How can we help?
-
zWAN
-
-
-
-
- Firewall & Layer 7 Application Filtering
- VPN Site-to-Site Tunnel Setup & Connectivity (z40 to Cloud vGR)
- Intrusion Prevention System (IPS) / Intrusion Detection System (IDS) Testing
- DNS Filtering
- DDoS Protection & Logging
- MAC Address Filtering & Geo-fencing
- Application Control & Protocol Blocking
- Authentication & Access Control (zID)
-
- WAN Link Failover & Load Balancing (ACI Mode)
- Dynamic Path Selection & Application-Aware Routing
- SaaS & Internet Breakout Validation
- QoS for Microsoft Teams (Datacenter vGR + Branch z40)
- Tunnel Failover (z40 ↔ vGR) — WAN00 (wired) primary, WAN03 (4G) & WAN04 (5G) backups
- IP Routing & Static Route Steering (z40 Branch)
- VLAN & Layer-2 Bridging
-
-
-
-
-
-
- Articles coming soon
-
- Articles coming soon
-
-
-
- Articles coming soon
-
- Articles coming soon
-
-
-
-
-
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
-
-
-
-
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
-
-
-
-
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
- Articles coming soon
-
-
-
- Articles coming soon
-
- IPsec Tunnel not Establishing
- SSL-VPN Tunnel not Establishing
- Mobile Network Issues
- Management Tunnel does not Establish
- DNS not Resolving from Local Network Appliance
- DNS Resolution Issues in Tunnel Configuration
- DHCP Server not Leasing IP to LAN PC
- Debugging EC Events - Unknown Status Issue
- Trusted-MAC Geofencing Issues
- DNS Issues from DC LAN PC
- Troubleshooting LAN Connectivity to Internet via WAN, Remote Branch LAN, or Local Branch LAN
- NetBalancer gateways displaying Faulty/Inactive
- Packet Drop Issues
-
-
zTC
-
-
-
-
-
- Citrix HDX + USB Headset (Call-Center Baseline)
- OS/Firmware Update & Rollback
- Power Management and Session State
- Wi-Fi Roaming & Link Change Mid-Session
- Kiosk / Assigned-Access Auto-Launch
- Barcode Scanner (HID) with Line-of-Business App
- Printing to Local USB & Network Printers
- USB Device Management – Block Storage
- Multi-Monitor & 4K Performance
- Microsoft AVD/RDP + Teams Optimized Video
- VMware Horizon + Smart Card / CAC Login
-
-
StorTrends
-
zAccess
-
zGuardian
You are here:
Print
Device Onboarding & Zero-Touch Provisioning (ZTP)
0 out Of 5 Stars
| 5 Stars | 0% | |
| 4 Stars | 0% | |
| 3 Stars | 0% | |
| 2 Stars | 0% | |
| 1 Stars | 0% |
Objective
Validate that a z40 can be brought under Director management via:
- Manual onboarding from the Onboard List Page, and
- Zero Touch Secure Provisioning via the AmZetta Provision Server (MSP-driven).
Confirm the device is visible to Director (Provider) after each flow.
Prerequisites
- z40 powered and with WAN connectivity (internet access).
- Director admin access.
- For manual onboarding: the device appears as a row in the Onboard List Page (so it can be onboarded or deleted).
- For ZTP: MSP access to the Provision Server, MSP credentials, the device’s Product ID (format: ModelNo:UUID), Tenant MGMT Portal Access URL, and associated access token.
Test 1 — Manual Onboarding via the Onboard List Page
Setup
- Log in to Director.
- Open the Onboard List Page (shows all Edge Controllers; you can Search, Onboard Edge Controller, or Delete).
Steps
- In the list, hover over the row for the target Edge Controller.
- An onboard icon appears in the row.
- Click the onboard icon.
- An onboarding panel opens.
- In the panel:
- Select the Edge Controller from the dropdown list (the device to onboard to Director).
- Leave the Management Tunnel Servers section as-is (it is disabled by default here).
- To add or change a management tunnel server, navigate to the Tunnel Server page and add it there (outside of this onboarding panel).
- Optionally provide:
- Name
- Description
- Tags: a set of key–value pairs (e.g., location, coordinates).
- Confirm/submit the onboarding action in the panel.
Validation
- The device is now onboarded to the Director.
- The row remains visible in the Onboard List Page and reflects the onboarded state.
Evidence
- Onboard List Page showing the device after the onboard action.
- (If you added Name/Description/Tags) verify they appear as entered.
Notes
- Search is available on the list page to quickly find the target device.
- Delete is available from the list: hovering over a row shows a delete icon. Clicking it opens a confirmation dialog (proceeding will permanently remove the onboarded Edge Controller from the Director; Cancel aborts the deletion).
Test 2 — Zero-Touch Secure Provisioning (ZTP) via Provision Server
Overview of roles
- AmZetta Provision Server maintains the Product ID of each Edge Controller (EC).
- Each EC is flashed with a firmware image and assigned a unique Product ID (ModelNo:UUID) written to the unit’s eMMC.
- MSP (Managed Service Provider) registers with the Provision Server to obtain MSP credentials, imports the Product IDs assigned for that MSP, and configures tenant information.
MSP Preparation (Provision Server)
- Register to the Provision Server and obtain MSP credentials.
- Import Product IDs (the ECs assigned to this MSP).
- Add Tenant MGMT Portal Access URL and access token for the tenant(s) this MSP will use.
- An MSP can add multiple tenants.
- Map each EC (PRODUCT ID) to the appropriate Tenant.
ZTP Flow (Device)
- Power on the Edge Controller and connect its WAN to the internet.
- On boot, the EC reaches the Provision Server automatically.
- The Provision Server handles the onboarding relationship according to the MSP’s mapping.
- Result: EC units that are waiting to be onboarded can be seen at Director (Provider).
Validation
- In Director (Provider), verify the device appears for the mapped Tenant as expected.
- Confirm the device is visible for onboarding/management per your Director workflow.
Evidence
- Director inventory view showing the EC visible under the mapped Tenant after ZTP.
- (If you manage multiple Tenants) confirm an EC mapped to a different Tenant appears under that Tenant as configured.
Negative / Edge Cases (as directly implied)
- No MSP registration / credentials on the Provision Server → ZTP cannot proceed; EC will not be mapped to any Tenant.
- PRODUCT ID not imported or not mapped to a Tenant → EC powers on but does not appear in Director (Provider) for any Tenant.
- Tenant MGMT Portal Access URL / access token missing → MSP cannot complete tenant setup; EC cannot be associated properly.
Acceptance Criteria
- Manual Onboarding: Using the onboard icon from the Onboard List Page, the device is onboarded to Director; optional Name/Description/Tags can be set; Management Tunnel Servers are not configured here (they’re added on the Tunnel Server page).
- ZTP via Provision Server: After MSP sets up (Product IDs, Tenant MGMT Portal Access URL + access token, mappings), powering on the EC results in the unit being visible at Director (Provider) for the mapped Tenant.
Was this article helpful?
0 out Of 5 Stars
| 5 Stars | 0% | |
| 4 Stars | 0% | |
| 3 Stars | 0% | |
| 2 Stars | 0% | |
| 1 Stars | 0% |
5
Table of Contents