commands (a - d) admin Retype: ** SZ100-Node1(config-admin-radius)# exit SZ100-Node1(config-admin)# exit SZ100-Node1(config)# Related Commands Table 5 lists the related admin configuration commands. Table 5. Commands related to ruckus(config-admin) Syntax and Type Parameters (if any) ruckus(config-admin)# do Description Executes the do command. Type: Privileged ruckus(config-admin)# email Sets the user’s email details. Type: Privileged ruckus(config-admin)# end Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-admin)# exit Exits from the EXEC. Type: Privileged ruckus(config-admin)# help Displays help. Type: Privileged ruckus(config-admin)# name Sets the account name. Sets the password for user. Sets the phone number of the user. Type: Privileged ruckus(config-admin)# password Type: Privileged ruckus(config-admin)# phone Type: Privileged ruckus(config-admin)# real-name Sets the real name. Type: Privileged ruckus(config-admin)# role Sets the user role. Sets the user’s job title. Type: Privileged ruckus(config-admin)# title Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 30 Configuration Commands (a - d) admin-radius admin-radius To configure the RADIUS server for administrators use the following command: ruckus(config)# admin-radius Syntax Description This command uses the following syntax: name: RADIUS server name Default This command has no default settings. Command Mode Config Example SZ100-Node1(config-admin)# radius SZ100-Node1(config-admin-radius)# SZ100-Node1(config-admin-radius)# SZ100-Node1(config-admin-radius)# SZ100-Node1(config-admin-radius)# Retype: ** SZ100-Node1(config-admin-radius)# SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 radius-1 ip 1.1.1.1 port 1813 realm tw1 shared-secret 11 exit 31 Configuration Commands (a - d) admin-radius Related Commands Table 6 lists the related admin-radius-service configuration commands. Table 6. Commands related to ruckus(config-radius-service) Syntax and Type Parameters (if any) Description ruckus(config-admin-radius)# backup ip : Sets the IP address of secondary RADIUS server Enables backup of RADIUS server. Type: Privileged port : Sets the port of secondary RADIUS server shared-secret: Sets the shared secret of secondary RADIUS server request-timeout : Sets the request timeout seconds for failover policy max-retry : Sets the maximum number of retries for failover policy retry-prilnvl : Sets the reconnect primary minutes for failover policy ruckus(config-admin-radius)# do Executes the do command. Type: Privileged ruckus(config-admin-radius)# end Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-admin-radius)# exit Exits from the EXEC. Type: Privileged ruckus(config-admin-radius)# help Displays help. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 32 Configuration Commands (a - d) admin-radius Table 6. Commands related to ruckus(config-radius-service) Syntax and Type Parameters (if any) Description ruckus(config-admin-radius)# ip Sets the IP addresses of the primary RADIUS server. Sets the RADIUS server name. backup Disables the backup RADIUS support. Type: Privileged ruckus(config-admin-radius)# name Type: Privileged ruckus(config-admin-radius)# no Type: Privileged ruckus(config-admin-radius)# port Type: Privileged ruckus(config-admin-radius)# realm Type: Privileged ruckus(config-admin-radius)# service Type: Privileged ruckus(config-admin-radius)# shared-secret Type: Privileged Sets the port addresses of the primary RADIUS server. Multiple realms Sets the realms. supported. Use a comma (,) to separate realms (example:home1,home2) : Multiple Sets the services. services supported. Use a comma (,) to separate services (example:home1,home2) Shared Sets the shared secret of the primary RADIUS server. secret between 1 and 255. ruckus(config-admin-radius)# test [CHAP | Type: Privileged PAP] Tests the RADIUS server based on the user credentials. ruckus(config-admin-radius)# type [ radius | tacacs ] Sets the admin authentication type, Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 33 Configuration Commands (a - d) ap ap To update the AP configuration, use the following commands: ruckus(config)# ap ruckus(config)# ap pre-prov > > ruckus(config)# ap swap > > Syntax Description This command uses the following syntax: lock : AP MAC address lock: Lock AP pre-prov : AP MAC address pre-prov: Update Pre-provision configuration swap : AP MAC address swap: Update Swap configuration trigger-swap : AP MAC address trigger-swap: Trigger swap action approve : AP MAC address approve: Approve AP to go ahead registration process Default This command has no default settings. Command Mode Config Example ruckus(config)# ap mac SZ100-Node1(config)# ap A1:87:45:34:56:FE ruckus(config)# ap pre-prov > SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 34 Configuration Commands (a - d) ap SZ100-Node1(config)# ap pre-prov import ftp:// ruckus:ruckus1!@172.19.7.100/backup/AP_ad8745345 ruckus(config)# ap swap > SZ100-Node1(config)# ap swap export ftp:// ruckus:ruckus1!@172.19.7.100 Related Commands • Table 7 lists the related ap profile configuration commands. • Table 8 lists the related ap model configuration commands. • Table 10 lists the related ap model lan1 configuration commands. Table 7 lists the related ap profile configuration commands. Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) Description ruckus(config-ap)# admin Sets the administrative logon credentials. Sets the administrative mode to either locked or unlocked. Sets the access point administration login credentials. Sets the model specification (overrides the zone configuration). Sets the access point administrative password. Sets the user location information of LAC or TAC. Type: Privileged ruckus(config-ap)# admin-mode Type: Privileged ruckus(config-ap)# ap-logon Type: Privileged ruckus(config-ap)# ap-model Type: Privileged ruckus(config-ap)# ap-password Type: Privileged ruckus(config-ap)# area-code Type: Privileged ruckus(config-ap)# ap-snmpoptions Sets the AP SNMP options. Type: Privileged ruckus(config-ap)# bonjourgateway Enables the bonjour gateway. Type: Privileged ruckus(config-ap)# bonjour-policy Enables the bonjour policy. