Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Onboard Switches to Mist Cloud

Follow these steps to claim new switches or adopt previously deployed switches into your organization. Ignore these steps if your switches are already onboarded to the Mist cloud.

Note:

Wired Assurance does not support Junos Flex images. To ensure compatibility, please verify that your switch is running a standard (non-Flex) Junos image. When upgrading a switch, we recommend doing so via the Mist cloud, which ensures that only a standard Junos image is deployed.

To configure and manage a switch through Juniper Mist cloud, you must onboard the switch into your organization.

You can onboard greenfield or brownfield switches to Mist:

  • Greenfield—New cloud-ready switches. Cloud-ready devices have a QR code or claim code on the chassis that you can scan to onboard the device quickly in the Juniper Mist portal.

  • Brownfield—Existing, in-service (brownfield) switches which are not cloud-ready but are still supported by Mist. These switches do not have a QR code attached. For devices that are not cloud-ready but still supported in Mist, you must enter some CLI commands locally in the switch to onboard (adopt) the device.

The switches use an HTTPS connection (TCP port 443) to send telemetry updates to the Juniper Mist cloud. In brownfield deployments, switches may initially use an SSH connection (TCP port 2200) during the adoption process before automatically transitioning to HTTPS over TCP port 443. SSH is also used when opening a remote shell to switches from the Utilities menu on the switch details page (Switches > Switch Name).

To forestall the chance of denial-of-service attacks or other possible SSH exploits, you can configure an upper limit of connections and/or sessions per connection on the switch. For Juniper EX and QFX series switches, the default value for ssh max-sessions-per-connection is 10, You can change that by issuing an Junos command such as the following:

Switch Onboarding Prerequisites

Before you onboard a switch:

  • Ensure that you have a Wired Assurance Subscription, and login credentials for the Juniper Mist portal. To get started with Mist, follow the instructions in Quick Start: Mist.

  • Ensure that the required switch administrator roles are assigned to you. For more information, refer to Switch Administrator Role Requirements.

  • Ensure that the switch is supported by Mist Wired Assurance. To see the supported switch models and software versions, refer to Hardware and Software Requirements for Your Wired Network.

  • Ensure that the switch is connected to a DNS server (an NTP server is also recommended), and is able to connect to the Juniper Mist cloud architecture over the Internet.

  • If there is a firewall between the cloud and the switch, allow outbound access on TCP port 2200 to the management port of the switch.

  • For a switch to establish a secure connection to the Mist cloud, ensure that the switch clock is synchronized with an accurate time source such as an NTP server.

  • (Applicable to CX Series switches) Before onboarding a Virtual Switching Framework (VSF) stack into Mist, ensure that VSF is fully configured using auto-stacking. Onboarding is supported only for VSF stacks configured in a ring topology. VSF settings cannot be modified through Mist.

Note: If the switch is operating in Mist monitor-only mode, ensure that all prerequisite configurations are applied through the switch CLI. For Mist-managed switches, make the required configuration changes through the Mist portal.

Onboard a Greenfield Switch

You can onboard one or more greenfield, cloud-ready switches using your computer, or a single switch using your mobile phone. The easiest way to onboard a single switch to the Mist cloud is by using the Mist AI Mobile App. To onboard multiple cloud‑ready switches together, use the Juniper Mist portal and enter the activation code linked to the purchase order.

To onboard a greenfield switch, follow the instructions in Quick Start: Cloud-Ready EX, QFX, and CX Switches with Mist.

For a quick demo, watch the following video:

Onboarding a Greenfield CloudReady EX switch is simple. In your inventory page, find the Switches tab. Click on Claim Switches.

Type in your switch's unique claim code, which can be found near the QR code at the front of the switch. Alternatively, you can also enter an activation code, which pulls all your newly purchased Juniper hardware from one order, rather than adding individual switch codes. Add and check for your desired settings, such as site assignment and configuration management.

Click Claim, and the switch has been added to the site. The EX3400 has been added. In the site view, you should see the switch appropriately assigned.

Notice that red indicates the switch is offline, but will turn green once it comes online. The switch is cloud-managed and accounted for as part of the health metrics above.

