Skip to content
SZ-MCP
Get Support

Lint rules

The linter has 30 rules: 2 critical, 18 warning and 10 info. Five of them have an automatic fix that Claude can turn into a change procedure (MOP) for you to approve. The other 25, including all seven ICX switch rules, give advice only. Claude lists the same rules with lint.rules(), and you can limit a run to some of them with lint.run({ rules: [...] }).

The Applies to column is the kind of object the rule reads from the daily config snapshot. ICX switch means the switch’s newest SwitchM backup.

Rule idFlagsApplies toSeverityWhy it mattersAuto-fix
wlan-wepWEP encryptionWLANcriticalWEP keys are recovered in minutes from captured traffic; anyone in range can join and read the network.No
wlan-wpa-tkipWPA1 or TKIP allowedWLANwarningWPA1 and TKIP are deprecated and weak; allowing them also caps every client on the WLAN at 802.11g rates.No
wlan-openOpen WLAN with no portalWLANwarningAn open network with no portal lets anyone in range join and puts their traffic in clear.No
wlan-wpa3-pmfWPA3 without required PMFWLANwarningWPA3 requires management frame protection; with it optional or off, clients fall back or fail to join.No
wlan-weak-passphraseCommon passphraseWLANcriticalA passphrase from the common-password lists is the first thing an attacker tries.No
wlan-guest-isolationGuest WLAN without client isolationWLANwarningOn a guest or portal WLAN, clients can reach each other (and scan each other) unless isolation is on.Yes
wlan-vlan1Clients on VLAN 1WLANinfoVLAN 1 is the default and usually the native/management VLAN of the switches; wireless clients belong on their own.No
wlan-hidden-ssidHidden SSIDWLANinfoHiding the SSID secures nothing (it is in every probe) and makes clients probe for it everywhere they go; some IoT devices join hidden networks badly.Yes
wlan-low-rates802.11b rates allowedWLANinfoBeacons and slow clients at 1–2 Mbps use airtime every AP on the channel shares; OFDM-only (or a BSS minimum rate) frees it. Old 802.11b-only devices can no longer join, so check the site has none.Yes
radio-24-overlapOverlapping 2.4 GHz channelsZone, AP groupwarningNeighbouring APs on overlapping 2.4 GHz channels interfere with each other instead of taking turns; auto channel should pick only from non-overlapping ones.Yes
radio-24-wide40 MHz on 2.4 GHzZone, AP groupwarningThere is room for one 40 MHz channel on 2.4 GHz; neighbouring APs on it overlap and slow each other down.Yes
radio-no-background-scanBackground scanning offZonewarningWithout background scanning the APs see no neighbours: no rogue detection (the rogue alert rules stay silent) and auto channel works blind.No
zone-rogue-offRogue detection offZonewarningWith rogue detection off, a device impersonating one of your SSIDs goes unseen, and the rogue alert rules have nothing to read.No
zone-ap-snmp-defaultAP SNMP with a default communityZonewarning”public” and “private” are the first communities anyone tries; with them, the APs answer (or accept) SNMP from anyone who can reach them.No
zone-ap-syslog-offAP syslog offZoneinfoThe APs’ own logs are what support asks for after a problem; SZ keeps only its events.No
apgroup-emptyEmpty AP groupAP groupinfoAn AP group with no APs is usually left over; it is one more place a setting can hide.No
system-ntpNo NTP serverControllerwarningEvent times, certificates and alert timings all depend on the controller clock.No
system-syslog-offController syslog offControllerinfoSmartZone sends its admin audit log (who changed what) only by syslog.No
system-snmp-defaultSNMP with a default communityControllerwarning”public” and “private” are the first communities anyone tries.No
system-backupNo scheduled config backupControllerwarningWithout a scheduled backup, a lost cluster takes its configuration with it.No
snmp-v2-writeSNMPv2 community with write accessController, ZonewarningSNMPv2 sends the community in clear text, so anyone who sees one request can write with it; on the controller that includes rebooting a node (RUCKUS-CTRL-MIB). Writes made this way skip the admin audit log.No
snmp-v2-trapsSNMPv2 trapsController, ZoneinfoAn SNMPv2 trap or inform carries the community in clear text to every target, and its contents (event text, MACs, names) unencrypted.No
snmp-v3-weakSNMPv3 user with weak or no privacyController, ZonewarningMD5 authentication and DES privacy are broken; an SNMPv3 user without privacy sends everything, including writes and traps, in clear text.No
icx-telnetTelnet enabled on a switchICX switchwarningTelnet sends the login and everything after it in clear text; SSH does the same job encrypted.No
icx-web-httpSwitch web UI over plain HTTPICX switchwarningThe web UI login travels in clear text over HTTP.No
icx-snmp-defaultSwitch SNMP with a default communityICX switchwarning”public” and “private” are the first communities anyone tries.No
icx-snmp-rwSwitch SNMP read-write communityICX switchinfoA read-write community lets anyone who knows it change the switch over SNMP, without the audit trail SmartZone keeps.No
icx-no-syslogSwitch sends no syslogICX switchinfoThe switch’s own log (link flaps, PoE faults, STP changes) is what support asks for after a problem.No
icx-no-ntpSwitch has no NTP serverICX switchwarningWithout NTP the switch clock drifts, and its log times stop lining up with the controller and the other switches.No
icx-no-aaa-loginSwitch login not set to AAAICX switchinfoWithout aaa authentication login default, console and SSH logins fall back to the switch’s defaults instead of your RADIUS/TACACS+ or named local users.No

One field each, on a WLAN, zone or AP group, never a field that carries a secret.

Rule idThe fix
wlan-guest-isolationTurns on client isolation
wlan-hidden-ssidBroadcasts the SSID
wlan-low-ratesTurns on OFDM-only
radio-24-overlapLimits the 2.4 GHz channel range to non-overlapping channels
radio-24-wideSets 2.4 GHz to 20 MHz

The other rules’ findings carry advice in words. Fixes to encryption settings, such as moving off TKIP or requiring PMF for WPA3, are not automatic because those settings carry the passphrase.

By comparing digests, not the secrets themselves. The snapshot stores a digest of each passphrase and SNMP community, and the linter compares them with digests of a list of well-known weak values. wlan-weak-passphrase says that a passphrase is on the list but never shows it. A finding can name a weak SNMP community, such as public. icx-snmp-default does not judge communities the switch stores encrypted.