Juniper Mist
Connect a Juniper Mist organization with a read-only token, map its sites by hand, and read Mist's disconnected report as Mist's view rather than a Cenovel observation.
What Cenovel reads from Mist
Cenovel can read one or more Juniper Mist organizations: their sites, device status, device inventory, device events and infrastructure alarms. It only reads. Nothing in Mist is changed, and Cenovel keeps client counts, not the identities of connected clients.
Each connection is read every five minutes. Sites and device status are read every time; device inventory is read at most about once an hour; events and alarms are read from where the previous read stopped. Each fact on the Mist panel carries its own time.
Mist's report about a device and Cenovel's own reachability check are different facts. Mist can say a device is disconnected from the Mist cloud while it still answers Cenovel, and the reverse. Cenovel shows them separately and never turns one into the other.
Before you connect
- Outbound access: Cenovel reaches Mist over HTTPS (TCP 443) to one host, the API host for your Mist region. Allow only that host. Cenovel refuses redirects to any other host.
- Token: create an organization API token for Cenovel alone, with read-only privileges. Optionally restrict it to the appliance's public address in Mist. A token that can change the organization is accepted with a warning that Cenovel needs only read access.
- Organization ID: find it in the Mist portal under Organization › Settings.
- Permission: only Administrator EX can connect, change or remove a Mist connection.
Scroll the table sideways to read all columns.
| Region in the console | Your Mist portal address | Host to allow |
|---|---|---|
| Global 01 | manage.mist.com | api.mist.com |
| Global 02 | manage.gc1.mist.com | api.gc1.mist.com |
| Global 03 | manage.ac2.mist.com | api.ac2.mist.com |
| Global 04 | manage.gc2.mist.com | api.gc2.mist.com |
| Global 05 | manage.gc4.mist.com | api.gc4.mist.com |
| EMEA 01 | manage.eu.mist.com | api.eu.mist.com |
| EMEA 02 | manage.gc3.mist.com | api.gc3.mist.com |
| EMEA 03 | manage.ac6.mist.com | api.ac6.mist.com |
| EMEA 04 | manage.gc6.mist.com | api.gc6.mist.com |
| APAC 01 | manage.ac5.mist.com | api.ac5.mist.com |
| APAC 02 | manage.gc5.mist.com | api.gc5.mist.com |
| APAC 03 | manage.gc7.mist.com | api.gc7.mist.com |
Connect Mist
Use Check token at any time to ask Mist whether it still accepts the stored token. Use Change to rotate the token, or to correct the region or organization; Cenovel checks the new details with Mist before saving them. Read now starts a read straight away and shows that it is working until the read finishes. Remove stops Cenovel reading Mist and erases the stored token; delete the token in Mist as well. What Mist reported earlier stays in history.
- Open Governance › Monitoring › Configuration › Access and find the Juniper Mist panel. Choose Connect Mist.
- Enter a name, choose the region your portal address names, and paste the organization ID and the token.
- Choose Check and connect. Cenovel checks the token with Mist before saving anything. If Mist refuses it, the drawer says why and nothing is saved.
- After a successful check, Cenovel stores the token sealed, never shows it again and starts the first read. Mist sites appear after that read.
Map Mist sites to Cenovel sites
Cenovel never maps a Mist site by itself. Each Mist site is listed as Not mapped yet until an operator chooses a Cenovel site, or chooses Ignore. When a Cenovel site has exactly the same name, the row offers it as a one-click choice; it is still only applied when you choose it. Only mapped sites place devices or raise Mist's reports at a Cenovel site.
A Mist site that is renamed keeps its mapping. The row shows the earlier name and the date of the rename until you choose Noted. A site that disappears from Mist's complete site list is shown as no longer listed, with the date, until you choose Remove mapping; its devices keep their last known site. If Mist lists it again it returns to be mapped. A partial site list never marks a site as missing.
