Device Onboarding & Zero-Touch Provisioning (ZTP)

How can we help?
You are here:
Print

Device Onboarding & Zero-Touch Provisioning (ZTP)

Objective

Validate that a z40 can be brought under Director management via:

  1. Manual onboarding from the Onboard List Page, and
  2. Zero Touch Secure Provisioning via the AmZetta Provision Server (MSP-driven).

Confirm the device is visible to Director (Provider) after each flow.

Prerequisites

  • z40 powered and with WAN connectivity (internet access).
  • Director admin access.
  • For manual onboarding: the device appears as a row in the Onboard List Page (so it can be onboarded or deleted).
  • For ZTP: MSP access to the Provision Server, MSP credentials, the device’s Product ID (format: ModelNo:UUID), Tenant MGMT Portal Access URL, and associated access token.

Test 1 — Manual Onboarding via the Onboard List Page

Setup

  1. Log in to Director.
  2. Open the Onboard List Page (shows all Edge Controllers; you can SearchOnboard Edge Controller, or Delete).

Steps

  1. In the list, hover over the row for the target Edge Controller.
    • An onboard icon appears in the row.
  2. Click the onboard icon.
    • An onboarding panel opens.
  3. In the panel:
    • Select the Edge Controller from the dropdown list (the device to onboard to Director).
    • Leave the Management Tunnel Servers section as-is (it is disabled by default here).
      • To add or change a management tunnel server, navigate to the Tunnel Server page and add it there (outside of this onboarding panel).
    • Optionally provide:
      • Name
      • Description
      • Tags: a set of key–value pairs (e.g., location, coordinates).
  4. Confirm/submit the onboarding action in the panel.

Validation

  • The device is now onboarded to the Director.
  • The row remains visible in the Onboard List Page and reflects the onboarded state.

Evidence

  • Onboard List Page showing the device after the onboard action.
  • (If you added Name/Description/Tags) verify they appear as entered.

Notes

  • Search is available on the list page to quickly find the target device.
  • Delete is available from the list: hovering over a row shows a delete icon. Clicking it opens a confirmation dialog (proceeding will permanently remove the onboarded Edge Controller from the Director; Cancel aborts the deletion).

Test 2 — Zero-Touch Secure Provisioning (ZTP) via Provision Server

Overview of roles

  • AmZetta Provision Server maintains the Product ID of each Edge Controller (EC).
    • Each EC is flashed with a firmware image and assigned a unique Product ID (ModelNo:UUID) written to the unit’s eMMC.
  • MSP (Managed Service Provider) registers with the Provision Server to obtain MSP credentials, imports the Product IDs assigned for that MSP, and configures tenant information.

MSP Preparation (Provision Server)

  1. Register to the Provision Server and obtain MSP credentials.
  2. Import Product IDs (the ECs assigned to this MSP).
  3. Add Tenant MGMT Portal Access URL and access token for the tenant(s) this MSP will use.
    • An MSP can add multiple tenants.
  4. Map each EC (PRODUCT ID) to the appropriate Tenant.

ZTP Flow (Device)

  1. Power on the Edge Controller and connect its WAN to the internet.
    • On boot, the EC reaches the Provision Server automatically.
  2. The Provision Server handles the onboarding relationship according to the MSP’s mapping.
  3. Result: EC units that are waiting to be onboarded can be seen at Director (Provider).

Validation

  • In Director (Provider), verify the device appears for the mapped Tenant as expected.
  • Confirm the device is visible for onboarding/management per your Director workflow.

Evidence

  • Director inventory view showing the EC visible under the mapped Tenant after ZTP.
  • (If you manage multiple Tenants) confirm an EC mapped to a different Tenant appears under that Tenant as configured.

Negative / Edge Cases (as directly implied)

  • No MSP registration / credentials on the Provision Server → ZTP cannot proceed; EC will not be mapped to any Tenant.
  • PRODUCT ID not imported or not mapped to a Tenant → EC powers on but does not appear in Director (Provider) for any Tenant.
  • Tenant MGMT Portal Access URL / access token missing → MSP cannot complete tenant setup; EC cannot be associated properly.

Acceptance Criteria

  • Manual Onboarding: Using the onboard icon from the Onboard List Page, the device is onboarded to Director; optional Name/Description/Tags can be set; Management Tunnel Servers are not configured here (they’re added on the Tunnel Server page).
  • ZTP via Provision Server: After MSP sets up (Product IDs, Tenant MGMT Portal Access URL + access token, mappings), powering on the EC results in the unit being visible at Director (Provider) for the mapped Tenant.
Was this article helpful?
0 out Of 5 Stars
5 Stars 0%
4 Stars 0%
3 Stars 0%
2 Stars 0%
1 Stars 0%
5
How can we improve this article?
Please submit the reason for your vote so that we can improve the article.
Table of Contents