Versa Device Activation and Zero Touch Provisioning (ZTP)


Configuring and Activating the Versa Device

Versa SD_WAN provides you multiple options to activate Branch CPEs across customer deployments sites. Use any of these options to address your use case scenario:


Global-Activation Zero Touch Provisioning (ZTP) 

This section covers:


Global Activation ZTP

Versa device activation or ZTP lets you connect the branch device to the network and power it on. The default configuration is added as part of the Versa FlexVNF software installation. After switching on and establishing an internet connection, the device calls home to a cloud hosted Versa-Staging controller. This staging-controller redirects the branch-device to the Staging-Controller hosted by the provider (Service-Provider or Enterprise).


The CPE device follows these stages:

  1. Versa Pre-Staging—Based on input from the distributor, an entry is created in the inventory for each device using the device serial number. The FQDN or IP-address of the provider’s Staging Controller is added to the device. The CPE device connects to the Versa Staging Controller and is redirected to the provider’s Staging Controller.

  2. Provider Pre-Staging—The provider claims the device and prompts for a 2-factor authentication and redirects the branch-device to the Staging controller. You can skip this stage if the distributor has knowledge of the provider’s Post-Staging Controller. 

  3. Provider Staging and Post-Staging—If you skip step 2, then functions like claiming the device is done here. The providers can onboard Customer’s (Tenants) here. IKE comes upon provider and customer tenants.

The branch device reboots at the end of each step before moving on to the next step.



                                    Figure 1: Global-Activation Zero Touch Provisioning


Refer Figure 2 Versa Device Activation Call Flow for more information about the device activation call flow. The device goes through the Versa Pre-Staging and Provider Post-Staging phases. As mentioned, you can skip the provider’s Pre-staging to avoid an additional reboot.


                                                                                                    Figure 2:  Versa Device Activation Call Flow


 In the Provider-Staging stage, use either PSK or PKI to authenticate the branch device. Figure 2 illustrates how to authenticate using PKI.

Refer to Instructions to onboard branches for Global-Activation for additional information to provision the branch device on the Versa Staging Director.


Instructions to Onboard Branches for Global-Activation

This section provides information about onboarding the branch-device using the Versa Director.


Onboarding the Branch-Device Using Versa Director

Follow these instructions to Onboard the branch-device using Versa Director:

  1. Login to the Cloud-Hosted Versa-Director.

  2. A Versa-Public Controller is created for branches to connect. The branch-device’s factory-default configuration automatically (once the device has internet connectivity) connect to this controller. It uses PKI to authenticate and sets up an IKE based IPSec tunnel.

  3. Use any of these pre-created templates to help associated bind-data with on boarding the branch-devices.

    • Versa-PreStaging—Use this when the device has to go through another Pre-Staging Controller. Bind-data includes Global-tenant-Id, Pre-Staging-Controllers PSK Auth Parameters, and Pre-Staging-Controller’s IP-Addresses.

    • Versa-Staging—Use this when the device has to go directly to Post-Staging Controller and the IP-Address of the controller is known. Bind-data includes Global-Tenant-Id, Staging-Controllers PSK Auth Parameters, and Staging-Controller’s IP-Addresses.
      File:Notes edit.svg You can modify the Versa-PreStaging, Versa-Staging and Versa-Staging-FQDN templates per provider. Create a different device-group and associate the template with it.
      For example, a provider can use a different local auth parameter for all its branches instead of using the default or use a separate local auth parameter per branch.

    • Versa-Staging-FQDN—Use this when the device needs to go directly to Post-Staging Controller and the FQDN of the controller is known. This is the most common use-case. Bind data includes Global-Tenant-Id, Staging-Controllers PSK Auth Parameters, Staging-Controller’s FQDNs.

    • Versa-Dummy-PostStaging—Placeholder since devices will not be attempting PostStaging with this Controller/Director.

                   

  1. These Device-Groups are pre-created to help on board the branch-devices.

    • Versa-PreStaging-DG—If the device needs to go through another Pre-Staging Controller.

