Zero-touch provisioning (ZTP) stands up a new site with no CLI and no truck-roll. Someone on site just plugs the edge in; the appliance does the rest — it's what makes zero-touch SD-WAN site rollouts a job for days rather than months.
How ZTP works
Pre-stage the site
Create the site in the Network Portal and assign its transports, segments, and policies before the hardware arrives.
Ship the edge
Send the edge appliance to the location. It's tied to your account, so it will only ever join your fabric.
Plug in WAN and power
On-site staff connect a WAN circuit and power. No configuration, no console — a network port and an outlet is enough.
Auto-register
The edge calls home over TLS, authenticates, and registers to the Portal. You approve it (or auto-approve pre-staged serials).
Pull configuration
It downloads the site's transports, segments, steering, and QoS policy, brings up the encrypted fabric, and reports healthy — usually in minutes.
What you need on site
- The edge appliance (or a virtual edge image for cloud sites).
- At least one WAN circuit live at the location.
- Power and a way to connect the LAN.
That's it — no engineer, no per-device setup.
Bulk and templated rollouts
For multi-site deployments, define a site template (standard transports, segments, and policy) and apply it to each new location, so every site comes up configured the same way. Pre-load serial numbers for auto-approval and roll out dozens of sites without touching each one.
Order matters
Pre-stage the site and its policy before the hardware is plugged in. If an edge registers before its site exists, it waits in a pending state until you assign it — harmless, but the site won't carry traffic until configuration is attached.
