Skip to content
ICX Setup
Get Support

Logins and passwords

You never type the switch password into a login prompt in ICX Setup. The app authenticates for you, using a fixed username and a list of passwords it tries in order. This page explains that list so you know exactly what it will try — and how to add your own.

RUCKUS ICX switches log in with the user super. ICX Setup uses that username on every connection, over both serial and SSH. The SSH connection screen pre-fills super and you can leave it as is.

ICX Setup tries passwords in this order until one works:

  1. sp-admin — the built-in factory first-boot password, always tried first.
  2. Your default password — the entry you starred in Settings (if any).
  3. The rest of your saved passwords, in order.

If you haven’t saved any passwords, the app seeds a single default entry with the password icx-setup. So out of the box the effective order is sp-admin then icx-setup.

A factory-fresh ICX switch demands a new password the first time you log in with the factory credentials. ICX Setup handles this automatically: when it hits the “new password” / “confirm” prompts, it sets your default password — the entry starred in Settings — and carries on.

Out of the box that starred entry is icx-setup, so on a Mac where you haven’t changed anything the switch ends up with the password icx-setup. If you starred a password of your own, the switch gets that one instead. Either way the password the switch ends up with is already in the list, so the next connection logs in without asking you.

Over a console cable, if every password in the list is rejected, ICX Setup does not simply give up. As a last resort it:

  1. Sends Ctrl+Y to drop the switch into its OS monitor (OS>).
  2. Runs reset_login, which clears the switch’s configured login credentials.
  3. Exits back to the login prompt and logs in with the factory sp-admin.
  4. Sets the password to your default password at the forced-change prompt.

This recovers a switch whose password nobody knows — but it changes the switch’s credentials, so it is not something to trigger by accident. If you have the right password and simply haven’t added it yet, disconnect and add it under Settings → Switch Passwords before reconnecting.

This path is serial only. Over SSH there is no OS monitor to reach, so a failed login just reports “The switch rejected the login credentials.”

The same recovery is available when ICX Setup re-logs-in after a reboot during an upgrade, but only when the release it just booted is FastIron 9.x or 10.x.

If your switches already have custom passwords, add them in Settings → Switch Passwords:

  • Give each entry a label and the password, and optionally mark one as the default (the star) so it’s tried right after sp-admin.
  • You can store up to 10 passwords.
  • Passwords are saved in the macOS Keychain, never in plain preferences.

The Settings footer restates the rule: “Passwords are tried in order: sp-admin (built-in), then your default password, then the rest. Username is always ‘super’.” See the Settings reference.

After login, ICX Setup escalates to the switch’s privileged (#) prompt with enable, trying each of your passwords and then an empty password. All of the app’s read and configuration commands run from there. If login is rejected outright you’ll see “The switch rejected the login credentials.” — add the correct password in Settings and reconnect.


More on where secrets live: Security and privacy · Contact support.