Juniper Mist Wired Assurance Guide
Learn how Mist Wired Assurance onboards and manages switches, measures wired SLEs, uses Marvis for troubleshooting, and structures subscriptions.
Key Points
- Mist Wired Assurance is a cloud service for switch onboarding, configuration, monitoring and AI-assisted operations.
- Wired service-level expectations measure successful connection, throughput and switch health from the client-experience perspective.
- Templates and port profiles help standardize configuration across sites without removing the underlying Junos capabilities.
- Supported EX, QFX and CX switches can use Wired Assurance, but platform and firmware compatibility must be checked.
- Subscriptions vary by tier, switch class and term; Marvis and Premium Analytics can be associated services.
Juniper Mist Wired Assurance applies the Mist cloud and AI operations model to enterprise switching. Instead of stopping at “is the switch up?”, it uses telemetry to show whether wired clients can connect, pass traffic and receive an acceptable experience. The service also handles onboarding, configuration templates and troubleshooting across supported EX, QFX and HPE Networking CX switches.
What Is Mist Wired Assurance?
Wired Assurance is a subscription-based cloud service in the Juniper Mist portal. It centralizes switch inventory, configuration and monitoring, while Mist AI analyzes telemetry for anomalies and likely root causes. It is not a replacement operating system: Junos remains on Juniper EX/QFX hardware, and supported CX switches retain their platform software. Mist provides the cloud operations layer.
The service is most valuable when wired and wireless are viewed together. A user complaint that appears to be Wi-Fi can originate from DHCP, VLAN, authentication, switch-port or upstream congestion. Shared telemetry and client context reduce the manual work required to join those events.
Architecture, Connectivity, and Telemetry
The cloud portal maintains organization, site, device, configuration, and assurance context. Supported switches establish the required management connectivity and send operational data to the service. Juniper documentation describes management methods that can include outbound SSH/NETCONF sessions depending on the platform and adoption model. Firewall, DNS, NTP, proxy, and management-network requirements should be validated before onboarding.
Separate management reachability from user traffic design. Define management VLANs or routing, source addresses, access control, name resolution, time synchronization, and internet egress. Document what happens if the cloud connection is unavailable. A temporary management outage should not be confused with a forwarding outage, but operators need a tested local access and recovery path.
Telemetry quality depends on consistent identity and topology. Use stable switch names, site assignments, interface descriptions, VLAN labels, and client context. Correct LLDP, RADIUS, DHCP, and authentication integrations improve root-cause analysis. Incomplete or inconsistent data can cause an assurance dashboard to describe symptoms without enough context to identify ownership.
Plan API and event integrations deliberately. Decide which inventory, alert, audit, or SLE data flows to the service desk, SIEM, reporting, or automation system. Start with actionable events and assigned owners instead of exporting every condition. The goal is a shorter operational workflow, not another stream of untriaged notifications.
From Day 0 Onboarding to Day 2 Operations
| Lifecycle | Wired Assurance role | Operational value |
|---|---|---|
| Day 0 | Claim inventory, assign site and prepare configuration | Consistent staging and ownership |
| Day 1 | Zero-touch provisioning, templates and port profiles | Repeatable rollout across sites |
| Day 2 | SLEs, insights, events, Marvis and root-cause workflows | Faster troubleshooting and proactive operations |
Templates can standardize VLANs, uplinks, authentication and port behavior across a fleet. Port profiles make role-based configuration easier for endpoints such as APs, phones, printers and cameras. The best deployments still maintain change control: a cloud template can spread a mistake as efficiently as a correct setting.
Templates, Port Profiles, and Change Control
Define a configuration hierarchy before creating templates. Separate organization-wide standards, site-specific values, switch-role settings, and device exceptions. Use variables for values that legitimately differ between sites instead of cloning templates. Record which source is authoritative when an effective configuration combines several layers.
Build port profiles around endpoint roles: access point, phone plus workstation, printer, camera, building system, user access, trunk, uplink, quarantine, and unused port. Each profile can carry VLAN, authentication, PoE, LLDP, storm control, and security behavior appropriate to that role. Clear naming helps a help-desk or field technician apply the correct intent without memorizing low-level commands.
Use peer review and staged rollout for template changes. Apply material changes to a lab or representative canary site, validate connectivity and SLEs, and then expand in controlled waves. Maintain a documented emergency procedure and local access path. Automation increases consistency, but it also increases the blast radius of an incorrect assumption.