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 35 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) Description ruckus(config-ap)# channelevaluation-interval :The interval value (Range: 60-3600 sec) Sets the channel evaluation interval. Type: Privileged ruckus(config-ap)# channel-select- 2.4g ${value}: 2.4GHz mode radio Sets a mode to automatically adjust AP channels. Type: Privileged 5g ${value}: 5GHz radio ruckus(config-ap)# channelflymtbc 2.4g : 2.4GHz Set MTBC value of ChannelFly radio Type: Privileged : MTBC value (Range:100~1440) 5g : 5GHz radio SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 36 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) Description ruckus(config-ap)# clientadmission-control 2.4g Enables the client admission control. Type: Privileged 2.4g minClientCount 5g Min Client Count (Default: 10) 2.4g maxRadioLoad Max Radio Load (Default: 75%) 2.4g minClientThroughput : Min Client Throughput (Default: 0.0Mbps) 5g minClientCount Min Client Count (Default: 20) 5g maxRadioLoad Max Radio Load (Default: 75%) 5g minClientThroughput Min Client Throughput (Default: 0.0Mbps) ruckus(config-ap)# description Sets the model specification (overrides the zone configuration). [ ipv6 | ipv4 ] Sets the device IP mode. Type: Privileged ruckus(config-ap)# device-ipmode Type: Privileged ruckus(config-ap)# do Executes the do command. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 37 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) ruckus(config-ap)# end Description Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-ap)# exit Exits from the EXEC. Type: Privileged ruckus(config-ap)# gps Sets the GPS coordinates to latitude and longitude values. Sets the GPS coordination latitude. Type: Privileged Sets the GPS coordination longitude. ruckus(config-ap)# help Displays help. Type: Privileged ruckus(config-ap)# gps-latitude Type: Privileged ruckus(config-ap)# gps-longitude Type: Privileged ruckus(config-ap)# hotspot20 Type: Privileged [ swe | cze | spa Sets the hotspot 2.0 settings. | eng | chi | ger | fre | jpn | dan | tur ] : Name swe: Swedish cze: Czech spa: Spanish eng: English chi: Chinese ger: German fre: French jpn: Japanese dan: Danish tur: Turkish ruckus(config-ap)# ip Type: Privileged address and secondary DNS servers. name-server secondary SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 38 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) ruckus(config-ap)# ip6 [ keep | auto ]: Retains the Sets the AP IPv6 address. AP settings Type: Privileged Description static Sets the location. Sets the additional information for location. [ disable | mesh | root | auto ] Sets the mesh mode to either: Type: Privileged ruckus(config-ap)# locationadditional-info Type: Privileged ruckus(config-ap)# mesh Type: Privileged • disable: Disable • mesh: Mesh AP • root: Root AP • auto: Auto ruckus(config-ap)# model Sets the model specifications. It overrides the zone configuration. Type: Privileged ruckus(config-ap)# name Sets the AP name. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 39 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) Description ruckus(config-ap)# no admin Disables the configuration. Type: Privileged bonjour-gateway channel-evaluationinterval channel-select-mode client-admission-control description gps ...................................continued hotspot20 ip ip6 location location-additional-info ruckus(config-ap)# no model Type: Privileged override-ap-mgmt-vlan Disables the configuration. channel-select-mode override-clientadmission-control override-smart-mon override-syslog-opt override-zone-location override-zone-locationadditional-info radio smart-mon swap-in-ap syslog uplink-ap venue-profile SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 40 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) Description ruckus(config-ap)# override-apmgmt-vlan Override AP Management VLAN. <2.4g> : 2.4 GHz radio Type: Privileged Overrides the auto channel selection mode and channelFly MTBC. ruckus(config-ap)# override-client- <2.4g> <5g> admission-control Overrides the client admission control. Type: Privileged ruckus(config-ap)# overridechannel-select-mode <5g> : 5 GHz radio Type: Privileged ruckus(config-ap)# override-smartmon Overrides the smart monitor. Type: Privileged ruckus(config-ap)# overridesyslog-opt Override Syslog options Type: Privileged ruckus(config-ap)# override-zonelocation Overrides the zone location settings. Type: Privileged ruckus(config-ap)# override-zonelocation-additional-info Overrides the zone’s additional information setting on location. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 41 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) Description ruckus(config-ap)# radio 2.4g channel Sets the radio channels. Type: Privileged 5g channel 2.4g channelization 5g channelization 2.4g tx-power 5g tx-power 2.4g wlan-service 5g wlan-service 2.4g wlan-group 5g wlan-group 2.4g roam [ enable | disable ] 5g roam [ enable | disable ] ruckus(config-ap)# smart-mon interval Enables the smart monitor. Type: Privileged threshold ruckus(config-ap)# swap-in-ap Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 Sets the AP Mac IP address for swap-in. 42 Configuration Commands (a - d) ap Table 7. Commands related to ruckus(config-ap). Syntax and Type Parameters (if any) ruckus(config-ap)# syslog enable Sets the syslog server. Enable the syslog server Type: Privileged Description enable [ Local2 | Keep Original | Local1 | Local5 | Local6 | Local0 | Local7 | Local3 | Local4 ] [ Error | Critical | Warning | All | Alert | Notice | Info | Emergency ] disable - Disables the syslog server ruckus(config-ap)# uplink [ smart | manual ] Type: Privileged ruckus(config-ap)# uplink-ap Sets the uplink to manual access point. Type: Privileged ruckus(config-ap)# venue-profile Sets the uplink selection to either smart or manual. Sets the venue profile Moves the access point to another zone. Type: Privileged ruckus(config-ap)# zone Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 43 Configuration Commands (a - d) ap Table 8 lists the related to ap-model configuration commands. Table 8. Commands related to ruckus(config-ap-model) Syntax and Type Parameters (if any) ruckus(config-ap-model)# do Description Executes the do command. Type: Privileged ruckus(config-ap-model)# end Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-ap-model)# exit Exits from the EXEC. Type: Privileged ruckus(config-ap-model)# ext-ant 2.4g - 2.4 with Enables the external antenna. DBI number Type: Privileged 2.4gg [ 3 | 2 ] 3/2 antennas 5g - 5g with DBI number 5gg [ 2 | 3 ] 5gg with 2/3 antennas ruckus(config-ap-model)# help Displays help. Type: Privileged ruckus(config-ap-model)# internalheater Enables the internal heater. Type: Privileged ruckus(config-ap-model)# lan1 ruckus(config-ap-model)# lan2 Sets the LAN configurations from 1 to 5. ruckus(config-ap-model)# lan3 ruckus(config-ap-model)# lan4 ruckus(config-ap-model)# lan5 Type: Privileged ruckus(config-ap-model)# led Enables the status of LEDs. Type: Privileged ruckus(config-ap-model)# ledmode Sets the LED mode. