Zero-Touch Provisioning: 50 routers deployed in one day
One of our clients—a vending machine operator with 50 locations in the Île-de-France region—needed to deploy Eziwan gateways across its entire network in a single day. Without a network technician at each location. Without training the point-of-sale managers. Without manual configuration.
Result: 47 active routers in 1 hour and 52 minutes; the last 3 became active the next morning after delayed reception.
Here's exactly how Eziwan's Zero-Touch Provisioning works.
The Problem with Traditional Deployment
Without ZTP, deploying 50 routers looks like this:
- Order the routers (D+2)
- Receive them and configure them one by one: APN, VPN, MQTT, DNS → 2–3 hours per router
- Label, pack, and ship to each site
- Coordinate with each site manager for installation
- Test the connection site by site
For 50 sites, we're looking at 3–4 weeks of work and often several field trips for debugging.
Zero-Touch Provisioning: How It Works
Eziwan ZTP is based on a simple principle: the provisioning token.
Step 1: Generating tokens in Eziwan
From the dashboard, you create a "deployment profile" that contains:
- The VPN configuration (OpenVPN or IPSec)
- MQTT configuration (broker, topics, QoS)
- RS485 configuration, if applicable
- Network settings (APN, DNS, NTP)
- Alerts and thresholds to be configured
You then generate a unique token for each router. Each token is:
- Single-use (one router = one token)
- Valid for 72 hours (security)
- Linked to a configuration profile
Eziwan Dashboard → Fleet → New Deployment
↓ Select the "Distrib-Auto-IDF-v2" profile
↓ Generate 50 tokens
↓ Export CSV with serial number, token, and address
Step 2: Factory Preconfiguration
The routers you receive already have the token embedded in the firmware. You don't need to do anything.
If you want to ensure that the on-site operator doesn't even have to scan a QR code, you can also pre-configure the token when placing your order—that's what our vending machine client does.
Step 3: On-site Installation (< 5 minutes)
The store manager receives the router along with clear instructions:
- Take the router out of the box
- Plug in the power cord
- Screw on the LTE antenna
- Wait for the green light to flash
That's it. The manager doesn't need to understand what an APN, a VPN, or an MQTT broker is.
What Happens Automatically
[00:00] Alimentation ON
[00:08] Boot OpenWRT
[00:15] Searching for an LTE network — Orange SIM1 detected
[00:28] Connexion LTE Cat6 — APN: eziwan.private — IP: 10.24.x.x
[00:35] HTTPS request to the Eziwan cloud: token validation
[00:38] ✓ Token np_ztp_8xK2mQ... validated — "Distrib-Auto-IDF-v2" profile received
[00:45] Application configuration VPN OpenVPN/IPSec...
[00:52] OpenVPN tunnel established — latency: 18 ms
[01:02] MQTT Configuration Applied — Broker Connection ✓
[01:18] Internal connectivity tests ✓
[01:47] ✓ Router registered in the dashboard — status: ONLINE
Total time: 1 minute 47 seconds.
The token is marked as used in Eziwan, and the router appears in your fleet with its address and status.
The dashboard at the time of deployment
During the two hours of our client's deployment, here's what they saw in Eziwan:
Déploiement #2025-03-05-IDF
────────────────────────────────
Tokens generated: 50
Active: 47 ● ONLINE
En attente : 3 ○ PENDING
Expired tokens: 0
────────────────────────────────
Last activated: DISTRIB-MARNE-049 2:52:18 PM
Total deployment time: 1 hr 52 min
Every router that comes online sends a notification (email or webhook). Our client set up a webhook to Slack—their technical team could see the routers coming online one after another in real time.
The 3 Routers That Are Behind Schedule
The three routers that were not activated on D-Day all had the same reason: the store manager was absent. They were activated the next morning, as soon as the stores opened.
No technician visits. No network interventions. No debugging.
Replacing a Faulty Router
ZTP also works for replacement. If a router fails:
- Order a replacement from Eziwan (router delivered in 2 business days with a pre-programmed token)
- Send the package directly to the site (or have the delivery person leave it there)
- The on-site technician unplugs the old router and plugs in the new one
- Eziwan automatically applies the old router’s configuration to the new one
The entire replacement process takes < 5 minutes on-site, with no technical expertise required.
ZTP Security: How the Process Withstands Attacks
ZTP is sometimes seen as a security risk: "If the router configures itself automatically over the Internet, could someone intercept it?" The short answer is no—here's why.
ZTP Eziwan Chain of Trust
1. The ZTP token is generated from your Eziwan dashboard (MFA-authenticated account)
2. The token is sent to the router from the factory via a secure channel (not by email)
3. The router starts up and contacts cloud.eziwan.com using HTTPS with TLS 1.3
4. The server validates: Is the token correct? Has it expired? Has it already been used?
5. The configuration is encrypted (AES-256) before transmission
6. Once activated, the token is invalidated—it cannot be used even if it is captured
7. Post-activation authentication now uses X.509 certificates (no longer tokens)
What an attacker who intercepts a ZTP token could do: retrieve the router's configuration profile (MQTT settings, APN) — no access to data from existing sites, no access to VPN tunnels from other sites. The token grants access to nothing more than the initial bootstrap of a router.
