Supported devices
Which devices Cenovel supports, how it reaches each one, and exactly what it reads from each vendor and operating system.
ReferenceReviewed against the application source on 3 October 2026
Devices at a glance
Cenovel reaches each device the way it can be read: SSH and SNMPv3 for switches, routers, firewalls and access points; Redfish for servers; and a read-only API for the cloud controllers. Identified means Cenovel recognizes the vendor and software and names the model. Monitored means it reads the device on the polling schedule. Cenovel never changes a device’s configuration.
Scroll the table sideways to read all columns.
| Device class | Vendor and software | How Cenovel reaches it | Support |
|---|---|---|---|
| Switches and stacks | Cisco IOS and IOS XE; Juniper Junos; Extreme Switch Engine and Fabric Engine | SSH and SNMPv3 | Identified and monitored |
| Switches | Cisco Catalyst 1200 and 1300; Extreme SLX-OS and Extreme ONE OS | SNMPv3 | Monitored with the standard SNMP tables; the software is not recognized |
| Switches | Aruba ArubaOS-Switch | SNMPv3 | Identified and monitored over SNMPv3 only; not in the catalog |
| Routers | Cisco IOS XE (Catalyst 8000 edge, 8000 Secure Routers); Juniper Junos (MX, ACX) | SSH and SNMPv3 | Identified and monitored |
| Firewalls | Palo Alto Networks PA-series | SNMPv3 | Monitored with the standard SNMP tables; PAN-OS is not recognized. In the catalog, with diagrams |
| Access points | Extreme IQ Engine (HiveOS) | SSH and SNMPv3 | Identified and monitored directly |
| Access points | Managed by Juniper Mist | Mist cloud API over HTTPS | Observed through Mist |
| Access points | Managed by ExtremeCloud IQ | ExtremeCloud IQ API over HTTPS | Observed through ExtremeCloud IQ |
| Access points | Any other, recorded with a management address | SNMPv3 | Monitored directly, unless a controller covers it |
| Servers | HPE iLO (including iLO 4) and Dell iDRAC | Redfish over HTTPS | Identified and monitored |
| Servers | Any other Redfish management controller | Redfish over HTTPS | Identified and monitored with the standard Redfish resources |
| UPS | Any | Not contacted | Inventory only: records, install reports, service and battery dates |
| Controllers and cloud | Juniper Mist; ExtremeCloud IQ | HTTPS API with a read-only token | Read-only observation |
How Cenovel reaches devices
- SSH
- TCP port 22 by default, with a Device CLI credential (password or private key). The device’s host key must be approved before any credential is sent. Cenovel runs only a fixed list of read-only show commands.
- SNMPv3
- UDP port 161, authPriv only: SHA-2 authentication (SHA-224, SHA-256, SHA-384 or SHA-512) and AES-128 privacy.
- Redfish
- HTTPS to the server’s management controller, port 443 by default. Cenovel trusts the certificate fingerprint an administrator accepted, and signs out when each read is done.
- Cloud API
- Outbound HTTPS to the vendor’s official regional API host, with a read-only token. Redirects to any other host are refused.
- Site collector
- A site’s collector can find devices and take scheduled SNMPv3 reads on the console’s behalf. Scheduled SSH reads run from the console.
Find devices tries each address in this order and stops at the first method that identifies it: a Redfish service on HTTPS, then SSH, then SNMPv3. A device found over SSH is read over SSH afterwards, and over SNMPv3 for its ports when SNMPv3 is set up. A device found over SNMPv3 is read over SNMPv3.
What Cenovel reads from switches, routers and firewalls
Each row is a vendor and operating system. Each cell says how Cenovel reads that fact: Both (over SSH and over SNMPv3), SSH only, SNMP only, Not read, or N/A where the fact does not apply. A device is read only the ways it has a working credential for. Choose a vendor, a fact or a method to narrow the table.