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 44 Configuration Commands (a - d) ap Table 8. Commands related to ruckus(config-ap-model) Syntax and Type Parameters (if any) ruckus(config-ap-model)# lldp Description Enables link layer discovery protocol. Type: Privileged ruckus(config-ap-model)# lldp-ad- interval Sets the LLDP advertise interval. Type: Privileged ruckus(config-ap-model)# lldphold-time Sets the LLDP hold time. Type: Privileged ruckus(config-ap-model)# lldpmgmt Enables LLDP management IP TLV. Type: Privileged ruckus(config-ap-model)# no ext-ant Type: Privileged internal-heater Disables or deletes the settings that have been configured. lan1 lan2 lan3 lan4 lan5 led lldp lldp-mgmt poe-operating-mode poe-out-port radio-band usb ruckus(config-ap-model)# poeoperating-mode Switches the PoE mode. Type: Privileged ruckus(config-ap-model)# poeout-port Enables the PoE out port. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 45 Configuration Commands (a - d) ap Table 8. Commands related to ruckus(config-ap-model) Syntax and Type Parameters (if any) Description ruckus(config-ap-model)# radioband ${value} Switches the radio band. [ enable | disable] Sets the USB port for a specific AP model. Type: Privileged ruckus(config-ap-model)# usb Type: Privileged Table 9 lists the related to ap-model-lan1 configuration commands. Table 9. Commands related to ruckus(config-ap-model-lan1) Syntax and Type Parameters (if any) Description ruckus(config-ap-model-lan1)# 8021x <802.1x-type> Sets 802.1x. Sets the authentication service configurations. Sets the authentication service configurations. Type: Privileged ruckus(config-ap-model-lan1)# acct-service Type: Privileged ruckus(config-ap-model-lan1)# auth-service Type: Privileged ruckus(config-ap-model-lan1)# do Executes the do command. Type: Privileged ruckus(config-ap-model-lan1)# end Type: Privileged ruckus(config-ap-model-lan1)# exit Ends the current configuration session and returns to privileged EXEC mode. Exits from the EXEC. Type: Privileged ruckus(config-ap-model-lan1)# help Displays help. Type: Privileged ruckus(config-ap-model-lan1)# no overwrite Does not permit overwriting. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 46 Configuration Commands (a - d) ap-auto-approve Table 9. Commands related to ruckus(config-ap-model-lan1) Syntax and Type Parameters (if any) ruckus(config-ap-model-lan1)# mac-bypass Description Sets the MAC bypass. Type: Privileged ruckus(config-ap-model-lan1)# members Sets the AP model configurations. Type: Privileged ruckus(config-ap-model-lan1)# no acct-service Disables or deletes the settings that have been configured. Type: User mac-bypass ruckus(config-ap-model-lan1)# profile : Ethernet port profile. Sets the Ethernet port profile. ruckus(config-ap-model-lan1)# supplicant mac Sets the supplicant. Type: Privileged custom ruckus(config-ap-model-lan1)# type [trunk-port | access-port | Sets the port type. general-port] Type: Privileged Type: Privileged ruckus(config-ap-model-lan1)# vlan-untag-id Sets the VLAN untag ID. : VLAN members Sets the VLAN members. Type: Privileged ruckus(config-ap-model-lan1)# vlan-members Type: Privileged ap-auto-approve To enable auto approve, use the following command: ruckus(config)# ap-auto-approve Syntax Description This command has no arguments or keywords SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 47 Configuration Commands (a - d) ap-auto-approve Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# ap-auto-approve Successful operation SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 48 Configuration Commands (a - d) ap-auto-tagging ap-auto-tagging To setup critical access point auto tagging rules or to enable auto tagging critical access points, use the following command: ruckus(config)# ap-auto-tagging Syntax Description This command has no arguments or keywords Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# ap-auto-tagging SZ100-Node1(config-ap-auto-tagging)# Related Commands Table 10 lists the related to ap-auto-tagging configuration commands. exi Table 10. Commands related to ruckus(config-ap-auto-tagging) Syntax and Type Parameters (if any) ruckus(config-ap-auto-tagging)# do Description Executes the do command. Type: Privileged ruckus(config-ap-auto-tagging)# enable Enables the auto tagging for critical APs. Type: Privileged ruckus(config-ap-auto-tagging)# end Type: Privileged ruckus(config-ap-auto-tagging)# exit Ends the current configuration session and returns to privileged EXEC mode. Exits from the EXEC. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 49 Configuration Commands (a - d) ap-cert-check Table 10. Commands related to ruckus(config-ap-auto-tagging) Syntax and Type Parameters (if any) ruckus(config-ap-auto-tagging)# help Description Displays help. Type: Privileged ruckus(config-ap-auto-tagging)# no Disables the auto tagging for critical APs. Type: Privileged ruckus(config-ap-auto-tagging)# rule Type: Privileged ruckus(config-ap-auto-tagging)# threshold - Traffic Selects the auto tagging rule. To bytes exceeds threshold view this command the ap-autorule tagging should be enabled. Disables the auto tagging for critical APs. To view this command the ap-auto-tagging should be enabled. [m|g] Sets the unit to either mega bytes or giga bytes. Type: Privileged ruckus(config-ap-auto-tagging)# unit Type: Privileged ap-cert-check To enable the access point certificate check, use the following command: ruckus(config)# ap-cert-check Syntax Description This command has no arguments or keywords. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# ap-cert-check Successful operation SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 50 Configuration Commands (a - d) ap-certificate-reset ap-certificate-reset To the AP certificate request which failed to update the certificate, use the following command: ruckus(config)# ap-certificate-reset Syntax Description This command has no arguments or keywords. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# ap-certificate-reset ap-control-mgmt-tos To enable the access control and management traffic type of service and values, use the following command: ruckus(config)# ap-control-mgmt-tos Syntax Description This command has no arguments or keywords. Default This command uses the following syntax: value: TOS value Command Mode Config Example SZ100-Node1(config)# ap-control-mgmt-tos 10 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 51 Configuration Commands (a - d) ap-heartbeat ap-heartbeat To setup the access point heartbeat, use the following command: ruckus(config)# ap-heartbeat Syntax Description This command uses the following syntax: seconds: Interval in seconds, which the AP sends the heartbeat to the controller such as: 30, 60, 150 and 300 Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# ap-heartbeat 30 app-denial-policy To create or update an Application Denial Policy, use the following command: ruckus(config)# app-denial-policy Syntax Description This command has the following parameter: : application name Default This command has no default settings. Command Mode Privileged Example SZ100-Node1(config)# app-denial-policy xyz SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 