INNOVEXUS
Integration · Extreme Networks

Innovexus + Extreme Networks.EXOS, VOSS, Fabric Engine — agentless PAM.

Extreme Networks operates across campus, data centre, and edge with EXOS as the historical platform, VOSS (Virtual Services Platform) for fabric-attached deployments, and the Fabric Engine successor unifying both. Innovexus brokers SSH sessions to every Extreme CLI-accessible platform — no agent, no ExtremeCloud IQ dependency, no MOS plugin. Vault, rotation, session recording, and drift detection work consistently.

§ 01 / Supported devices and OS

Extreme Networks platforms supported.

Innovexus is agentless from the Extreme device perspective. Connection via SSH (preferred) and console. Authentication via TACACS+, RADIUS, or local users.

Device family
OS / platform
Examples
Notes
X-Series switches (EXOS)
ExtremeXOS
X450, X460, X465, X590, X670, X690, X870
Full session recording, vault, rotation, drift detection
VSP / 5000 / 7000 series (VOSS)
VOSS
VSP 4900, VSP 7400, VSP 8000, 5520, 5320
Fabric-attached and fabric-extend environments
Fabric Engine
Fabric Engine (unified successor)
Fabric Engine 5000, 5320, 5420, 7520, 7720
Unified EXOS+VOSS successor; same SSH and AAA primitives
Extreme access points
AP firmware
AP3000, AP4000, AP5050 (Wi-Fi 6 / 6E / 7)
CLI access; configuration typically managed via ExtremeCloud IQ
Cloud-managed
ExtremeCloud IQ
XIQ tenant administration
SAML SSO via Innovexus identity for XIQ web admin
§ 02 / How the integration works

Extreme-specific setup, in plain language.

Most Extreme Networks fleets are running through Innovexus within 1–2 business days. The mix of EXOS and VOSS platforms is handled cleanly because both expose standard SSH-based AAA.

  1. 01

    Vault local admin credentials

    Pull existing local admin credentials from each platform class (EXOS and VOSS use slightly different config syntax; Innovexus handles the difference). Vault them. Rotation runs on schedule.

  2. 02

    Allowlist the pod IP

    Add the Innovexus pod's outbound IP to your management ACLs. Existing TACACS+/RADIUS continues at the device level.

  3. 03

    Role mapping

    Map Extreme role profiles to Innovexus role definitions. EXOS uses default `admin` / `user` accounts; VOSS uses CLI access levels (rwa, ro, layer-2-admin, etc.).

  4. 04

    Session recording and drift collection

    Session recording captures the full CLI experience across both EXOS and VOSS. Configuration drift collection uses the appropriate `show configuration` syntax per platform.

  5. 05

    Engineers connect through the pod

    Engineers log into Innovexus with their FIDO2 hardware key, click into an Extreme device, and the brokered SSH session opens with the assigned role. Recording, audit, and credential lifecycle operate automatically.

§ 03 / What you get

What you get once integrated.

/ 01

Mixed EXOS / VOSS session recording

Both platforms supported with appropriate CLI parsing. Searchable text across the mixed fleet — useful as Extreme customers consolidate onto Fabric Engine over time.

/ 02

Atomic credential rotation across platforms

Local admin credentials, TACACS+ shared secrets, and RADIUS keys rotate on schedule. Rotation handles the syntactic differences between EXOS and VOSS automatically.

/ 03

IP-locked management

Extreme devices accept management connections only from the Innovexus pod IP. Out-of-band emergency access via vaulted credentials remains available.

/ 04

Configuration drift detection

Continuous baseline collection across EXOS, VOSS, and Fabric Engine fleets. Drift detected outside approved sessions fires an alert.

/ 05

Fabric Engine migration support

Innovexus supports both legacy EXOS and VOSS plus the unified Fabric Engine successor, so PAM operations don't need to change as you migrate. Audit continuity is preserved across the platform transition.

/ 06

NOC + SOC bundled

Network monitoring and security operations alongside PAM. Same console, one audit trail, one tier price.

Extreme Networks integration · FAQ

Common questions about Innovexus and Extreme Networks

Direct, sourced answers about how Innovexus integrates with this vendor's platforms.

01

Does Innovexus require ExtremeCloud IQ?

No. The integration is direct via SSH using each platform's standard AAA primitives. ExtremeCloud IQ, ExtremeCloud A3 (formerly Aerohive), and ExtremeManagement are not dependencies. If you run XIQ for orchestration, Innovexus runs alongside it — we handle privileged human and vendor access; XIQ handles cloud management.

02

How does this handle the EXOS-to-Fabric-Engine migration?

Cleanly. Innovexus supports EXOS, VOSS, and Fabric Engine in the same fleet. As you migrate devices to Fabric Engine, Innovexus continues to broker sessions, vault credentials, and detect drift through the transition. The audit trail remains continuous — you can search a single device's session history across the platform migration boundary.

03

What about Extreme's Aerohive APs (now ExtremeWireless)?

Aerohive APs and the Extreme Wireless platform are typically managed via ExtremeCloud IQ rather than direct CLI. Innovexus integrates with XIQ via SAML SSO for tenant administration. CLI access to APs is supported for diagnostic purposes but not the primary administrative path.

04

Can Innovexus rotate VOSS shared secrets?

Yes. VOSS-side TACACS+ and RADIUS shared secrets are vaulted and rotated on schedule. The rotation uses VOSS's configuration syntax for shared-key updates and respects the platform's commit model.

05

How does this work in a fabric-attached environment?

Innovexus is fabric-topology agnostic — we connect via SSH to whichever VOSS or Fabric Engine devices you put in scope, regardless of fabric role. The integration doesn't depend on or interfere with the fabric (SPB, VXLAN) control plane. Configuration drift detection works across the entire fabric.

06

Does session brokering work over slow campus WAN links?

Yes, with normal SSH overhead. The brokered SSH session adds typically 5–20 ms of latency at the protocol layer beyond direct access. For campus and branch deployments where the device is reached over a WAN link, total round-trip latency depends on the WAN — not Innovexus. The broker model imposes no additional latency penalty beyond the SSH layer.

Extreme fleet on unified PAM, in days.

FROM $199 / MO5-DAY FREE TRIAL

Vault credentials for one device class, allowlist the pod IP, point engineers at it. EXOS, VOSS, and Fabric Engine all supported in the same trial. 5-day trial, no card required.