    • Versa-Staging-DG—If the device needs to go directly to Post-Staging Controller and the IP-Address of the controller is known.

    • Versa-Staging-FQDN-DG—If the device needs to go directly to Post-Staging Controller and the FQDN of the controller is known. This is the most common use-case.

                   


                 The templates are associated with the device groups. As an example, the Versa-Staging-DG device group is shown.


                 


  1. Use Workflows to onboard the device. The manufacturer provides Versa with a list of chassis-ids shipped to a provider.

         File:Notes edit.svgUse the serial number of the box as the devices chassis-id.


        


  1. Versa will contact the provider and get the Staging-Controller information along with the tunnel auth parameters.

           File:Notes edit.svg This is a one-time activity that happens before any device is shipped or provisioned.

 

  1. Continue to enter the Location-Information and Bind-Data of the Staging-Controller.


         

        File:Notes edit.svg You have to configure all the fields in this window.

 

         Refer to this table to configure the Bind data user inputs:

Field

Description

Versa-Provider_Peer_WAN1_IP

This is the controllers WAN IP address.

Versa-Provider_Global_Tenant_Id

This is the tenants ID used for identifying a tenant.

Versa-Provider_Peer_Auth_Key

This is the controller’s authentication key used for authenticating the tunnel between the controller and the branch.

Versa-Provider_Peer_WAN2_IP

This is the controllers WAN IP address.

Versa-Provider_Peer_Auth_Id

This is the controller's ID string used for authenticating the tunnel between the controller and the branch.

  1. Once deployed, the Versa-Director’s Tasks confirms the successful deployed of the device.

 

Identifying Branch-Device on Versa-Public CA 

Follow these steps to identify the brach-device on Versa-Public CA:

  1. The branch-device by default will try to fetch certificates from the Cloud-Hosted Versa-Certificate-Authority. In the current release, an End-Entity entry should be added in the CA for issuing the certificate. In the next release, a CA connector will be added in the Versa-Director which will automatically create an entry in the CA as part of onboarding a device. 

  2. Login to the Versa-CA. A browser certificate is required for logging in.

         

          Refer to the Google's website for information on adding a certificate to the Chrome web-browser.

  1. Add an end-entity using the VersaPublicEE profile. It is important to note that the Username and Common Name should be same.

         

  1. The summary of the added users can be seen using the Search End Entities Option. The status of the device will show:

    • New—If the certificate has not been issued yet.

    • Generated—If the device connected and fetched a certificate.

    • Revoked—If the CA revoked certificate (an already issued certificate) for this device.


                     File:Notes edit.svg Click Edit to change the state of an entity from Generated to New to change the status of the device. Do this only when you want to re-provision the device again.

 

  1. For device activation, the ports are preconfigured. Once, the device is activated, the next-stage configuration can change the port assignment. The WAN port on the branch device needs to be plugged to the internet to connect to the Versa-Director. 

         

  1. The device will try to fetch the certificate from the Versa-CA. The CA should show that it has issued a certificate.

         

 

         File:Notes edit.svgRefer to Step 6 Activating Versa Device in URL Based Zero-Touch Provisioning (URL-ZTP) for two-factor authentication.

 

  1. The device will setup IKE based tunnel with the Versa-Public Controller. The controller will notify the Versa-Director of the new device and based on the bind-data, new configuration will be pushed to the device.

         


Debugging Failures on the Branch-Device Web-UI

  1. If there are failures, the installer can connect a laptop to the LAN port of the device and troubleshoot the failure. The laptop should receive an address in the 192.168.0.x/24 from the DHCP server running on the LAN interface.

  2. On the laptop, open a browser and type http://192.168.1.1:80

  3. Login with the provided default credentials and click on the Activation tab. Hit “Activate” button.


          The activation process will:

           For example, if the connectivity test passed and certificate fetching failed, the “View failure” will show up. Clicking on it will pop-up the failure statistics.