52 Configuration Commands (a - d) app-port-mapping Related Commands Table 11 lists the related app-denial-policy configuration commands. Table 11. Commands related to ruckus(config-app-denial-policy) Syntax and Type Parameters (if any) ruckus(config-app-denial-policy)# description Description Sets the description. Type: Privileged ruckus(config-app-denial-policy)# rule Creates/Updates Application Denial Policy rule Type: Privileged ruckus(config-app-denial-policy)# rule no Removes Application Denial Policy rule. Type: Privileged Table 12 lists the related app-denial-policy-rule configuration commands. Table 12. Commands related to ruckus(config-app-denial-policy-rule) Syntax and Type Parameters (if any) Description ruckus(config-app-denial-policyrule)# applicationtype [ port | http-domain-name Sets the application type. ] Type: Privileged port: Port http-domain-name: HTTP domain name ruckus(config-app-denial-policyrule)# content Sets the content. Type: Privileged app-port-mapping To create or update application port mapping, use the following command: ruckus(config)# app-port-mapping Syntax Description This command has the following parameter: : application name SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 53 Configuration Commands (a - d) app-port-mapping Default This command has no default settings. Command Mode Privileged Example SZ100-Node1(config)# app-port-mapping abc Related Commands Table 13 lists the related app-port-mapping configuration commands. Table 13. Commands related to ruckus(config-app-port-mapping) Syntax and Type Parameters (if any) Description ruckus(config-app-portmapping)# port : Port Sets the port. [tcp | udp] Sets the protocol Type: Privileged ruckus(config-app-portmapping)# protocol Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 54 Configuration Commands (a - d) cert-store cert-store To create or update certificate configurations, use the following command: ruckus(config)# cert-store ap-cert ruckus(config)# cert-store cert ruckus(config)# cert-store csr ruckus(config)# cert-store hotspot-cert ruckus(config)# cert-store web-cert Syntax Description This command uses the following syntax: ap-cert : Create / updates the AP port certificate cert : Create / updates the certificate configuration csr : Create / updates CSR (Certificate Signing Request) configuration hotspot-cert : Sets the hotspot certificate web-cert : Sets the management web certificate Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# cert-store cert apcert SZ100-Node1(config-cert)# Related Commands Table 14 lists the related cert-store configuration commands. Table 14. Commands related to ruckus(config-cert-store) configuration Syntax and Type Parameters (if any) Description ruckus(config-cert-store)# cert Uploads the certificate file. Type: Privileged append ruckus(config-cert-store)# city Sets the city Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 55 Configuration Commands (a - d) cert-store Table 14. Commands related to ruckus(config-cert-store) configuration Syntax and Type Parameters (if any) Description ruckus(config-cert-store)# common-name Sets the domain name Type: Privileged ruckus(config-cert-store)# country Sets the country. Type: Privileged ruckus(config-cert-store)# description Sets the description Type: Privileged ruckus(config-cert-store# do Executes the do command. Type: Privileged ruckus(config-cert-store)# email Sets the email address. Type: Privileged Type: Privileged ruckus(config-cert-store)# end Ends the current configuration session and return to privileged EXEC mode. ruckus(config-cert-store)# exit Exits from the EXEC. Type: Privileged ruckus(config-cert-store)# help Displays help. Type: Privileged ruckus(config-cert-store)#intercert :FTP URL Upload intermediate CA certificate. Type: Privileged format: ftp:// : @ / ruckus(config-cert-store)# no inter-cert Type: Privileged root-cert ruckus(config-cert-store)# organization Sets the organization. Sets the key passphrase. Disables all commands. Type: Privileged ruckus(config-cert-store)# passphrase Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 56 Configuration Commands (a - d) changepassword Table 14. Commands related to ruckus(config-cert-store) configuration Syntax and Type Parameters (if any) ruckus(config-cert-store)# private- upload key Type: Privileged csr ruckus(config-cert-store)# rootcert :FTP URL format: ftp:// : @ / Type: Privileged Description Sets the private key. Select the root certificate. Sets the certificate type to trusted root certificate. ruckus(config-cert-store)# rootcert-type Type: Privileged ruckus(config-cert-store)# server- :FTP URL cert format: ftp:// Upload server certificates. Type: Privileged : @ / ruckus(config-cert-store)# state Sets the state Sets the organization unit. Type: Privileged ruckus(config-cert-store)# unit Type: Privileged changepassword To change the administrative password, use the following command: ruckus(config)# changepassword Syntax Description This command uses the following syntax: old password: Existing password new password: Changed password. The password must contain at least eight characters with at least one number, one letter, and one special character (~ ! @ # $ % ^ & * ( ) - _ = + [ ] { } \ | ; : ' " , . < > / ?) except ` or $(. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 57 Configuration Commands (a - d) clock Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# changepassword Old Password: ******* New Password: ******* clock To update the system clock or the timezone configuration, use the following command: ruckus(config)# clock timezone Syntax Description This command uses the following syntax: timezone: Sets the system clock timezone : Timezone name of the domain Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# clock timezone Africa/Nairobi SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 58 Configuration Commands (a - d) cluster-ip-list cluster-ip-list To update the node IP address mapping list of the cluster configuration, use the following command: ruckus(config)# cluster-ip-list Syntax Description This command uses the following syntax: ip-mappings: Node IP mapping list, which is space separated. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# cluster-ip-list : : SZ100-Node1(config)# cluster-ip-list 172.19.18.96:172.19.13.56 172.19.15.67:172.19.10.07 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 59 Configuration Commands (a - d) cluster-name cluster-name To change the cluster name, use the following command: ruckus(config)# cluster-name Syntax Description This command uses the following syntax: cluster-name: Change the cluster name. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# cluster-name cls1 cluster-redundancy To create or update a cluster redundancy configuration, use the following command: ruckus(config)# cluster-redundancy Syntax Description This command has no arguments or keywords Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# cluster-redundancy Related Commands • Table 15 lists the related cluster redundancy configuration commands. • Table 16 lists the related cluster redundancy cluster configuration commands. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 60 Configuration Commands (a - d) cluster-redundancy Table 15 lists the related cluster redundancy configuration commands. Table 15. Commands related to ruckus(config-cluster-redundancy) Syntax and Type Parameters (if any) Description ruckus(config-clusterredundancy)# cluster Create or update the cluster redundancy configuration. Type: Privileged priority [ up | down ] ruckus(config-clusterredundancy)# do Executes the do command. Type: Privileged ruckus(config-clusterredundancy)# enable Enables the cluster redundancy configuration. Type: Privileged ruckus(config-clusterredundancy)# end Ends the current configuration session and returns to privileged EXEC mode. Type: Privileged ruckus(config-clusterredundancy# exit Exits from the EXEC. Type: Privileged ruckus(config-clusterredundancy)# help Displays the help. Type: Privileged ruckus(config-clusterredundancy)# no cluster Deletes cluster redundancy configurations. Disables cluster redundancy. Type: Privileged ruckus(config-clusterredundancy)# no enable Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 61 Configuration Commands (a - d) cluster-redundancy Table 16 lists the related cluster redundancy cluster configuration commands. Table 16. Commands related to ruckus(config-cluster-redundancy-cluster) Syntax and Type Parameters (if any) ruckus(config-cluster-redundancycluster)# do Description Executes the do command. Type: Privileged ruckus(config-cluster-redundancycluster)# dual-list Type: Privileged ruckus(config-cluster-redundancycluster)# end Sets the dual address list. List format: IPv4 address/IPv6 address,IPv4 address,IPv6 address Ends the current configuration session and returns to privileged EXEC mode. Type: Privileged ruckus(config-cluster-redundancycluster)# exit Exits from the EXEC. Type: Privileged ruckus(config-cluster-redundancycluster)# help Displays the help. Type: Privileged ruckus(config-cluster-redundancycluster)# name Sets the cluster name. Type: Privileged ruckus(config-cluster-redundancycluster)# ip-list Type: Privileged : Control IPs. Sets the Control IP list. Comma separated IP list. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 62 Configuration Commands (a - d) dns-server-service dns-server-service To create or update DNS server services, use the following command. ruckus(config)# dns-server-service Syntax Description This command has the following keywords: : DNS server service name Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# dns-server-service xy Related Commands Table 17 lists the related dns-server-service configuration commands. Table 17. Commands related to ruckus(dns-server-service) Syntax and Type Parameters (if any) ruckus(config-dns-server-service)# description Description Sets description. Type: Privileged ruckus(config-dns-server-service)# do Executes the do command. Type: Privileged ruckus(config-dns-server-service)# exit Exits from the EXEC. Type: Privileged ruckus(config-dns-server-service)# end Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 Ends the current configuration session and returns to the privileged EXEC mode. 63 Configuration Commands (a - d) do Table 17. Commands related to ruckus(dns-server-service) Syntax and Type Parameters (if any) ruckus(config-dns-server-service)# help Description Displays help. Type: Privileged ruckus(config-dns-server-service)# name Sets the DNS server services name. Type: Privileged ruckus(config-dns-serverservice)## no Disable and delete commands. Type: Privileged ruckus(config-dns-server-service)# primary-ip Sets the primary IP address. Type: Privileged ruckus(config-dns-serverservice)## secondary-ip Type: Privileged Sets the secondary IP address. ruckus(config-dns-server-service)# no description Delete the description. Type: Privileged ruckus(config-dns-server-service)# no primary-ip Deletes the primary IP address. Type: Privileged ruckus(config-dns-serverservice)## no secondary-ip Type: Privileged Deletes the secondary IP address. do To setup the do command, use the following command. ruckus(config)# do Syntax Description This command has no arguments or keywords. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 64 Configuration Commands (a - d) dp-group Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# do dp-group To enable and sets the data plane grouping, use the following command. ruckus(config)# dp-group Syntax Description This command uses the following syntax: : Dataplane groups, which is comma separated DP MAC addresses in a group. For example, 3 DP value is seen as “,”. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# dp-group dp1-172.19.7.100 dp2-172.19.8.120 SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 65 3 Configuration Commands (e-r) This chapter describes the commands that you can use to configure, enable, and disable various components of the controller. The following table lists the commands. NOTE: For easy access and reading, the configuration chapter has been split into 3 chapters based on the alphabetical order of commands. Table 18. Configuration commands encrypt-mac-ip encrypt-zone- end name eth-portvalidate-onetrunk event event dbpersistence event email event snmpnotification event-email event-threshold exit ftp-server ftp-test help hostname identity-provider interface ip ip control-nat ip name-server ip name-server- ip route ipv6 ip route-ipv6 ipsec-profile lbs-service ldap-service license license cloud license export license local license syncnow lineman localdb-service logging console lwapp2scg mgmt-acl no ad-service no admin no admin-radius no ap no ap autoapprove no ap autotagging no ap-controlmgmt-tos no ap-group no block-client no bonjourfencing no bonjour-fencingpolicy no bonjourgateway no bonjourpolicy no cert-store no data-plane license import no device-policy no diffserv no controlplane no dns-server- no dp-group service SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 no ap-cert-check no encrypt-mac-ip 66 Configuration Commands (e-r) Table 18. Configuration commands no encryptzone-name no ethernetport-profile no event no hotspot no hotspot20- no hotspot20- no identityvenue-profile wlan-profile provider no ip no ipsecprofile no l2-acl no lbs-service no ldap-service no lineman no logging no oauthservice no operatorprofile no osu-portalprofile no outbound firewall no proxy-aaa no report no role no sci-profile no snmpnotification no snmp-v2community no snmp-v3user no user-agent- no user-group blacklist no user-role no user-traffic- no vlan-pooling no webno wlan profile authentication no wlan-group no wlanscheduler ntp-server oauth-service operator-profile outboundfirewall rebalance-aps report no zone no ftp-server northboundauthtype no guest-access no interface northbound-portal proxy-aaa rks-gre SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 67 Configuration Commands (e-r) encrypt-mac-ip encrypt-mac-ip To enable encryption of MAC and IP address for Wireless Internet Service Provider roaming (WISPr) enriched URL, use the following command. ruckus(config)# encrypt-mac-ip Syntax Description This command has no arguments or keywords. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# encrypt-mac-ip Successful operation encrypt-zone-name To enable AP Zone name encryption for Wireless Internet Service Provider roaming (WISPr) enriched URL, use the following command. ruckus(config)# encrypt-zone-name Syntax Description This command has no arguments or keywords. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# encrypt-zone-name Successful operation SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 68 Configuration Commands (e-r) eth-port-validate-one-trunk eth-port-validate-one-trunk To update the validator for an AP with at least one trunk port, use the following command. ruckus(config)# eth-port-validate-one-trunk Syntax Description This command has the following keywords: disable: Disable the validator for the AP with at least one trunk port enable: Enable the validator for the AP with at least one trunk port Default This command has no default settings. Command Mode Config Example ruckus(config)# eth-port-validate-one-trunk end To end the current session and returns to privileged EXEC mode, use the following command. ruckus(config)# end Syntax Description This command has no arguments or keywords. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# end SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 69 Configuration Commands (e-r) event event To update the event notification configuration, use the following command. ruckus(config)# event Syntax Description This command uses the following syntax: : Single configuration event notification Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# event 1002 Related Commands Table 19 lists the related event configuration commands. Table 19. Commands related to ruckus(config-event) Syntax and Type Parameters (if any) ruckus(config-event)# dbpersistence Description Enables the data blade persistence for the event. Type: Privileged ruckus(config-event)# do Executes the do command. Type: Privileged ruckus(config-event)# email Enables the email notification. Type: Privileged ruckus(config-event)# end Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-event)# exit Exits from the EXEC. Type: Privileged ruckus(config-event)# help Displays the help. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 70 Configuration Commands (e-r) event db-persistence Table 19. Commands related to ruckus(config-event) Syntax and Type Parameters (if any) Description ruckus(config-event)# no db-persistence Enables the SNMP trap. Type: Privileged email snmp-trap ruckus(config-event)# snmp-trap Enables the SNMP trap. Type: Privileged event db-persistence To enable data base persistence for the event, use the following command. ruckus(config)# event db-persistence Syntax Description This command has no arguments or keywords. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# event db-persistence No. Event Code Category Type Description Severity SNMP Email DB Persistence ----- ----------- ------------------------ ---------------------1 103 AP Communication AP managed This event occurs when AP is approved by the SmartZone. Informational Disabled Disabled Enabled 2 105 AP Communication AP rejected This event occurs when AP is rejected by the SmartZone.Minor Enabled Disabled Enabled 3 106 AP Communication AP firmware updated This event occurs when AP successfully updates its firmware. Informational Disabled Disabled Enabled SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 71 Configuration Commands (e-r) event email event email To enable event triggers for selected email notification, use the following command. ruckus(config)# event email Syntax Description This command has no arguments or keywords. Command Mode Config Example SZ100-Node1(config)# event email No. Event Code Category Type Description Severity SNMP Email DB Persistence ----- ----------- ------------------------ ---------------------1 103 AP Communication AP managed This event occurs when AP is approved by the SmartZone Informational Enabled Enabled Enabled . 2 105 AP Communication AP rejected This event occurs when AP is rejected by SmartZone Minor Enabled Enabled Enabled 3 106 AP Communication AP firmware updated This event occurs when AP successfully updates its firmware Informational Enabled Enabled Enabled Please choose Event Codes (separated by ',') to enable Event to trigger Email: SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 72 Configuration Commands (e-r) event snmp-notification Related Commands Table 20 lists the related event-email configuration commands. Table 20. Commands related to ruckus(config-event-email) Syntax and Type Parameters (if any) ruckus(config-event-email)# enable Description Enables notification email for events. Type: Privileged ruckus(config-event-email)# mail- email address to Email address configuration. Type: Privileged ruckus(config-event-email)# no enable Disables the email notification for events. Type: Privileged ruckus(config-event-email)# no mail-to Disables email address configuration. Type: Privileged event snmp-notification To enable selected SNMP notification, use the following command. ruckus(config)# event snmp-notification Syntax Description This command has no arguments or keywords. Command Mode Config Example SZ100-Node1(config)# event snmp-notification No. Event Code Category Type Description Severity SNMP Email DB Persistence ----- ----------- ------------------------ ---------------------1 103 AP Communication AP managed This event occurs when AP is approved by the SmartZone Informational Enabled Enabled Enabled . SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 73 Configuration Commands (e-r) event-email event-email To setup the event to email services, use the following command. ruckus(config)# event-email Syntax Description This command has no arguments or keywords. Command Mode Config Example SZ100-Node1(config)# event-email SZ100-Node1(config-event-email)# Related Commands Table 21 lists the related event-email configuration commands. Table 21. Commands related to ruckus(config-event-email) Syntax and Type Parameters (if any) ruckus(config-event-email)# do Description Enables the do command. Type: Privileged ruckus(config-event-email)# enable Enables