On this page
01 What IronPoint was
IronPoint was the wireless line that Foundry Networks added around 2004 so that it could sell a complete campus edge: FastIron Edge switches with Power over Ethernet feeding IronPoint access points, all under one management umbrella. The first and best known product was the IronPoint 200, a dual-band 802.11a/b/g access point. The user guide dated early 2004 is the document that most old links to this domain point at.
Foundry never became a significant WLAN vendor. The line existed to keep a switching customer from bringing in a competitor for wireless, and it was marketed as a wireless solution rather than as a standalone product family.
02 The IronPoint 200 access point
The IronPoint 200 supported 802.11a in the 5 GHz band and 802.11b/g in 2.4 GHz, drew power over Ethernet from a PoE switch port, and could run as a standalone access point with its own web interface or under central management. Security followed the enterprise pattern of the day: 802.1X with a RADIUS server, WPA and later WPA2, multiple SSIDs each mapped to a wired VLAN, and MAC filtering as a fallback. Rogue access point detection and client load balancing between radios appeared in later firmware.
| Component | Role | Notes |
|---|---|---|
| IronPoint 200 | 802.11a/b/g access point | PoE powered; standalone or managed |
| IronPoint wireless management | Central configuration and monitoring | Software application, early releases |
| IronPoint-FES | Switch-integrated AP management | FastIron Edge switches managing attached access points |
| IronPoint Mobility | Controller-based approach | Later positioning; details vary by source |
03 Management model
Early IronPoint deployments used a management application to push configuration to autonomous access points. Around 2005 Foundry introduced IronPoint-FES, in which a FastIron Edge switch discovered attached access points, applied a template and monitored them, so a wireless rollout became an extension of the wiring closet configuration. Later marketing described an IronPoint Mobility approach with a central controller handling roaming and policy, in line with the controller architectures that dominated enterprise WLAN by then. Sources on how far that shipped are thin, so treat it as positioning rather than a documented product generation.
FoundryNet is an independent archive and reference, not affiliated with Foundry Networks or its successors. This page describes the IronPoint line qualitatively and does not reproduce the user guide or product brief.
04 IronPoint in Foundry's own filings
The dates on this page can be tightened from the company's filings. Foundry's Form 10-K for 2003, filed in March 2004, says the company introduced its first wireless product, the IronPoint 200 access point, in the third quarter of 2003, the same year the IEEE 802.11g-2003 amendment was published. The same filing describes an IronPoint edition of the IronView Network Manager for centralised access point management and says FastIron Edge switches could be software upgraded to integrated wireless LAN capability; the 10-K for 2004 names that software IronWare-IP. The 10-K for 2007 describes the IronPoint access point connecting to an IronPoint-FES wireless switch for management, mobility and security.
Two details need care. The January 2007 results release lists IronPoint 200 access points among products introduced in 2006, three years after the first launch; the release does not explain the repeat, so do not assume a new hardware revision without a dated datasheet. And the October 2006 capture of the IronPoint family page lists an IronPoint Mobility Series of controllers and access points, an IronPoint Wireless Location Manager for tracking 802.11 devices and finding rogue access points, the IronPoint-FES switch and an IronPower injector. The controller series therefore did reach the catalogue; how far it sold is not recorded anywhere this site can cite. A separate product page captured in October 2007 describes an IronPoint 250, a standalone dual-band 802.11a/b/g access point with an automatic discovery and configuration protocol, management by web interface, CLI or SNMP v2 and v3, and power from an adapter, an 802.3af switch port or an injector.
| IronPoint element (2003 to 2008) | Vendor-neutral equivalent today | Standard or reference |
|---|---|---|
| Dual-band 802.11a/b/g radios | 802.11ax or 802.11be access points; a/b/g clients are rare and slow the cell | IEEE 802.11-2020 and later amendments |
| WPA and WPA2 with 802.1X and RADIUS | WPA3 for personal and enterprise networks, still with 802.1X and RADIUS behind it | IEEE 802.1X, RFC 2865 |
| IronView centralised AP management | Controller or cloud-managed WLAN with a tunnelling protocol between AP and controller | RFC 5415, CAPWAP |
| IronPoint-FES switch-integrated management | Controller-less access point clusters with one elected manager | Vendor specific |
| Wireless Location Manager and rogue detection | Wireless intrusion detection built into the WLAN management plane | Vendor specific |
| 802.3af power from a FastIron Edge port | 802.3at and 802.3bt budgets for multi-radio access points | IEEE 802.3 |
| Automatic discovery on the IronPoint 250 | Zero-touch provisioning from the management plane | Vendor specific |
05 Position in the WLAN market
Enterprise wireless in the mid-2000s was dominated by a few specialists and by the largest switching vendor. Foundry sold IronPoint mainly into its existing FastIron and BigIron accounts, particularly schools and universities that wanted a single support contract. Volumes were small, the product refresh cycle lagged the market, and there was no 802.11n product before the Brocade acquisition in December 2008. Brocade did not continue a Foundry-derived wireless line.
