Reference / Devices

Supported devices

Which devices Cenovel supports, how it reaches each one, and exactly what it reads from each vendor and operating system.

ReferenceReviewed against the application source on 3 October 2026

Devices at a glance

Cenovel reaches each device the way it can be read: SSH and SNMPv3 for switches, routers, firewalls and access points; Redfish for servers; and a read-only API for the cloud controllers. Identified means Cenovel recognizes the vendor and software and names the model. Monitored means it reads the device on the polling schedule. Cenovel never changes a device’s configuration.

Scroll the table sideways to read all columns.

Device classVendor and softwareHow Cenovel reaches itSupport
Switches and stacksCisco IOS and IOS XE; Juniper Junos; Extreme Switch Engine and Fabric EngineSSH and SNMPv3Identified and monitored
SwitchesCisco Catalyst 1200 and 1300; Extreme SLX-OS and Extreme ONE OSSNMPv3Monitored with the standard SNMP tables; the software is not recognized
SwitchesAruba ArubaOS-SwitchSNMPv3Identified and monitored over SNMPv3 only; not in the catalog
RoutersCisco IOS XE (Catalyst 8000 edge, 8000 Secure Routers); Juniper Junos (MX, ACX)SSH and SNMPv3Identified and monitored
FirewallsPalo Alto Networks PA-seriesSNMPv3Monitored with the standard SNMP tables; PAN-OS is not recognized. In the catalog, with diagrams
Access pointsExtreme IQ Engine (HiveOS)SSH and SNMPv3Identified and monitored directly
Access pointsManaged by Juniper MistMist cloud API over HTTPSObserved through Mist
Access pointsManaged by ExtremeCloud IQExtremeCloud IQ API over HTTPSObserved through ExtremeCloud IQ
Access pointsAny other, recorded with a management addressSNMPv3Monitored directly, unless a controller covers it
ServersHPE iLO (including iLO 4) and Dell iDRACRedfish over HTTPSIdentified and monitored
ServersAny other Redfish management controllerRedfish over HTTPSIdentified and monitored with the standard Redfish resources
UPSAnyNot contactedInventory only: records, install reports, service and battery dates
Controllers and cloudJuniper Mist; ExtremeCloud IQHTTPS API with a read-only tokenRead-only observation

How Cenovel reaches devices

SSH
TCP port 22 by default, with a Device CLI credential (password or private key). The device’s host key must be approved before any credential is sent. Cenovel runs only a fixed list of read-only show commands.
SNMPv3
UDP port 161, authPriv only: SHA-2 authentication (SHA-224, SHA-256, SHA-384 or SHA-512) and AES-128 privacy.
Redfish
HTTPS to the server’s management controller, port 443 by default. Cenovel trusts the certificate fingerprint an administrator accepted, and signs out when each read is done.
Cloud API
Outbound HTTPS to the vendor’s official regional API host, with a read-only token. Redirects to any other host are refused.
Site collector
A site’s collector can find devices and take scheduled SNMPv3 reads on the console’s behalf. Scheduled SSH reads run from the console.

Find devices tries each address in this order and stops at the first method that identifies it: a Redfish service on HTTPS, then SSH, then SNMPv3. A device found over SSH is read over SSH afterwards, and over SNMPv3 for its ports when SNMPv3 is set up. A device found over SNMPv3 is read over SNMPv3.

What Cenovel reads from switches, routers and firewalls

Each row is a vendor and operating system. Each cell says how Cenovel reads that fact: Both (over SSH and over SNMPv3), SSH only, SNMP only, Not read, or N/A where the fact does not apply. A device is read only the ways it has a working credential for. Choose a vendor, a fact or a method to narrow the table.

10 device families, 13 facts

Scroll the table sideways to read all columns.

