What Is ZTP (Zero-Touch Provisioning)?

Related problems: Sending engineers to every branch to install routers costs too much; Rolling out new sites takes weeks of configuration work; Configurations differ from site to site because each was set up by hand; Replacing a failed device at a remote site takes too long

Zero-touch provisioning (ZTP) is a way of deploying network equipment so that a new device configures itself when it is powered on and connected, instead of an engineer configuring it by hand on site. The device reaches a provisioning or management service, proves its identity, and downloads its software and configuration. ZTP is widely used in SD-WAN rollouts and by managed network providers to bring up branch sites quickly and consistently.

Not to be confused with imaging and zero-touch deployment, which sets up company laptops and other computers with a standard configuration and enrolls them in device management.

At a glance

  • ZTP removes on-site configuration work, not the physical work of installing and cabling the device.
  • The device is usually registered in advance by serial number or certificate, then shipped directly to the site.
  • On first boot it reaches a cloud or on-premises provisioning service and pulls its configuration.
  • It is common in SD-WAN, wireless and branch networking, and support varies by vendor and model.
  • It typically depends on the site having working connectivity, often internet with automatic addressing.

What problem it solves

Rolling out a network at many locations used to mean either sending a skilled engineer to each site or preconfiguring every device at a staging center and shipping it out. Both are slow and expensive, and hand-built configurations drift from one site to the next. Replacing a failed router at a remote branch could mean waiting for an engineer to travel.

ZTP lets the central team define configurations in templates, assign them to devices by serial number, and ship devices straight from the distributor. Someone at the site, such as an office manager or a field technician, plugs it in. The device comes online with the intended configuration, and the central team can confirm it from a dashboard.

How it works

Registration. The device’s serial number, certificate or other identity is registered with the vendor’s or provider’s provisioning service and linked to a site and configuration template.

First boot. When powered on, the device looks for network connectivity, commonly by requesting an address automatically through DHCP on its WAN port. Some devices can use cellular or other fallback connections.

Discovery. The device contacts a known provisioning address, often built into its software, or learns one from the network. It authenticates, usually with a certificate installed at the factory.

Configuration and software. The service sends the device its configuration and, where needed, a software update. The device applies them and connects to the central management platform.

Ongoing management. Once provisioned, the device is usually managed centrally, so later changes can also be pushed without a site visit. Details depend on the platform; some on-premises equipment uses older script-based methods that fetch a file from a server on the local network.

Managed providers often handle registration and templates for you; our Managed Network Services page covers how those services are structured.

When it matters for buyers

  • Multi-site rollouts. Retail chains, clinics, branch offices and franchise networks benefit most, because savings grow with the number of sites.
  • Choosing SD-WAN or customer premises equipment. Check how ZTP works on the specific models offered, not just whether the brochure mentions it.
  • Sites with unusual connectivity. Static IP addressing, proxies or a locked-down upstream network may need a manual step before ZTP can work.
  • Spares and replacements. ZTP can shorten the time to replace a failed device, as long as spares are registered and stocked.

Questions to ask vendors

  • What does someone at the site need to do, step by step, and what skills do they need?
  • What connectivity must be in place before the device can provision itself?
  • How is the device authenticated, and how is the configuration protected in transit?
  • Who registers devices and builds the templates: us, you, or a reseller?
  • What happens if provisioning fails, and how is that escalated?
  • How are replacement devices registered and shipped after a failure?

How it differs from SD-WAN

SD-WAN is a way of building and managing a wide area network that steers traffic across several links. ZTP is a deployment method: how a device gets its initial configuration. SD-WAN products made ZTP familiar because they are managed centrally and installed at many sites, but ZTP is also used for switches, access points, firewalls and customer premises equipment outside SD-WAN. Buying SD-WAN does not by itself mean every rollout will be zero-touch; confirm what the vendor’s process actually requires at your sites.

Frequently Asked Questions

Does zero-touch mean nobody has to touch the device?
No. Someone still has to unbox it, rack or place it, and plug in power and the network cables. Zero-touch means nobody with networking skills has to configure it on site. Some deployments also need a person on site to scan a code or confirm activation.
What does a device need to use ZTP?
It needs a path to reach the provisioning service, usually an internet connection with automatic addressing, and a way to prove its identity, such as a serial number or certificate registered in advance. Sites with static addressing, proxies or restrictive firewalls may need extra steps.
Is ZTP secure?
It can be, when devices authenticate to the provisioning service with certificates or pre-registered identities and download configurations over encrypted connections. Weak implementations that accept any device or fetch configurations without verification are a risk. Ask how the vendor verifies both the device and the server.
Is ZTP only for SD-WAN?
No. SD-WAN made it well known for branch rollouts, but many switches, wireless access points, firewalls and routers support some form of zero-touch or automated provisioning.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.