06 IronPoint today
The hardware is obsolete. 802.11a/b/g radios are slower than any current client expects, the security firmware stopped in the late 2000s and predates fixes for well-known WPA2 weaknesses, and the management software will not run on current operating systems without effort. An IronPoint 200 should not be placed on any network that carries real traffic. Its value is as a collector item or as a PoE load for testing a switch port. The security advisories page lists why unpatched Foundry-era firmware is a risk. The switching and routing lines it was sold alongside are profiled in the product family archive.
07 Running an IronPoint today: the switch-side checks
If an IronPoint 200 or 250 is still hanging from a ceiling, the useful checks are on the switch that feeds it, because the access point has its own command set and no current firmware. First confirm the port budget: an 802.3af access point draws at most 12.95 W at the device, and the switch must be able to supply it after the other ports on the same power supply. Then confirm which VLANs the port carries, because each SSID was mapped to a wired VLAN and an untagged port silently drops the others. Finally look at what the access point is actually bridging onto the wire; a device that old should not be the path for anything that carries credentials.
fes1# show interfaces brief (note link, speed and whether the port is tagged) fes1# show vlan (the port should be tagged in every VLAN an SSID maps to) fes1# show mac-address ethernet 1/12 (one entry is the access point; the rest are wireless clients) fes1# show log (repeated link flaps on the port point to a power budget problem)
The client MAC addresses learned through that port are the quickest census of who still uses the radio, and SNMP polling of the AP's uplink port gives the traffic volume over a week without touching the access point. If the count is not zero, plan the replacement before pulling the unit; if there is any doubt about what the clients are sending, mirroring the AP uplink to a capture host shows it in the clear.
Pitfalls seen with these units:
- Expecting IronWare syntax on the access point; the IronPoint CLI was its own, and the FastIron Edge managed it through IronPoint-FES rather than sharing a command set.
- Assuming an 802.11a radio is usable on every 5 GHz channel today; channel plans and DFS rules changed after 2008 and old firmware cannot be updated to follow them.
- Reading a 2006 product page as a datasheet; the archived pages describe features and management options, not radio power, client limits or certified regions.
- Leaving the management web interface on a routable address; its TLS and cipher options are those of the mid-2000s.
- Counting on the IronView IronPoint edition to still run; it was a management application of the same age as the access points, and a switch-side inventory does the same census without it.
08 Questions
What was the Foundry IronPoint 200?
A dual-band 802.11a/b/g enterprise access point introduced around 2004. It was powered over Ethernet, supported 802.1X with RADIUS, multiple SSIDs mapped to VLANs, and could be managed standalone or centrally from Foundry management software or a FastIron Edge switch.
What was IronPoint-FES?
An integration in which FastIron Edge switches discovered, configured and monitored attached IronPoint access points. It let a wireless deployment be managed as part of the wiring closet rather than from a separate wireless controller.
Did Foundry make an 802.11n access point?
Not before the Brocade acquisition in December 2008. The IronPoint line stayed at 802.11a/b/g throughout its life, and Brocade did not continue any Foundry wireless products, so no 802.11n IronPoint was ever released.
Is it safe to use an IronPoint 200 today?
No. The firmware has had no security updates since the late 2000s, the radios are slow by modern standards, and the encryption options predate current fixes. Keep it off any network with real users or data.
Why was Foundry a minor wireless player?
Wireless was a defensive addition to protect switching accounts, not a core competence. Foundry lacked the radio engineering depth of the specialists, refreshed the line slowly and never shipped a controller generation that matched the market before the company was sold.
Was there an IronPoint 250?
Yes. A Foundry product page captured in October 2007 describes the IronPoint 250 as a standalone dual-band 802.11a/b/g access point with automatic discovery and configuration, management by web interface, CLI or SNMP, and three powering options: an adapter, an 802.3af switch port or an inline injector. Like the 200, it never received an 802.11n successor under Foundry.