Handle exceptions with ownership and expiry. A one-off port or site override can be necessary during migration, but invisible permanent exceptions recreate configuration drift. Record the business reason, approver, and review date, then remove or incorporate the requirement into the standard when appropriate.
Wired Service-Level Expectations
Juniper documents wired SLEs around three experience areas: successful connect, throughput and switch health. The dashboards classify problems so an operator can move from a high-level failure rate to affected sites, switches, VLANs, interfaces or clients.
- Successful connect: helps identify failures before or during network access, including authentication and address-assignment problems.
- Throughput: highlights congestion, interface anomalies, storm control and other conditions that affect usable traffic.
- Switch health: surfaces CPU, memory, environmental and platform issues that can degrade service.
Marvis can add natural-language investigation and recommendations, but it is an associated subscription rather than a reason to skip sound telemetry, naming and site design. Good data in produces better operational answers.
Use baselines before setting targets. Measure connection success, authentication, address assignment, port errors, congestion, CPU, memory, and environmental health on a representative stable network. Then define which degradation creates an alert, who owns it, and what evidence is required for escalation. Default dashboards become more valuable when paired with an operational response.
Investigate from the user outcome toward the infrastructure. Start with the affected clients, time window, site, and service, then follow the classifier into authentication, DHCP, VLAN, port, uplink, or switch health. Compare recent changes and similar unaffected clients. This keeps the SLE workflow focused on evidence rather than treating every anomaly as a hardware fault.
Supported EX, QFX and CX Switches
Wired Assurance supports a broad set of Juniper EX and QFX platforms and, following HPE's networking portfolio integration, selected CX switches. Compatibility is model- and release-specific. Check the current supported-hardware list for the minimum Junos or platform version before onboarding.
EX is generally the first choice for a Mist-managed campus access design because Juniper positions it for interoperability with Mist APs. QFX support can extend assurance to selected core and data-center-adjacent roles. The EX Series guide and QFX guide cover the hardware differences.
Do not infer support from the family name alone. Check the exact switch PID, port configuration, minimum software release, management mode, and feature limitations against the current documentation. The official subscription table groups supported switches into device classes, which can also affect the orderable subscription SKU.
For mixed portfolios, define which sites and roles will be cloud-managed, assurance-only, or managed through existing tools. A phased approach can preserve stable core workflows while introducing cloud operations at the access layer. The target operating model should be explicit so engineers do not make competing changes through multiple systems.
Wired Assurance Licensing
Juniper's current subscription documentation separates the base Wired Assurance service from associated subscriptions. The base service is ordered for the supported switch class and term. Optional Marvis for Wired and Premium Analytics capabilities require the base service and can be purchased separately or through applicable bundles. Common terms include one, three, and five years, with exact SKUs varying by device class.
Subscriptions are associated with active device counts rather than permanently locked to a particular serial number. A failed switch can be replaced without buying an additional entitlement when the number of active managed devices remains within the purchased quantity. Inventory, subscription usage, and renewal ownership still need active management in the portal.
Keep the Junos or platform feature entitlement separate from the cloud-service entitlement. A switch may require a software tier for routing, encryption, or other features in addition to Wired Assurance. Marvis and analytics do not replace those platform licenses. Compare quotes with separate columns for hardware, operating-system features, base assurance, associated services, support, term, and renewal.
Match services to an operational requirement. Purchase Marvis for Wired where its actions and investigation workflows will be used, and Premium Analytics where extended or cross-domain reporting has an owner. Buying every add-on without a process to consume it increases recurring cost without improving outcomes.
Brownfield and Greenfield Migration Models
Greenfield: Claim inventory, assign sites, build templates, validate software, and use zero-touch provisioning before switches reach remote locations. Test DHCP, DNS, NTP, cloud reachability, administrator access, and rollback in staging. Ship a documented cabling and acceptance plan with each site kit.
Brownfield: Inventory the running configuration and identify local features, scripts, authentication, and monitoring dependencies before adoption. Remove stale configuration where safe, map existing intent to templates and port profiles, and decide which exceptions must remain. Do not assume that importing a switch automatically turns an inconsistent configuration into a standard one.
Phased fleet: Start with a representative but lower-risk site. Validate management stability, effective configuration, SLE data, alerts, local recovery, and help-desk workflow. Expand by repeatable site waves and maintain a clear system of record while both old and new management methods coexist.