What Cenovel reads from each device family, and over which method
Device familyIdentityStack membersModulesPower and fansOpticsPort linkPort speedPort VLANPoENeighborsCountersMAC and ARPTemperature
Cisco IOS and IOS XECatalyst 1000, 2960, 3560, 3850, 4500 and 9000 switches; Catalyst 8000 edge platforms and 8000 Secure Routers.Both1BothBoth23Both4Both5BothSNMP6Not readSSHBoth7SNMP8SNMP9Not read
Cisco Catalyst 1200 and 1300These do not run IOS, so Cenovel reads them over SNMPv3 only.SNMP10SNMPNot readSNMP4SNMP5SNMPSNMP6Not readNot readSNMP11SNMP8SNMP9Not read
Juniper JunosEX and QFX switches and Virtual Chassis, EX9200; MX and ACX routers.BothBothBoth123Both4Both13BothBoth14SSH15SSHBoth11Both816SNMP9SSH17
Extreme Switch Engine (EXOS)4000, 5000 and 7000 series universal switches running Switch Engine, X450E and X460, and their stacks.BothBothBoth183Both4Both5BothSNMP6Not readSSHBoth11SNMP8SNMP9Not read
Extreme Fabric Engine (VOSS)Universal switches running Fabric Engine, and the 7830.BothNot readSNMP3Both4Both5BothSNMP6Not readSSHBoth11SNMP8SNMP9Not read
Extreme SLX-OS and Extreme ONE OSThe 8520 and 8720. Read over SNMPv3 only.SNMP10SNMPNot readSNMP4SNMP5SNMPSNMP6Not readNot readSNMP11SNMP8SNMP9Not read
Palo Alto Networks PAN-OSPA-series firewalls. Read over SNMPv3 only.SNMP10SNMPNot readSNMP4SNMP5SNMPSNMP6Not readNot readSNMP11SNMP8SNMP9Not read
Extreme IQ Engine (HiveOS) access pointsAccess points that Cenovel reads directly. See Access points below for controller-managed ones.Both19N/AN/AN/AN/ASNMPSNMP6Not readN/ABoth11SNMP8N/ANot read
Aruba ArubaOS-SwitchRecognized over SNMPv3. Not in the built-in catalog.SNMP20SNMPNot readSNMP4SNMP5SNMPSNMP6Not readNot readSNMP11SNMP8SNMP9Not read
Any other SNMPv3 deviceCenovel reads the standard tables from any device that answers SNMPv3 with an authorized credential.SNMP10SNMPNot readSNMP4SNMP5SNMPSNMP6Not readNot readSNMP11SNMP8SNMP9Not read

Notes

  1. Over SSH, a Catalyst 9200, 9300 or 9500 is named with its license tier (-A or -E) when the switch prints one.
  2. Over SSH: uplink network modules and stacking modules. Line cards in a modular chassis are not modeled.
  3. Over SNMP, a module is recognized only when its part number is one Cenovel knows.
  4. Over SNMP, power supplies are read with their state; fans are listed without a state.
  5. Vendor, part number and serial of each optic. Light levels are not read.
  6. Speed only. Duplex is not read.
  7. LLDP and CDP. A site collector reads LLDP only.
  8. Counter samples taken over SNMP give traffic rates and changes in errors and discards. No rate is shown until two comparable samples exist.
  9. MAC addresses learned on each port, with IP addresses from the ARP table. A port with eight or more addresses is treated as an uplink and skipped.
  10. Model and serial come from the device’s standard entity table, where the device lists them. Cenovel does not recognize this software, so no software version is read.
  11. LLDP. CDP is a Cisco protocol.
  12. Over SSH: uplink and stacking modules (PICs) from the chassis hardware list.
  13. Over SSH, Junos also gives transmit and receive light levels, module temperature, voltage and alarms.
  14. Over SSH: speed, duplex and auto-negotiation. Over SNMP: speed only.
  15. Untagged VLAN, tagged VLANs and spanning-tree state of each port.
  16. Over SSH, Junos also reports its own current traffic rate and error totals. Cenovel shows them as the switch’s figures and does not store them as counter samples.
  17. Optic module temperature only. Switch chassis temperature is not read.
  18. Over SSH: versatile interface modules (VIMs).
  19. Over SSH, an access point identified over SSH is read over SSH too.
  20. Vendor and software version are recognized from the system description; model and serial come from the standard entity table.

