The setup checklist
The setup checklist at https://sz-mcp.lanpulse.com/setup takes a new
organisation from a controller login to alerts in your inbox in six steps. Each
step can also be done later from the dashboard or by asking Claude, and the
checklist notices: its ticks are read from where each setting actually lives,
not stored separately.
An organisation admin who opens the dashboard with no controller saved is sent to the checklist once per browser session, unless someone has hidden it. Until every step is done (or the checklist is hidden), the dashboard shows a Setup card with the next step and a Continue setup button.
| # | Step | Who can do it |
|---|---|---|
| 1 | Connect the controller | Admin |
| 2 | Check what the login may do | Admin |
| 3 | Start collecting data | Admin |
| 4 | Read the first health report | Engineer or admin |
| 5 | Turn on alerts | Engineer or admin adds the checks; admin adds contacts and sends the test |
| 6 | Open a board | Engineer or admin |
Steps 2 to 6 stay locked until the controller is connected. Other members see the checklist, with a note on the steps someone else has to do. See How alerts work for the full role table.
Step 1: Connect the controller
Section titled “Step 1: Connect the controller”This is the same credentials form as the dashboard: host, port, username and password, checked by a real login. The controller must be reachable from the internet on 8443 (or 443) with a publicly trusted certificate. The step is done once the login has been verified. See SmartZone credentials and Controller requirements.
Step 2: What does the privilege check tell me?
Section titled “Step 2: What does the privilege check tell me?”It reads what the saved SmartZone login is allowed to do and gives advice. It
never blocks anything. Clicking Check makes one read,
GET /userGroups/currentUser/permissionCategories, and sorts the login’s
permission categories (System, AP, WLAN, Client, Administrator, ICX Switch,
MVNO) into read-only or writable.
| Result | Severity shown | Meaning |
|---|---|---|
| Read-only | OK | SZ-MCP can read everything this login sees and change nothing. Changes asked of Claude are refused by SmartZone. |
| Some categories writable | Note | The login can change those categories. |
| Every category writable, or Administrator writable | Warning | The login can change everything, or administrator accounts and roles. |
When the login can change anything, the advice is:
- For monitoring only, use a SmartZone user group with the Read-Only System Admin role.
- To let Claude make changes, give full access only in the categories you want changed. Network Admin covers AP, WLAN, Client and ICX without System or Administrator.
Two more notes can appear. If the login is limited to some domains, the inventory, metrics and alerts cover only what that login sees. And if it lacks full access to System › Northbound Data Streaming, it could not set up streaming (see the note under step 3).
Step 3: Start collecting data
Section titled “Step 3: Start collecting data”Clicking Start turns on API polling and the hourly inventory refresh, then
reads the whole controller once. The first run syncs the inventory (zones,
APs, switches, ports) and completes one poll, which takes a few seconds; the
result reads like Inventory: 412 entities (120 APs, 8 switches). First poll done.
From then on SZ-MCP polls the controller API every 5 minutes for metrics, outstanding alarms and rogue access points (ports and controller statistics every 15 minutes), and refreshes the inventory hourly. The step shows whether polling is on and whether the last poll or sync failed.
Step 4: What does the first health report check?
Section titled “Step 4: What does the first health report check?”The report reads the controller (reads only, about 20 calls plus one per certificate in use) and grades each finding OK, Note, Warning or Critical, with a fix for anything not OK. Critical findings sort first. A summary line above the checks gives the cluster name and version, zone count, APs up, clients and switches online.
| Check | Warning or Critical when |
|---|---|
| Controller cluster | Critical if the cluster or any node is not In_Service |
| Upgrade in progress | Shown as a Note while an upgrade is running |
| Access points | APs offline: Warning, or Critical when 20% or more are offline. Names the zones |
| Switches | Any switch not online (Warning) |
| AP firmware / Switch firmware | More than one firmware version within the same model (Warning). Needs the inventory from step 3 |
| Outstanding alarms | Critical alarms (Critical) or Major alarms (Warning) |
| Licence capacity | A licence pool 90% used (Warning) or full (Critical) |
| Licence expiry | A licence expiring within 60 days (Warning), or within 14 days (Critical). One already expired is a Warning |
| Certificates in use | A certificate the controller uses expiring within 30 days (Warning) or 7 days, or expired (Critical) |
Configuration checks
Section titled “Configuration checks”The report also checks five settings, each with one read. This is a “linter-lite”, not a full best-practice audit.
| Check | What it looks at | Result |
|---|---|---|
| WLAN security | Every WLAN (POST /query/wlan, up to 5,000) | Critical if any WLAN uses WEP. Warning if any allows WPA1/TKIP, or is open with no portal. A guest-portal WLAN is expected to be open and is not flagged |
| Configuration backup | Scheduled backup and auto export | Warning with no scheduled backup. Note if backups are scheduled but stay on the controller (no auto export to FTP) |
| Time (NTP) | The controller’s NTP servers | Warning if none is set |
| Syslog | Whether syslog is on, and to which host | Note if off: SmartZone sends its admin audit log (who changed what) only by syslog |
| SNMP | SNMPv2 communities | Warning if a community is public or private (noting write access) |
The SNMP read returns SNMPv3 passwords and v2 community strings; the report keeps only whether a v2 community is one of those two defaults.
If a read fails, its check is left out. If the controller answers none of them, the step reports that and saves nothing. The last report is kept and shown on the checklist; Run again replaces it.
Step 5: Turn on alerts
Section titled “Step 5: Turn on alerts”Alerts need two things: the checks that decide what is a problem, and someone to tell. The step has three lines:
- Starter checks — Add installs the 27-rule starter pack (devices offline, alarms, licences, certificates, rogues on your SSIDs). See the starter pack.
- Email contacts — if there are none, Add puts your own sign-in email on the contact list. The button names the address before you click it.
- Test — once there is a contact, Send a test sends one notification to every contact and channel and reports each as sent or failed.
The step is done when at least one starter rule is installed and there is at least one email contact. Add more people, a webhook or Jira on the Alerts card; see Alert notifications.
Step 6: Open a board
Section titled “Step 6: Open a board”Create the overview board makes a board named Network overview with eight panels, then opens it:
| Panel | Shows |
|---|---|
| APs online | Count of APs up |
| Switches online | Count of switches up |
| Clients | Wireless clients |
| Controller CPU | Gauge of the busiest node, amber above 70%, red above 90% |
| Clients by zone | The eight busiest zones over the board’s 6-hour range |
| Busiest APs | Top 10 APs by clients |
| Open problems | Current alert problems |
| Recent alarms | Controller alarms from the last 24 hours |
Clicking it again creates another copy. Change it, or build others, by asking Claude. See Boards.
Can I hide the checklist?
Section titled “Can I hide the checklist?”Yes. An admin can click Hide this checklist at the bottom of the page,
which removes the Setup card from the dashboard for the whole organisation.
Show it again brings it back. The /setup page stays reachable either way.