10 device families, 13 facts
Scroll the table sideways to read all columns.
| Device family | Identity | Stack members | Modules | Power and fans | Optics | Port link | Port speed | Port VLAN | PoE | Neighbors | Counters | MAC and ARP | Temperature |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cisco IOS and IOS XECatalyst 1000, 2960, 3560, 3850, 4500 and 9000 switches; Catalyst 8000 edge platforms and 8000 Secure Routers. | Both1 | Both | Both23 | Both4 | Both5 | Both | SNMP6 | Not read | SSH | Both7 | SNMP8 | SNMP9 | Not read |
| Cisco Catalyst 1200 and 1300These do not run IOS, so Cenovel reads them over SNMPv3 only. | SNMP10 | SNMP | Not read | SNMP4 | SNMP5 | SNMP | SNMP6 | Not read | Not read | SNMP11 | SNMP8 | SNMP9 | Not read |
| Juniper JunosEX and QFX switches and Virtual Chassis, EX9200; MX and ACX routers. | Both | Both | Both123 | Both4 | Both13 | Both | Both14 | SSH15 | SSH | Both11 | Both816 | SNMP9 | SSH17 |
| Extreme Switch Engine (EXOS)4000, 5000 and 7000 series universal switches running Switch Engine, X450E and X460, and their stacks. | Both | Both | Both183 | Both4 | Both5 | Both | SNMP6 | Not read | SSH | Both11 | SNMP8 | SNMP9 | Not read |
| Extreme Fabric Engine (VOSS)Universal switches running Fabric Engine, and the 7830. | Both | Not read | SNMP3 | Both4 | Both5 | Both | SNMP6 | Not read | SSH | Both11 | SNMP8 | SNMP9 | Not read |
| Extreme SLX-OS and Extreme ONE OSThe 8520 and 8720. Read over SNMPv3 only. | SNMP10 | SNMP | Not read | SNMP4 | SNMP5 | SNMP | SNMP6 | Not read | Not read | SNMP11 | SNMP8 | SNMP9 | Not read |
| Palo Alto Networks PAN-OSPA-series firewalls. Read over SNMPv3 only. | SNMP10 | SNMP | Not read | SNMP4 | SNMP5 | SNMP | SNMP6 | Not read | Not read | SNMP11 | SNMP8 | SNMP9 | Not read |
| Extreme IQ Engine (HiveOS) access pointsAccess points that Cenovel reads directly. See Access points below for controller-managed ones. | Both19 | N/A | N/A | N/A | N/A | SNMP | SNMP6 | Not read | N/A | Both11 | SNMP8 | N/A | Not read |
| Aruba ArubaOS-SwitchRecognized over SNMPv3. Not in the built-in catalog. | SNMP20 | SNMP | Not read | SNMP4 | SNMP5 | SNMP | SNMP6 | Not read | Not read | SNMP11 | SNMP8 | SNMP9 | Not read |
| Any other SNMPv3 deviceCenovel reads the standard tables from any device that answers SNMPv3 with an authorized credential. | SNMP10 | SNMP | Not read | SNMP4 | SNMP5 | SNMP | SNMP6 | Not read | Not read | SNMP11 | SNMP8 | SNMP9 | Not read |
No device family matches. Choose All vendors or Anything to see more.
Notes
- Over SSH, a Catalyst 9200, 9300 or 9500 is named with its license tier (-A or -E) when the switch prints one.
- Over SSH: uplink network modules and stacking modules. Line cards in a modular chassis are not modeled.
- Over SNMP, a module is recognized only when its part number is one Cenovel knows.
- Over SNMP, power supplies are read with their state; fans are listed without a state.
- Vendor, part number and serial of each optic. Light levels are not read.
- Speed only. Duplex is not read.
- LLDP and CDP. A site collector reads LLDP only.
- Counter samples taken over SNMP give traffic rates and changes in errors and discards. No rate is shown until two comparable samples exist.
- MAC addresses learned on each port, with IP addresses from the ARP table. A port with eight or more addresses is treated as an uplink and skipped.
- Model and serial come from the device’s standard entity table, where the device lists them. Cenovel does not recognize this software, so no software version is read.
- LLDP. CDP is a Cisco protocol.
- Over SSH: uplink and stacking modules (PICs) from the chassis hardware list.
- Over SSH, Junos also gives transmit and receive light levels, module temperature, voltage and alarms.
- Over SSH: speed, duplex and auto-negotiation. Over SNMP: speed only.
