Logins and passwords
You never type the switch password into a login prompt in ICX Setup. The app authenticates for you, using a fixed username and a list of passwords it tries in order. This page explains that list so you know exactly what it will try — and how to add your own.
The username is always super
Section titled “The username is always super”RUCKUS ICX switches log in with the user super. ICX Setup uses that username on every connection, over both serial and SSH. The SSH connection screen pre-fills super and you can leave it as is.
The password order
Section titled “The password order”ICX Setup tries passwords in this order until one works:
sp-admin— the built-in factory first-boot password, always tried first.- Your default password — the entry you starred in Settings (if any).
- The rest of your saved passwords, in order.
If you haven’t saved any passwords, the app seeds a single default entry with
the password icx-setup. So out of the box the effective order is
sp-admin then icx-setup.
Forced password change on first login
Section titled “Forced password change on first login”A factory-fresh ICX switch demands a new password the first time you log in with the factory credentials. ICX Setup handles this automatically: when it hits the “new password” / “confirm” prompts, it sets your default password — the entry starred in Settings — and carries on.
Out of the box that starred entry is icx-setup, so on a Mac where you haven’t
changed anything the switch ends up with the password icx-setup. If you
starred a password of your own, the switch gets that one instead. Either way
the password the switch ends up with is already in the list, so the next
connection logs in without asking you.
When every password fails (console only)
Section titled “When every password fails (console only)”Over a console cable, if every password in the list is rejected, ICX Setup does not simply give up. As a last resort it:
- Sends Ctrl+Y to drop the switch into its OS monitor (
OS>). - Runs
reset_login, which clears the switch’s configured login credentials. - Exits back to the login prompt and logs in with the factory
sp-admin. - Sets the password to your default password at the forced-change prompt.
This recovers a switch whose password nobody knows — but it changes the switch’s credentials, so it is not something to trigger by accident. If you have the right password and simply haven’t added it yet, disconnect and add it under Settings → Switch Passwords before reconnecting.
This path is serial only. Over SSH there is no OS monitor to reach, so a failed login just reports “The switch rejected the login credentials.”
The same recovery is available when ICX Setup re-logs-in after a reboot during an upgrade, but only when the release it just booted is FastIron 9.x or 10.x.
Adding your own passwords
Section titled “Adding your own passwords”If your switches already have custom passwords, add them in Settings → Switch Passwords:
- Give each entry a label and the password, and optionally mark one as
the default (the star) so it’s tried right after
sp-admin. - You can store up to 10 passwords.
- Passwords are saved in the macOS Keychain, never in plain preferences.
The Settings footer restates the rule: “Passwords are tried in order: sp-admin (built-in), then your default password, then the rest. Username is always ‘super’.” See the Settings reference.
Getting to the privileged prompt
Section titled “Getting to the privileged prompt”After login, ICX Setup escalates to the switch’s privileged (#) prompt with
enable, trying each of your passwords and then an empty password. All of the
app’s read and configuration commands run from there. If login is rejected
outright you’ll see “The switch rejected the login credentials.” — add the
correct password in Settings and reconnect.
Next steps
Section titled “Next steps”More on where secrets live: Security and privacy · Contact support.