Access points

An access point is read one of three ways. While Mist or ExtremeCloud IQ has described an access point within the last hour, Cenovel does not poll it directly. If that description goes stale, or two controller devices could be the same access point, Cenovel polls it directly again where it has a management address. Whichever way, the closet, switch and port come from the switch’s own neighbor table.

WayMethodWhat it gives
Read directlySNMPv3, or SSH for an IQ Engine access point identified over SSHWhether it answers Cenovel, its identity, and its LLDP neighbor: the switch port it is plugged into.
Through Juniper MistMist cloud API, every five minutesMist’s view of the connection, model, serial, firmware, uptime, radios (band, channel, power, clients, utilization), a client count, its LLDP neighbor, device events and alarms. Mist reporting a device disconnected opens an outage worded as Mist’s report.
Through ExtremeCloud IQExtremeCloud IQ APIStatus, model, serial, firmware, management address, radios, a client count and its LLDP neighbor.

Cenovel keeps client counts from a controller, never the identities of connected clients. See Juniper Mist for connecting Mist.

Servers

Cenovel reads a server through its management controller’s Redfish service: HPE iLO (including iLO 4) and Dell iDRAC, and the standard Redfish resources of any other controller. It does not read the operating system running on the server.

FactWhat is read
IdentityManufacturer, model, serial, BIOS version, power state and host name; the management controller’s model and firmware.
HealthThe overall health and health rollup, with the conditions the controller reports.
Power suppliesEach supply’s model, serial, capacity and health, and whether power is still redundant.
FansEach fan’s state and reading.
TemperatureEach sensor’s reading in degrees Celsius against its caution and critical limits.
StorageHealth of each storage controller.

A list that the controller returned only in part is marked incomplete, so a partly read server never looks fully healthy.

UPS

A UPS is an inventory record. Cenovel keeps its vendor, model, serial and closet, its install reports, its service history and its battery replacement dates, and says when a battery or service falls due. Cenovel does not contact the UPS or its network card.

Controllers and cloud services

Juniper Mist
Sites, device status and inventory, device events and infrastructure alarms for access points, switches and gateways. Read every five minutes; signed webhooks are optional.
ExtremeCloud IQ
The location tree and the device list, as read-only observations.

Both are read only, and both need each controller site mapped to a Cenovel site by hand. A Mist device is linked to an inventory record by serial, then by MAC address, never by name. An ExtremeCloud IQ device is matched by serial, then MAC address, then management address, then name. A controller never creates or changes an inventory record.

Not supported yet

This release does not support:

  • SNMPv1 and SNMPv2c, and SNMPv3 without privacy or with MD5, SHA-1 or DES. Cenovel uses SNMPv3 with SHA-2 authentication and AES-128 privacy only.
  • Recognizing Cisco NX-OS, Arista EOS, Palo Alto PAN-OS and Extreme SLX-OS software. Devices running them are read only through the standard SNMP tables.
  • SSH reads of Palo Alto firewalls, Aruba switches, Catalyst 1200 and 1300 switches, and SLX switches.
  • Cisco Meraki, Aruba access points, Aruba Central and other controllers or cloud services. Cenovel reads only Juniper Mist and ExtremeCloud IQ.
  • Polling a UPS or its network card. A UPS is an inventory record.
  • Switch chassis temperature and other environmental sensors on switches.
  • Per-port VLAN membership on Cisco, Switch Engine and Fabric Engine switches, and per-port duplex outside Junos.

A device in none of the rows above can still be recorded by hand, and drawn with a custom port placement; see If your model is missing.

Describes the release being prepared for deployment. Check the behavior on your installed release.

↑ ↓ to moveEnter to openEsc to close