- Untagged VLAN, tagged VLANs and spanning-tree state of each port.
- Over SSH, Junos also reports its own current traffic rate and error totals. Cenovel shows them as the switch’s figures and does not store them as counter samples.
- Optic module temperature only. Switch chassis temperature is not read.
- Over SSH: versatile interface modules (VIMs).
- Over SSH, an access point identified over SSH is read over SSH too.
- Vendor and software version are recognized from the system description; model and serial come from the standard entity table.
Access points
An access point is read one of three ways. While Mist or ExtremeCloud IQ has described an access point within the last hour, Cenovel does not poll it directly. If that description goes stale, or two controller devices could be the same access point, Cenovel polls it directly again where it has a management address. Whichever way, the closet, switch and port come from the switch’s own neighbor table.
| Way | Method | What it gives |
|---|---|---|
| Read directly | SNMPv3, or SSH for an IQ Engine access point identified over SSH | Whether it answers Cenovel, its identity, and its LLDP neighbor: the switch port it is plugged into. |
| Through Juniper Mist | Mist cloud API, every five minutes | Mist’s view of the connection, model, serial, firmware, uptime, radios (band, channel, power, clients, utilization), a client count, its LLDP neighbor, device events and alarms. Mist reporting a device disconnected opens an outage worded as Mist’s report. |
| Through ExtremeCloud IQ | ExtremeCloud IQ API | Status, model, serial, firmware, management address, radios, a client count and its LLDP neighbor. |
Cenovel keeps client counts from a controller, never the identities of connected clients. See Juniper Mist for connecting Mist.
Servers
Cenovel reads a server through its management controller’s Redfish service: HPE iLO (including iLO 4) and Dell iDRAC, and the standard Redfish resources of any other controller. It does not read the operating system running on the server.
| Fact | What is read |
|---|---|
| Identity | Manufacturer, model, serial, BIOS version, power state and host name; the management controller’s model and firmware. |
| Health | The overall health and health rollup, with the conditions the controller reports. |
| Power supplies | Each supply’s model, serial, capacity and health, and whether power is still redundant. |
| Fans | Each fan’s state and reading. |
| Temperature | Each sensor’s reading in degrees Celsius against its caution and critical limits. |
| Storage | Health of each storage controller. |
A list that the controller returned only in part is marked incomplete, so a partly read server never looks fully healthy.
UPS
A UPS is an inventory record. Cenovel keeps its vendor, model, serial and closet, its install reports, its service history and its battery replacement dates, and says when a battery or service falls due. Cenovel does not contact the UPS or its network card.
Controllers and cloud services
- Juniper Mist
- Sites, device status and inventory, device events and infrastructure alarms for access points, switches and gateways. Read every five minutes; signed webhooks are optional.
- ExtremeCloud IQ
- The location tree and the device list, as read-only observations.
Both are read only, and both need each controller site mapped to a Cenovel site by hand. A Mist device is linked to an inventory record by serial, then by MAC address, never by name. An ExtremeCloud IQ device is matched by serial, then MAC address, then management address, then name. A controller never creates or changes an inventory record.
Not supported yet
This release does not support:
- SNMPv1 and SNMPv2c, and SNMPv3 without privacy or with MD5, SHA-1 or DES. Cenovel uses SNMPv3 with SHA-2 authentication and AES-128 privacy only.
- Recognizing Cisco NX-OS, Arista EOS, Palo Alto PAN-OS and Extreme SLX-OS software. Devices running them are read only through the standard SNMP tables.
- SSH reads of Palo Alto firewalls, Aruba switches, Catalyst 1200 and 1300 switches, and SLX switches.
- Cisco Meraki, Aruba access points, Aruba Central and other controllers or cloud services. Cenovel reads only Juniper Mist and ExtremeCloud IQ.
- Polling a UPS or its network card. A UPS is an inventory record.
- Switch chassis temperature and other environmental sensors on switches.
- Per-port VLAN membership on Cisco, Switch Engine and Fabric Engine switches, and per-port duplex outside Junos.
A device in none of the rows above can still be recorded by hand, and drawn with a custom port placement; see If your model is missing.
Describes the release being prepared for deployment. Check the behavior on your installed release.