How Mist devices are linked to records
Cenovel links a Mist device to an inventory record by serial number first, then by hardware address. It does not match by name.
When the match is not clear, nothing is linked and the device is listed under Devices not linked until somebody decides, with the reason. Examples are two Mist devices with the same serial, a serial or hardware address carried by more than one record, a hardware address that belongs to a record with a different serial (possibly a replaced unit), or two Mist devices claiming the same record.
While Mist has described an access point recently, Cenovel does not poll that access point directly; its closet, switch and port still come from the switch. If Mist's description goes stale, or the link is contested, Cenovel polls the access point itself again where it has a management address.
Mist reports this device disconnected
When a read shows Mist reporting a linked device on a mapped site as disconnected, Cenovel opens an outage named Mist reports this device disconnected, with Warning priority. It carries the time Mist gives for the disconnection, when known, and the time Cenovel read it. When a later read shows Mist reporting the device connected, the outage closes with the words Mist reports it connected again.
This is Mist's view of the device's connection to the Mist cloud. It is not the same as Access point not answering Cenovel, which comes from Cenovel's own reads. Check both before deciding where the fault is.
Nothing is concluded from a device whose status Mist does not give, a device that is not linked or is contested, or a site nobody has mapped. A failed read never opens or closes this outage.
Planned work can quiet it. A maintenance window on the access point, offered as Juniper Mist's disconnected report, quiets that report while the window is open.
When a read fails or Mist asks Cenovel to wait
- A failed read is shown as The last read failed, with its time and the reason in plain words. The last successful read keeps its own time. A failed read says nothing about the devices.
- If Mist's site list or device status cannot be read, nothing from that read is stored. If only inventory, events or alarms fail, the rest of the read is kept and the failed part is recorded on its own.
- If Mist's list changes while Cenovel is paging through it, nothing is concluded from that read and the next read starts over.
- If Mist asks Cenovel to slow down, Cenovel waits for the time Mist gives. The panel shows Waiting before the next read and when the next read can start; Read now is unavailable until then.
- Cenovel limits itself to 2,500 Mist requests an hour for each connection, half of what Mist allows one token, so other tools keep headroom. The panel shows the requests used this hour.
Keep the token alive
Mist removes API tokens that go unused for 90 days. Cenovel uses the token on every read, so an active connection keeps it alive. Pausing the connection stops reads and stops Cenovel watching anything Mist reports; a connection paused for about three months will need a new token.
The panel warns when the token has gone unused for 60 days, or for 30 days on a paused connection. After 90 days it says the token has probably been removed. Create a new read-only token in Mist and rotate it with Change.
Optional webhooks
Cenovel works without webhooks: it polls Mist with outbound HTTPS only. Webhooks let Mist deliver device events and alarms sooner, but they need Mist's cloud to reach the appliance inbound over HTTPS with a publicly trusted certificate.
Webhooks are off until you choose Turn on webhooks. Cenovel then shows a secret once. In Mist, add an HTTP POST webhook to the path shown, on the appliance's public address, with that secret. Rotate secret makes a new one; Turn off stops accepting deliveries while polling carries on.
Cenovel accepts a delivery only when its signature matches the secret, it names this organization and it is within the size limit. Refused deliveries are counted on the panel with the time of the last one. A repeated delivery is not processed twice.
A delivery is stored as an event or alarm. It never opens or closes an outage by itself: outages come only from Cenovel's own reads of Mist's device status.
Limits of this guide
- This guide is checked against the application source and automated runs against a simulated Mist organization built from Mist's published API. It has not been proven against a real Mist organization.
- How long Cenovel keeps stored Mist events, alarms and device movements is not yet governed by a retention setting.
- Only Juniper Mist's disconnected report opens an outage. Stored device events and infrastructure alarms do not raise outages.
- Some behavior described here may not be in your installed version. Check your release notes.
Reviewed against the current source code. Confirm the behavior and available actions on your installed release.