Lint rules
The linter has 30 rules: 2 critical, 18 warning and 10 info. Five of them
have an automatic fix that Claude can turn into a change procedure (MOP) for
you to approve. The other 25, including all seven ICX switch rules, give advice
only. Claude lists the same rules with lint.rules(), and you can limit a run to
some of them with lint.run({ rules: [...] }).
Which rules are there?
Section titled “Which rules are there?”The Applies to column is the kind of object the rule reads from the daily config snapshot. ICX switch means the switch’s newest SwitchM backup.
| Rule id | Flags | Applies to | Severity | Why it matters | Auto-fix |
|---|---|---|---|---|---|
wlan-wep | WEP encryption | WLAN | critical | WEP keys are recovered in minutes from captured traffic; anyone in range can join and read the network. | No |
wlan-wpa-tkip | WPA1 or TKIP allowed | WLAN | warning | WPA1 and TKIP are deprecated and weak; allowing them also caps every client on the WLAN at 802.11g rates. | No |
wlan-open | Open WLAN with no portal | WLAN | warning | An open network with no portal lets anyone in range join and puts their traffic in clear. | No |
wlan-wpa3-pmf | WPA3 without required PMF | WLAN | warning | WPA3 requires management frame protection; with it optional or off, clients fall back or fail to join. | No |
wlan-weak-passphrase | Common passphrase | WLAN | critical | A passphrase from the common-password lists is the first thing an attacker tries. | No |
wlan-guest-isolation | Guest WLAN without client isolation | WLAN | warning | On a guest or portal WLAN, clients can reach each other (and scan each other) unless isolation is on. | Yes |
wlan-vlan1 | Clients on VLAN 1 | WLAN | info | VLAN 1 is the default and usually the native/management VLAN of the switches; wireless clients belong on their own. | No |
wlan-hidden-ssid | Hidden SSID | WLAN | info | Hiding the SSID secures nothing (it is in every probe) and makes clients probe for it everywhere they go; some IoT devices join hidden networks badly. | Yes |
wlan-low-rates | 802.11b rates allowed | WLAN | info | Beacons and slow clients at 1–2 Mbps use airtime every AP on the channel shares; OFDM-only (or a BSS minimum rate) frees it. Old 802.11b-only devices can no longer join, so check the site has none. | Yes |
radio-24-overlap | Overlapping 2.4 GHz channels | Zone, AP group | warning | Neighbouring APs on overlapping 2.4 GHz channels interfere with each other instead of taking turns; auto channel should pick only from non-overlapping ones. | Yes |
radio-24-wide | 40 MHz on 2.4 GHz | Zone, AP group | warning | There is room for one 40 MHz channel on 2.4 GHz; neighbouring APs on it overlap and slow each other down. | Yes |
radio-no-background-scan | Background scanning off | Zone | warning | Without background scanning the APs see no neighbours: no rogue detection (the rogue alert rules stay silent) and auto channel works blind. | No |
zone-rogue-off | Rogue detection off | Zone | warning | With rogue detection off, a device impersonating one of your SSIDs goes unseen, and the rogue alert rules have nothing to read. | No |
zone-ap-snmp-default | AP SNMP with a default community | Zone | warning | ”public” and “private” are the first communities anyone tries; with them, the APs answer (or accept) SNMP from anyone who can reach them. | No |
zone-ap-syslog-off | AP syslog off | Zone | info | The APs’ own logs are what support asks for after a problem; SZ keeps only its events. | No |
apgroup-empty | Empty AP group | AP group | info | An AP group with no APs is usually left over; it is one more place a setting can hide. | No |
system-ntp | No NTP server | Controller | warning | Event times, certificates and alert timings all depend on the controller clock. | No |
system-syslog-off | Controller syslog off | Controller | info | SmartZone sends its admin audit log (who changed what) only by syslog. | No |
system-snmp-default | SNMP with a default community | Controller | warning | ”public” and “private” are the first communities anyone tries. | No |
system-backup | No scheduled config backup | Controller | warning | Without a scheduled backup, a lost cluster takes its configuration with it. | No |
snmp-v2-write | SNMPv2 community with write access | Controller, Zone | warning | SNMPv2 sends the community in clear text, so anyone who sees one request can write with it; on the controller that includes rebooting a node (RUCKUS-CTRL-MIB). Writes made this way skip the admin audit log. | No |
snmp-v2-traps | SNMPv2 traps | Controller, Zone | info | An SNMPv2 trap or inform carries the community in clear text to every target, and its contents (event text, MACs, names) unencrypted. | No |
snmp-v3-weak | SNMPv3 user with weak or no privacy | Controller, Zone | warning | MD5 authentication and DES privacy are broken; an SNMPv3 user without privacy sends everything, including writes and traps, in clear text. | No |
icx-telnet | Telnet enabled on a switch | ICX switch | warning | Telnet sends the login and everything after it in clear text; SSH does the same job encrypted. | No |
icx-web-http | Switch web UI over plain HTTP | ICX switch | warning | The web UI login travels in clear text over HTTP. | No |
icx-snmp-default | Switch SNMP with a default community | ICX switch | warning | ”public” and “private” are the first communities anyone tries. | No |
icx-snmp-rw | Switch SNMP read-write community | ICX switch | info | A read-write community lets anyone who knows it change the switch over SNMP, without the audit trail SmartZone keeps. | No |
icx-no-syslog | Switch sends no syslog | ICX switch | info | The switch’s own log (link flaps, PoE faults, STP changes) is what support asks for after a problem. | No |
icx-no-ntp | Switch has no NTP server | ICX switch | warning | Without NTP the switch clock drifts, and its log times stop lining up with the controller and the other switches. | No |
icx-no-aaa-login | Switch login not set to AAA | ICX switch | info | Without aaa authentication login default, console and SSH logins fall back to the switch’s defaults instead of your RADIUS/TACACS+ or named local users. | No |
What do the automatic fixes change?
Section titled “What do the automatic fixes change?”One field each, on a WLAN, zone or AP group, never a field that carries a secret.
| Rule id | The fix |
|---|---|
wlan-guest-isolation | Turns on client isolation |
wlan-hidden-ssid | Broadcasts the SSID |
wlan-low-rates | Turns on OFDM-only |
radio-24-overlap | Limits the 2.4 GHz channel range to non-overlapping channels |
radio-24-wide | Sets 2.4 GHz to 20 MHz |
The other rules’ findings carry advice in words. Fixes to encryption settings, such as moving off TKIP or requiring PMF for WPA3, are not automatic because those settings carry the passphrase.
How are weak passwords detected?
Section titled “How are weak passwords detected?”By comparing digests, not the secrets themselves. The snapshot stores a
digest of each passphrase and SNMP community, and the linter compares them with
digests of a list of well-known weak values. wlan-weak-passphrase says that a
passphrase is on the list but never shows it. A finding can name a weak SNMP
community, such as public. icx-snmp-default does not judge
communities the switch stores encrypted.