Documentation

SD-WAN · Guides

Zero-touch provisioning

Bring a new SD-WAN site online without an engineer — ship the edge, plug in WAN and power, and it auto-registers to the Network Portal and pulls its configuration.

Zero-touch provisioning (ZTP) stands up a new site with no CLI and no truck-roll. Someone on site just plugs the edge in; the appliance does the rest — it's what makes zero-touch SD-WAN site rollouts a job for days rather than months.

How ZTP works

Pre-stage the site

Create the site in the Network Portal and assign its transports, segments, and policies before the hardware arrives.

Ship the edge

Send the edge appliance to the location. It's tied to your account, so it will only ever join your fabric.

Plug in WAN and power

On-site staff connect a WAN circuit and power. No configuration, no console — a network port and an outlet is enough.

Auto-register

The edge calls home over TLS, authenticates, and registers to the Portal. You approve it (or auto-approve pre-staged serials).

Pull configuration

It downloads the site's transports, segments, steering, and QoS policy, brings up the encrypted fabric, and reports healthy — usually in minutes.

What you need on site

  • The edge appliance (or a virtual edge image for cloud sites).
  • At least one WAN circuit live at the location.
  • Power and a way to connect the LAN.

That's it — no engineer, no per-device setup.

Bulk and templated rollouts

For multi-site deployments, define a site template (standard transports, segments, and policy) and apply it to each new location, so every site comes up configured the same way. Pre-load serial numbers for auto-approval and roll out dozens of sites without touching each one.

Order matters

Pre-stage the site and its policy before the hardware is plugged in. If an edge registers before its site exists, it waits in a pending state until you assign it — harmless, but the site won't carry traffic until configuration is attached.

Need a hand with SD-WAN?Talk to our team →