For every model, define success criteria before onboarding. Examples include configuration compliance, connection-success rate, alert response, software consistency, reduced troubleshooting time, and fewer site-specific exceptions. A migration is complete when operations work reliably, not merely when every serial number appears in inventory.
Security, Roles, and Day-Two Operations
Integrate administrator access with the organization's identity provider where appropriate, require strong authentication, and apply least-privilege roles. Separate routine operations from organization-wide administration. Document emergency access, ownership transfer, and offboarding, and review audit records for high-impact changes.
Define firmware policy, maintenance windows, canary groups, and rollback expectations. Review release notes and platform compatibility, then monitor SLEs and switch health after an upgrade. Avoid changing firmware, templates, and authentication policy in the same window unless the test plan can isolate failures.
Create runbooks for common events: switch offline, port flap, authentication failure, DHCP failure, high CPU, power issue, loop, rogue DHCP, and configuration noncompliance. State the evidence to collect and the boundary between help desk, network engineering, security, reseller, and manufacturer support.
Measure adoption. Track whether configuration drift falls, incidents are detected earlier, mean time to resolution improves, and site deployments become more repeatable. Compare those benefits with subscription and operating cost during renewal rather than renewing solely because the service is already deployed.
Mist Wired Assurance Deployment Plan
- Inventory switch models, serials, firmware and existing Junos licenses.
- Check every model against Mist supported hardware and minimum releases.
- Define organizations, sites, naming, templates and administrator roles.
- Pilot one representative switch and validate rollback procedures.
- Create port profiles for common endpoint roles and authentication policy.
- Set SLE baselines and alert ownership before broad onboarding.
- Match switch class, tier, term and optional Marvis/analytics subscriptions.
Use https://globalpricelist.com/juniper-mist to compare current Mist-related hardware and subscription part numbers, and keep the broader Mist AI licensing overview available when reviewing wireless and WAN services in the same program.
Before production, test switch replacement, cloud-connectivity loss, local administrator access, a template change, a port-profile change, authentication, DHCP, alerts, and escalation. Save a healthy baseline and the accepted effective configuration for each site type.
Keep the bill of materials itemized by switch class, quantity, base assurance term, optional Marvis or analytics service, platform license, and support. Align renewal dates with procurement ownership and review inactive or spare devices so subscription usage stays accurate.
Create an acceptance report for each site type. Include cloud reachability, inventory assignment, effective configuration, uplinks, VLANs, routing, authentication, DHCP, PoE, AP connectivity, alert delivery, SLE visibility, local recovery, and software compliance. Record expected results and owners for exceptions. This turns onboarding into a repeatable service transition instead of a dashboard enrollment exercise.
After broad rollout, review template drift, exception count, subscription utilization, SLE trends, incident response, upgrade success, and administrator activity. Compare operational outcomes with the pre-migration baseline. If data quality or response ownership is weak, fix those processes before buying additional analytics capabilities.
Wired Assurance is most useful as part of a coherent access architecture. Pair it with the Juniper AP comparison for wireless refresh planning and the SRX comparison where branch WAN and security assurance are also in scope. Keep the base subscriptions and optional Marvis services itemized for each domain.
Before renewal, compare active inventory, purchased quantities, feature use, support outcomes, and operational improvements. Remove unused capacity where appropriate and correct entitlement gaps before they affect management or assurance workflows.
Sources
- Mist Wired Assurance Overview - Juniper Networks
- Mist Wired Assurance Datasheet - HPE Juniper Networking
- Wired SLEs - Juniper Networks
- Mist Subscription Types - Juniper Networks
FAQ
What does Juniper Mist Wired Assurance do?
It provides cloud onboarding, configuration, monitoring, wired SLEs and AI-assisted troubleshooting for supported enterprise switches.
Which switches work with Mist Wired Assurance?
Supported hardware includes many EX and selected QFX and CX switches. Compatibility depends on exact model and software release.
What are wired SLEs?
Wired service-level expectations measure client-impacting outcomes such as successful connection, throughput and switch health and classify likely causes.
Is Marvis included with Wired Assurance?
Marvis can be an associated subscription and requires active Wired Assurance. Bundles may package services differently, so verify the quote.
How long are Wired Assurance subscriptions?
Common switch cloud-subscription terms are 1, 3 or 5 years, with class and tier varying by platform and feature requirements.
Check Current Juniper Mist Pricing
Browse the full, daily-updated Juniper Mist GPL on GlobalPriceList.com.
View Juniper Mist Price List