Kaspersky SD-WAN

Scenario: Automatic registration of a CPE device using the Zero Touch Provisioning technology.

You can register new CPE devices using Zero Touch Provisioning (ZTP). ZTP allows a CPE device to automatically connect to the orchestrator.

When using ZTP, you must generate an URL with the basic CPE device settings. Basic settings are those settings that are necessary to automatically connect a CPE device to the orchestrator. To complete the registration, you must connect the administrator device to the CPE device and visit the generated basic settings URL on the administrator device.

The ZTP registration scenario for a CPE device involves the following steps:

  1. Creating a CPE template

    Create and configure a CPE template. For details on managing CPE templates, see Managing CPE templates. You can use the created CPE template to configure other CPE devices.

  2. Adding a CPE device

    Add a CPE device. When adding the CPE device, assign the created CPE template to it and select whether the CPE device must automatically turn on after registration. The added CPE device has the Waiting status. For details on managing CPE devices, see Managing CPE devices.

  3. Two-factor authentication (optional step)

    If you want to register your CPE device securely, use two-factor authentication.

  4. Generating an URL with basic settings

    Generate an URL with basic CPE device settings.

  5. Registering the CPE device

    Do the following:

    1. Connect the administrator device to the LAN port of the CPE device.

      The administrator device gets an IP address and the IP address of the default gateway via DHCP. The received IP address of the default gateway is the IP address of the CPE device.

    2. Visit the generated basic settings URL of the CPE device on the administrator device in one of the following ways:
      • In the address bar of the browser, enter the basic settings URL of the CPE device and press Enter.
      • Open the HTML file that you saved when generating the basic settings URL of the CPE device.
    3. On the opened page, click the Apply configuration button.

    The CPE device automatically connects to the orchestrator, binds to the added CPE device in the orchestrator web interface, and registers itself. A registered CPE device has the Registered status and is in the Enabled or Disabled state.

  6. Enabling the CPE device (optional step)

    If, when adding the CPE device, you specified that it must not be enabled automatically, enable the CPE device. An enabled CPE device has the Registered status and is in the Enabled state.

  7. Enabling traffic encryption on the device (optional step)

    If you need to use traffic encryption on the CPE device, enable it for the entire device or for a specific link.