the email notifications for events. Type: Privileged ruckus(config-event-email)# end: Privileged End the current configuration session and returns to the privileged EXEC mode. ruckus(config-event-email)# exit Privileged Exit from the EXEC. ruckus(config-event-email)# help Privileged Display the help message. ruckus(config-event)# mail-to Sets the email address configuration. ruckus(config-event)# no enable Disables various options. Type: Privileged mail-to Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 74 Configuration Commands (e-r) event-threshold event-threshold To update the event threshold configuration, use the following command. ruckus(config)# event-threshold Syntax Description This command has no arguments or keywords. Command Mode Config Example SZ100-Node1(config)# event-threshold thres SZ100-Node1(config-event-threshold)# Related Commands Table 22 lists the related event-threshold configuration commands. Table 22. Commands related to ruckus(config-event-threshold) Syntax and Type Parameters (if any) ruckus(config-event-threshold)# do Description Enables the do command. Type: Privileged ruckus(config-event-threshold)# end: Privileged End the current configuration session and returns to the privileged EXEC mode. ruckus(config-event-threshold)# exit Exit from the EXEC. Type: Privileged ruckus(config-event-threshold)# help Display the help message. Type: Privileged ruckus(config-threshold)# unit Sets the threshold unit. Type: Privileged ruckus(config-threshold)# value Sets the threshold value. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 75 Configuration Commands (e-r) exit exit To exit from the EXEC, use the following command. ruckus(config)# exit Syntax Description This command has no arguments or keywords. Command Mode Config Example SZ100-Node1(config)# exit ftp-server To update the FTP server for uploading reports configuration, use the following command. ruckus(config)# ftp-server Once you enter the config-ftp-server context, you can configure the rest of the FTP server settings (see example below). Syntax Description This command has no arguments or keywords Default This command has no default settings. Command Mode config Example SZ100-Node1(config)# ftp-server f1 SZ100-Node1(config-ftp-server)# SZ100-Node1(config-ftp-server)# host 1.1.1.1 SZ100-Node1(config-ftp-server)# port 21 SZ100-Node1(config-ftp-server)# username test SZ100-Node1(config-ftp-server)# password Password: **** SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 76 Configuration Commands (e-r) ftp-server Retype: **** SZ100-Node1(config-ftp-server)# exit SZ100-Node1(config)# Related Commands Table 23 lists the related ftp-server commands. Table 23. Commands related to ruckus(config-ftp-server) Syntax and Type Parameters (if any) ruckus(config-ftp-server)# do Description Executes the do command. Type: Privileged ruckus(config-ftp-server)# end Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-ftp-server)# exit Exits from the EXEC. Type: Privileged ruckus(config-ftp-server)# help Displays the help. Type: Privileged ruckus(config-ftp-server)# host Sets the FTP server IP address. Sets the FTP password. Sets the FTP server port. Type: Privileged ruckus(config-ftp-server)# password Type: Privileged ruckus(config-ftp-server)# port Type: Privileged ruckus(config-ftp-server)# protocol Sets the protocol. Type: Privileged ruckus(config-ftp-server)# remote- directory Sets the FTP remote directory. Type: Privileged ruckus(config-ftp-server)# test Test the FTP settings. Type: Privileged ruckus(config-ftp-server)# username Sets the user name. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 77 Configuration Commands (e-r) ftp-test ftp-test To test the FTP server connection, use the following command. ruckus(config)# ftp-test Syntax Description This command uses the following syntax: : FTP server name Default This command has no default settings. Command Mode config Example SZ100-Node1(config)# ftp-test FTP-SERVER Fail to connection to FTP server help To display the help message, use the following command. ruckus(config)# help Syntax Description This command has no arguments or keywords. Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# help admin Create/Update Administrator account configuration admin-radius Create/Update RADIUS server for Administrators ap-auto-approve Enable AP auto approve SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 78 Configuration Commands (e-r) hostname hostname To change the hostname, use the following command. ruckus(config)# hostname Syntax Description This command uses the following syntax: hostname: Changed hostname Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# hostname identity-provider To create or update identity provider configuration, use the following command. ruckus(config)# identity-provider Syntax Description This command uses the following syntax: name: Name of the identity provider Default This command has no default settings. Command Mode Config Example SZ100-Node1(config)# identity-provider idwlan SZ100-Node1(config-identity-provider)# SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 79 Configuration Commands (e-r) identity-provider Related Commands • Table 24 lists the related identity-provider configuration commands. • Table 25 lists the related identity-provider-acct-profile configuration commands. • Table 26 lists the related identity-provider-acct-profile-realm configuration commands. • Table 27 lists the related identity-provider-auth-profile configuration commands • Table 28 lists the related identity-provider-auth-profile-realm configuration commands. • Table 29 lists the related identity-provider-osu-enable configuration commands. • Table 30 lists the related identity-provider-realms configuration commands. • Table 31 lists the related identity-provider-realms-eaps configuration commands. • Table 32 lists the related identity-provider-realms-eaps-auth configuration commands Table 24 lists the related identity-provider configuration commands. Table 24. Commands related to ruckus(config-identity-provider) Syntax and Type Parameters (if any) ruckus(config-identity-provider)# acct-enable Description Enables accounting. Type: Privileged ruckus(config-identity-provider)# acct-profile Sets the accounting profile. Type: Privileged ruckus(config-identity-provider)# auth-profile Sets the authentication profile. Type: Privileged ruckus(config-identity-provider)# description Sets the description. Type: Privileged ruckus(config-identity-provider)# do Executes the do command. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 80 Configuration Commands (e-r) identity-provider Table 24. Commands related to ruckus(config-identity-provider) Syntax and Type Parameters (if any) ruckus(config-identity-provider)# end Description Ends the current configuration session and returns to privileged EXEC mode. Type: Privileged ruckus(config-identity-provider)# exit Exits from the EXEC. Type: Privileged Displays the help. ruckus(config-identity-provider)# help Type: Privileged ruckus(config-identity-provider)# home-ois Type: Privileged 5-hex Sets the Home OIs. 3-hex ruckus(config-identity-provider)# name Sets the identity provider name. ruckus(config-identity-provider)# no acct-enable Disables the commands. Type: Privileged osu-enable Type: Privileged home-ois plmns realms ruckus(config-identity-provider)# osu-enable Enables the online signup and provisioning. Type: Privileged ruckus(config-identity-provider)# plmns Sets the PLMNs. Sets the realms Type: Privileged ruckus(config-identity-provider)# realms Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 81 Configuration Commands (e-r) identity-provider Table 25 lists the related identity-provider-acct-profile configuration commands. Table 25. Commands related to ruckus(config-identity-provider-acct-profile) Syntax and Type Parameters (if any) Description ruckus(config-identity-provideracct-profile)# default no-match-realm acct Sets the default service. Type: Privileged no-realm acct ruckus(config-identity-provideracct-profile)# description Sets the description Type: Privileged Executes the do command. ruckus(config-identity-provideracct-profile)# do Type: Privileged ruckus(config-identity-provideracct-profile)# end Ends the current configuration session and returns to privileged EXEC mode. Type: Privileged ruckus(config-identity-provideracct-profile)# exit Exits from the EXEC. Type: Privileged ruckus(config-identity-provideracct-profile)# help Displays the help. Type: Privileged ruckus(config-identity-provideracct-profile)# no realm Disables the realm command. Sets the accounting service realm. Type: Privileged ruckus(config-identity-provideracct-profile)# realm Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 82 Configuration Commands (e-r) identity-provider Table 26 lists the related identity-provider-acct-profile-realm configuration commands. Table 26. Commands related to ruckus(config-acct-profile-realm) Syntax and Type Parameters (if any) Description ruckus(config-identity-provideracct-profile-realm)# acct-service Sets the accounting service. Type: Privileged ruckus(config-identity-provideracct-profile-realm)# do Executes the do command. Type: Privileged ruckus(config-identity-provideracct-profile-realm)# end Ends the current configuration session and returns to privileged EXEC mode. Type: Privileged ruckus(config-identity-provideracct-profile-realm)# exit Exits from the EXEC. Type: Privileged ruckus(config-identity-provideracct-profile-realm)# help Displays the help. Type: Privileged ruckus(config-identity-provideracct-profile-realm)# name Sets the realm name. Sets the accounting service realm. Type: Privileged ruckus(config-identity-provideracct-profile)# realm Type: Privileged Table 27 lists the related identity-provider-auth-profile configuration commands. Table 27. Commands related to ruckus(config-identity-provider-auth-profile) Syntax and Type Parameters (if any) ruckus(config-identity-provider auth-profile)# aaa-interim-acct-interval Description Sets the accounting interim interval for the hosted AAA server. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 83 Configuration Commands (e-r) identity-provider Table 27. Commands related to ruckus(config-identity-provider-auth-profile) Syntax and Type Parameters (if any) Description ruckus(config-identity-providerauth-profile)# aaa-session-idletimeout Sets the idle session timeout for the hosted AAA server. ruckus(config-identity-provider auth-profile)# aaa-session-timeout Sets the session timeout for the hosted AAA server. Type: Privileged Type: Privileged ruckus(config-identity-providerauth-profile)# aaa-support Enables the hosted AAA server support. Type: Privileged ruckus(config-identity-providerauth-profile)# default Type: Privileged no-match-realm acct Sets the default service. - Set to either RADIUS, local-database, na (request rejected) or radius. Set the authentication service name. no-realm acct Sets the default authentication service. ruckus(config-identity-providerauth-profile)# description Sets the description Type: Privileged ruckus(config-identity-providerauth-profile)# do Executes the do command. Type: Privileged ruckus(config-identity-providerauth- profile)# end Type: Privileged ruckus(config-identity-providerauth-profile)# exit Ends the current configuration session and returns to privileged EXEC mode. Exits from the EXEC. Type: Privileged SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 84 Configuration Commands (e-r) identity-provider Table 27. Commands related to ruckus(config-identity-provider-auth-profile) Syntax and Type Parameters (if any) ruckus(config-identity-providerauth-profile)# help Description Displays the help. Type: Privileged ruckus(config-identity-providerauth-profile)# gpp-support Sets the PLMN identifier. Type: Privileged Disables the commands. ruckus(config-identity-providerauth-profile)# no aaa-support Type: Privileged realm ruckus(config-identity-providerauth-profile)# realm Sets the authentication service realm. Sets the mobile country code. Sets the mobile network code. gpp-support Type: Privileged ruckus(config-identity-providerauth-profile)# sgsn-mcc Type: Privileged ruckus(config-identity-providerauth-profile)# sgsn-mnc Type: Privileged Table 28 lists the related identity-provider-auth-profile-realm configuration commands. Table 28. Commands related to ruckus(config-identity-provider-auth-profile-realm) Syntax and Type Parameters (if any) ruckus(config-identity-providerauth-profile-realm)# auth-method Description Sets the authorization method. Type: Privileged ruckus(config-identity-providerauth-profile-realm)# auth-service Type: Privileged Set to either RA- Sets the authentication service. DIUS, local-database, na (request rejected) or radius. Set the authentication service name. SZ-100 and vSZ-E CLI Reference Guide for SmartZone 3.5, 800-71293-001 85 Configuration Commands (e-r) identity-provider Table 28. Commands related to ruckus(config-identity-provider-auth-profile-realm) Syntax and Type Parameters (if any) ruckus(config-identity-providerauth-profile-realm)# do Description Executes the do command. Type: Privileged ruckus(config-identity-provider auth-profile-realm)# dynamic-vlan Sets the dynamic VLAN ID. Type: Privileged Ends the current configuration session and returns to privileged EXEC mode. ruckus(config-identity-providerauth- profile-realm)# end Type: Privileged ruckus(config-identity-providerauth-profile-realm)# exit Exits from the EXEC. Type: Privileged ruckus(config-identity-providerauth-profile-realm)# help Displays the help. Type: Privileged ruckus(config-identity-providerauth-profile-realm)# name