ZTP Zero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. makes the deployment of managed device plug-n-play. The managed device now learns all the required information from the network and provisions itself automatically.
With ZTP Zero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention., a managed device automatically gets its local and global configuration and license limits from a central managed device. A manage device with factory default settings gather the required information from the network and then provision itself automatically.
The main elements for ZTP Zero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. are:
Auto discovery of Mobility Conductor.
Configuration download from the Mobility Conductor.
The following modes are supported:
In this mode, managed device provisions completely automatically. The managed device gets the local IP address and routing information from DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. and gets the Mobility Conductor information and regulatory domain from one of the supported servers. Then, it downloads the entire configuration from the Mobility Conductor.
In this mode, managed device gets its local IP address and routing information from DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server. However, user is required to provide Mobility Conductor information and regulatory domain. Then, it downloads the entire configuration from the Mobility Conductor.
In this mode, managed device gets all the basic provisioning information from user inputs. However, even in this mode, controller can download configuration from the Mobility Conductor if the managed device role is specified as a managed device.
An auto provisioning managed device acts as a DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. client to get its local IP address, routing information, and Mobility Conductor information and regulatory domain from a DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server or Activate server. A factory-default managed device boots in auto provisioning mode. To interrupt the auto provisioning process, enter the string mini-setup or full-setup at the initial setup dialog prompt shown below:
Auto-provisioning is in progress. Choose one of the following options to override or
debug...
'enable-debug' : Enable auto-provisioning debug logs
'disable-debug': Disable auto-provisioning debug logs
'mini-setup' : Stop auto-provisioning and start mini setup dialog for smart-branch role
'full-setup' : Stop auto-provisioning and start full setup dialog for any role
Enter Option (partial string is acceptable):_
If the managed device can not complete ZTP Zero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. provisioning through Activate, then the initial setup process waits for the user to provide input
Activate
The managed device interacts with the activate server to get Mobility Conductor information. The managed device establishes HTTPS Hypertext Transfer Protocol Secure. HTTPS is a variant of the HTTP that adds a layer of security on the data in transit through a secure socket layer or transport layer security protocol connection. connection with the activate server and posts provision requests to it. The activate server authenticates the managed device and provides the Mobility Conductor information and country code to the managed device.
Activate Interface— The managed device and the Mobility Conductor interact with the activate server to receive information about each other. Once all the information is available in the activate server, the relationship between a Mobility Conductor and all the managed device managed by it is provisioned automatically.
The managed device interacts with the activate server to learn about their role, Mobility Conductor information, and their regulatory domain. The Mobility Conductor sends its own information and not managed device information. Activate reuses existing AP-information field for managed device interactions. To achieve this, the following two steps are performed:
1. Mobility Conductor retrieving allowlist db from activate server. The following steps are involved to get the allowlist db:
a. Mobility Conductor sends initial post with ‘keep-alive’ connection type with the following information:
Type as provision update, mode as managed device, session id, Ap-information that includes <serial number>, <mac>, <model>.
b. Activate responds with the following information:
Type as provision update, activate assigned session id, status, and connection as keep alive.
c. Mobility Conductor then sends a second POST Power On Self Test. An HTTP request method that requests data from a specified resource. with ‘close’ connection type with the following information:
Type as provision update, session id received from activate, Ap-information that includes <serial number>, <mac>, <model>, length of certificate, signed certificate, and device certificate.
d. Activate then responds with the following information:
Type as provision update, the same session id that activate assigned in the first response, status as success or failure, mode as conductor, and the list of managed devices with the allowlist db that contains <MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address>,<Serial number>,<Model>,<Mode>,<Hostname>, and <Config group>.
2. Managed device contacting activate and retrieving the provisioning rule
The following steps are involved to retrieve the provision rule:
a. Navigate to the device list and select a device that you want to designate as Mobility Conductor.
b. Edit the selected device and set its mode to Conductor.
c. Go to setup and create a folder with the managed device_to_Conductor rule.
d. Populate the rule with the following information:
Select conductor device.
Specify IP address of the conductor.
Specify country code for managed device that will be in this folder.
Specify configuration group for managed device that will be in this folder.
|
|
A folder can contain only one type of managed device that have the same country code and map to the same configuration group. Different folders need to be created for each such group, if the country code or mapping to the configuration changes. |
e. Again, navigate to the device list and select a device that you intend to designate as managed device.
f. Edit the selected device and set its name to the desired hostname. If the name is not set, it will be autogenerated.
g. Move the selected managed device to the folder created in step c.
When a factory-default controller boots, it starts the auto-provisioning process. The following sections describe the provisioning workflow, and the process to prepare your network for ZTP Zero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. using DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. for a managed device.
The managed device can get the information required for provisioning from a DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. server instead of Activate. Using DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. helps the ZTP Zero Touch Provisioning. ZTP is a device provisioning mechanism that allows automatic and quick provisioning of devices with a minimal or at times no manual intervention. controllers get conductorinformation when the users are unable to use Activate. Option 43 of DHCP Dynamic Host Configuration Protocol. A network protocol that enables a server to automatically assign an IP address to an IP-enabled device from a defined range of numbers configured for a given network. can be used for broadcasting the conductor information to the managed devices.
This feature supports the following topologies:
VMM with VPNC
HMM with VPNC
HMM without VPNC
|
|
VPNC must be a hardware controller and not a virtual machine. |
This feature also supports L2 and L3 Mobility Conductor redundancy scenarios, where the managed device can get primary Mobility Conductor and standby Mobility Conductor (L2 or L3 standby conductor) information.
In VPNC scenarios, the managed devices can get primary Mobility Conductor information, standby Mobility Conductor, Primary VPNC and standby VPNC information.
Option 43 contains the following information to help provision a managed device:
Conductor IP
VPNC IP
Primary Conductor MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network.
Redundant Conductor MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network.
Redundant VPNC MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network.
Country Code
Option 43 contains the following information:
conductorip, country-code, conductor-mac1 (No L2 redundant Conductor)
conductorip, country-code, conductor-mac1, conductor-mac2 (L2 Redundant Conductor)
conductorip, country-code, vpnc ip, vpnc-mac1 (No L2 Redundant VPNC)
conductorip, country-code, vpnc ip, vpnc-mac1, vpnc-mac2 (L2 Redundant VPNC)