What it cannot do: activate a router that is already active, access sites that have already been deployed, or obtain VPN keys from other clients.
Certificate Rotation After ZTP
After ZTP activation, the router generates its own key pair (RSA 4096 or ECC P-256) and requests a certificate signed by the Eziwan CA. This certificate is valid for 2 years and is automatically renewed 30 days before expiration—without human intervention and without a new ZTP token.
ZTP for Subcontractors and Integrators
ZTP takes on a whole new dimension when you're an industrial integrator managing deployments for multiple clients.
Multi-tenant: Separating Customer Bases
Eziwan allows you to create isolated customer spaces (organizations) within the same instance. Each end customer has its own space with its own ZTP tokens, its own access rights, and its own data—without ever seeing other customers' data.
The integrator has an aggregated view of all its customers, with separate permissions:
| Access Level | What the Integrator Sees | What the End Customer Sees |
|---|---|---|
| Integrator Admin | All sites for all clients | Only their own sites |
| Account Manager | Sites for a specific client | Only their own sites |
| Field Technician | Sites in their area | Not applicable |
Deployment Process for an Integrator
1. Client signs the contract → Integrator creates the client organization in Eziwan
2. The integrator configures the deployment profiles for this client
3. Order of 50 routers → Eziwan pre-flashes them with the tokens
4. Direct shipment to the end customer (without going through the integrator's warehouse)
5. The customer's local technicians install the routers (5 min per site)
6. The integrator monitors the activation from their dashboard
7. Full validation → Handover of the project to the end client, if desired
This process enables a team of five integrators to manage deployments at 200 or more geographically dispersed sites simultaneously, without ever having to send a technician for the initial configuration.
What Is Not Included in the ZTP
ZTP handles the initial configuration, but not everything:
- Hardware failures: always require on-site intervention (power supply, cables)
- Network coverage: if LTE is below -110 dBm at the site, an external antenna is required
- Highly specific configurations: complex VLANs, multi-WAN — these can be configured via the dashboard after activation
Frequently Asked Questions
Is ZTP secure? What happens if a token is intercepted? Each token is single-use and valid for 72 hours. Even if a token were intercepted, it would only allow the recipient to receive a configuration profile—not to access data from existing sites. The received profile is encrypted in transit (HTTPS TLS 1.3). After activation, the token is marked as used and cannot be reused. The router then authenticates itself using an X.509 certificate.
Can the configuration received by the router during ZTP be customized? Yes. The configuration profile in Eziwan is fully customizable: carrier APN, VPN configuration (OpenVPN or IPSec), MQTT settings, RS485/Modbus configuration, alerts, and firewall policies. Once the profile is defined, all routers using that profile receive exactly the same configuration. Profiles can be versioned and migrated.
What happens if the router does not contact the ZTP server within 72 hours? The token expires, and the router remains in the "unconfigured" state (it can connect to the Internet, but no VPN tunnel or MQTT configuration is active). Simply generate a new token in the Eziwan dashboard and associate it with the router—there’s no need to resend anything or physically access the router.
Does ZTP work if the site doesn't have a reliable connection during the first boot? The router attempts to contact the ZTP server at startup and repeats these attempts for 72 hours. If LTE coverage is insufficient during the first startup (antenna not screwed in, poor coverage area), properly attaching the antenna and restarting the router will restart the procedure.
Can ZTP be used on third-party (non-Eziwan) routers? Native ZTP functionality is specific to the Eziwan Gateway. For third-party devices, Eziwan offers a provisioning API that can be integrated with solutions such as NETCONF/YANG or TR-069, provided the third-party hardware supports them. Please contact our team for specific use cases.
How do I manage firmware updates via ZTP? Firmware updates are not part of the initial ZTP deployment—they are managed separately from the Eziwan dashboard (OTA updates, scheduling outside of production hours, automatic rollback in case of failure). ZTP only configures network settings, VPNs, protocols, and alerts.
Further Reading
- Guide: Industrial 4G LTE Router — Migrating from ADSL
- Guide: Choosing an Industrial 4G Router in 2026
- Docs: Eziwan Fleet Management
- Blog: Secure Remote Access for PLCs and SCADA
Do you manage a network of sites that need to be equipped? Contact us for a ZTP POC — we'll help you deploy the first routers for free.
Additional Resources
- Mass ZTP Deployment Guide — large-scale automatic provisioning
- Eziwan Gateway — the industrial gateway compatible with Zero-Touch Provisioning
- Industrial Routers — devices ready for ZTP and OTA management
- Router Fleet Management Guide — centralized monitoring after deployment