Onboard a Brownfield Switch (EX and QFX Series)

Use the Adopt Switch option to onboard a brownfield switch that is not cloud-ready or does not have a QR code. When you adopt a brownfield switch, you can have Mist manage it (recommended), which means any existing configuration will be replaced with settings made in the Mist console. Or, you can choose to not have Mist manage the switch, in which case the existing configuration will remain as is, plus some new settings for connecting to the cloud and telemetry. An unmanaged switch will be unique – configurations made in the Mist console will not be applied, nor will it benefit from the use of templates or site variables or any of the other conveniences available to managed devices. In addition, subsequent configurations made on the switch will not be "known" to Mist, so you may want to set up a warning message in the CLI to indicate it is part of the Mist environment, or limit who can make configuration changes so they don't conflict.

If Mist will manage the switch, that is, you select the Manage configuration with Mist option when onboarding it, be sure to back up the existing Junos OS configuration before adopting the switch. Do this by connecting to the switch, logging on to the CLI, and in Junos, running the request system configuration rescue save command to save the currently active configuration and any installation-specific parameters.

For virtual devices such as a vJunos-switch or legacy devices that predate the use of Mist claim codes on the hardware, you need to adopt, rather than claim them. Note that if the VM was previously claimed in one environment, such as Global02, it may not be available from the inventory or installed base of another environment or organization (this is because the MAC address may still be attached to the original environment.) You need to release the device from the original environment, or recreate the virtual device, which will generate a new virtual MAC for it.

In the procedure below, you will make configuration changes to the Juniper Mist portal, and also to the switch using the Junos OS CLI. Be sure you can log in to both environments.

Note:

An unmanaged switch still receives configurations from Mist to maintain connectivity with the Mist cloud. These include system scripts and extensions for efficient stats collection, system syslog settings for efficient logging on the device, and a user account named 'mist' for cloud communication.

To onboard a brownfield switch to the Mist cloud:

  1. Log in to your organization on the Juniper Mist cloud and then click Organization > Inventory in the menu.
  2. Select Switches at the top of the page that appears, and then click the Adopt Switch button in the upper-right corner to generate the Junos OS CLI commands needed for the interoperability. Ensure that the EX/QFX radio button is selected.
    Mist dashboard screenshot showing Switch Adoption pop-up with CLI command for adopting a Juniper switch. Navigation menu on left.

    The generated commands create a Juniper Mist user account, and an SSH connection to the Juniper Mist cloud over TCP port 2200 (the switch connection is initiated from a management interface and is used for setting up configuration and sending telemetry data).

  3. In the Switch Adoption window that appears, click the Copy to Clipboard icon to get the commands from the Juniper Mist cloud.
  4. Log in to the switch via Junos OS CLI.
  5. In the CLI, type edit to start configuration mode, and then paste the commands you just copied (type top if you are not already at the base level of the hierarchy).
  6. (Optional) If you want to add a system message, use the following command:
  7. Verify your updates on the switch by running show commands at the [system services] level of the hierarchy, and again at the [system login user mist] level of the hierarchy.
  8. Run the commit command to save the configuration.
    When onboarded to Mist, the new switch appears on the Inventory page.
  9. On the Juniper Mist portal, click Organization > Inventory > Switches and select the switch you just added.
  10. Click the More drop-down list at the top of the page, and then click the Assign to Site button.
  11. In the page that appears, choose which site you want to assign the switch to.
  12. Select the Manage configuration with Mist check box.
  13. Click Click Assign to Site.

    The onboarded switch, when assigned to a site, will appear on the Switches Page page with the status Connected.

    You can also run the show system connections command locally on the switch to check whether the switch is connected to Mist. This command shows an ESTABLISHED TCP session to Mist.

For a quick demo, watch the following video:

Adopting switches for brownfield environments only takes a few steps. In Organization, look for the Inventory tab and toggle to Switches. Click on Adopt Switches.

This brings up a clipboard of CLI commands to copy and paste into the console of a switch. Put in the config and commit it in the switch. Ensure that TCP port 2200 is open to the internet.

This allows for the switch to communicate with the Juniper Mist cloud. Check that it is connected properly by entering Show System Connection to see an established TCP session. Going back to the dashboard, you can see the EX switch online and fully cloud-managed.

Templates will also be inherited when you enable Configuration Management. Don't forget to save. Now you're good to go.

Adopting an EX switch to the Juniper Mist cloud from a brownfield environment is a straightforward process. Now you have the power and simplicity of a cloud-managed solution for your EX switches.

Onboard a Brownfield Switch (CX Series)

Use the Adopt Switch option to onboard a brownfield switch that is not cloud-ready or does not have a QR code. When you adopt a brownfield switch, you can have Mist manage it (recommended) or choose to not have Mist manage the switch. If you want Mist to manage the switch, be sure to back up the existing AOS-CX configuration before adopting the switch.

In the procedure below, you will make configuration changes to the Juniper Mist portal, and also to the switch using the AOS-CX CLI. Ensure that you can log in to both the environments.

Note:

An unmanaged switch still receives configurations from Mist to maintain connectivity with the Mist cloud. The configurations include a user account named 'mist' for cloud communication.

To onboard a brownfield switch to the Mist cloud:

  1. Log in to your organization on the Juniper Mist cloud and then click Organization > Inventory in the menu.
  2. Select Switches at the top of the page that appears, and then click the Adopt Switch button in the upper-right corner to generate the registration code needed for the interoperability.
  3. In the Switch Adoption window that appears, select the CX radio button to access the registration code.
    Switch Adoption interface with instructions to check switch requirements and CLI commands. CX option selected with mist registration-code field and Copy to clipboard button.
    Note: The registration code is valid for only 30 days.
  4. Click Copy to Clipboard to copy the registration code.
  5. Log in to the CX switch via CLI or SSH.
  6. Start the configuration mode and complete the following optional configurations if required:
    1. If you want to onboard a switch to the Mist cloud through a proxy server, configure the proxy details on the switch.
      Note:

      The proxy IPv4 address or fully-qualified domain name (FQDN) may be configured via either DHCP vendor-specific sub-option 148 or via the CLI.

      • FDQN format: http-proxy.network.com:8080
      • IPv4 address format: 192.168.1.254:8080

      If the proxy setting is received via DHCP option, the VRF on which the DHCP option was received is used automatically. When the HTTP proxy is manually configured via the CLI, a specific VRF (such as the mgmt VRF) can be specified to use the proxy connection. A manually configured HTTP proxy will override any proxy settings received from other sources.

      To configure the HTTP proxy via DHCP sub-option 148, a vendor class (option 60) must be defined on the DHCP server for each CX switch. To obtain the vendor class identifier, run the following command on the switch:

      A proxy is used by organizations that require all internet traffic to pass through a proxy server for security, while still using the cloud-hosted Mist platform for centralized management and monitoring.

    2. If you want to specify a VRF for connectivity, use the vrf-override command within the mist configuration context.

      When a VRF override is configured, the CXMA agent, which is equivalent to JMA (Junos Mist Agent) on EX and QFX Series switches, exclusively uses that VRF for connectivity to the Mist redirect sever and Mist cloud, regardless of connection failures.

    3. If you want to onboard the switch to the Mist cloud through a specific source interface IP, configure the interface details on the switch.

      This setup is used by organizations to control which interface the switch uses to connect to the Mist Cloud, often for routing, firewall, or network segmentation purposes in distributed switching infrastructures. If a source interface is configured for a VRF, the CXMA agent uses the specified source interface for outbound connections.

  7. Configure the registration code that you have copied from the Switch Adoption window in Mist.
    Note: The registration code is automatically removed from the switch after successful registration. It is not stored in the running or startup configuration and is used solely during the initial device registration process.
  8. Verify your updates on the switch by running show mist command on the switch.
  9. To verify if the switch is added to Mist, click Organization > Inventory > Switches to go to the inventory page which lists the switch you added.
  10. To assign the newly added switch to a site, select the switch from the inventory page.
  11. Click the More drop-down list at the top of the page, and then click the Assign to Site button.
  12. In the page that appears, choose which site you want to assign the switch to.
  13. Select the Manage configuration with Mist check box.
    Note:

    When Manage configuration with Mist is enabled on a CX switch, management through HPE Aruba Networking Central is automatically disabled. To prevent configuration conflicts, the switch should be managed from a single platform. Enabling this setting designates Mist as the authoritative source for configuration management.

  14. Click Click Assign to Site.

    The onboarded switch, when assigned to a site, will appear on the Switches Page page with the status Connected.