         



URL Based Zero-Touch Provisioning (URL-ZTP) 

This section covers:


URL ZTP

In addition to Zero-Touch Provisioning described above, Versa supports site administrator assisted URL based Zero-Touch Provisioning. These are the two advantages of this feature:

  1. Decouple a particular hardware (chassis-id) from a branch location i.e. bootstrap any hardware running an appropriate Versa FlexVNF software.

  2. Allow device activation directly to Post-Staging Controller i.e. it can choose to go through the staging process and skip the pre-staging process (Versa Pre-Staging and Provider Pre-Staging).

In this approach, a URL is created to bootstrap the device when it on-boards. This URL is sent to northbound AMQP server. You can also access this URL from the Versa Director using REST APIs. 

The onsite installer can connect their laptop to the LAN port on the Versa branch-device to access the internet and check the email sent from the administrator managing the Versa Director to access the URL. Versa device runs a DHCP Server on the LAN port on the factory default device.

File:Notes edit.svg URL based ZTP supports on both bare metal and virtual environment.


Adding a URL ZTP for a New Device Group

You can create device groups to logically group devices based on their location and type. Creating groups help in defining policies for the group. Follow these steps to add a new device group with URL ZTP configured for it. 

  1. Select the Director Context > Workflow tab > Add Device to configure URL ZTP per device-group.

  2. Enter these details in the Add Device window:

Use this field…

to …

Basic Tab

Name

Enter the name of the device that you want to add to the organization and to the device group.

Global Device ID

The system auto-generates the value with the next available ID.  

Organization

Select an NMS organization from the Versa Director. 

Serial Number

Click Generate Serial Number to auto generate and auto populate the chassis/device ID.

File:Notes edit.svgThe Generate Serial Number button appears only when you select ZTP enabled Device Group.

 

Device Groups

Select a ZTP enabled device group and associate the device to it.

 

  1. Click +Device Group to configure the URL based ZTP to the group. This opens the Create Device Group window.


         

  1. Enter these details in the Create Device Group window:

Use this field…

to …

Name

Enter the name of the device that you want to add to the organization and to the device group.

Description

Enter a brief description of the device group and its purpose.

Tags

Enter a tag to identify the device group.

Organization

Select an NMS organization from the Versa Director for this device group.

Enable Two Factor Auth

Select this to enable two-factor authentication. This enables the email and phone field in the Contact Information panel. A red asterisk appears over these two  fields.

You get notified via an email when a branch performs Zero Touch Provisioning ( ZTP). You have to click the authentication mail to allow URL based ZTP.

Staging Template

Select a staging template for the device.

Post Staging Template

Select the post staging template for the device.

General

Select this template when using vCPE devices.

Contact Information

This information is used for Two Factor Auth.

  • Enter the email ID for the device group. You get notified via an email when a branch performs Zero Touch Provisioning ( ZTP). You have to click the authentication mail to allow URL based ZTP.

  • Enter the phone number for the device group. This is used to receive One Time Password (OTP).

URL Based ZTP tab

URL Based ZTP

Select this to enable the URL Based ZTP for the device group.

  • Pre Staging—Select this to configure URL ZTP at pre-staging state.

  • Staging—Select this to configure URL ZTP at staging state.

  • Controller—Select a controller for which URL ZTP is applied.

  • VPN Profile—Select this to setup the IPSec VPN tunnel with the controller.

5. Click OK to add a device group with URL ZTP configured on it.


Enabling URL Based ZTP on an Existing Device-Group

You can also configure URL based ZTP on an existing device group. Follow these steps to enable URL ZTP per device-group:

  1. Select the Director Context > Administration tab > SDWAN > Device Groups and select an existing device group on to configure the URL based ZTP. This opens the Edit Device Group window.


  2. Select a Staging Template or Post Staging Template for the device.
  3. Select the URL Based ZTP tab in the Edit Device Group window and enter these details: 


Use this field…

to …

URL Based ZTP Tab

URL Based ZTP

Select this to enable the URL Based ZTP for the device group.

  • Pre Staging—Select this to configure URL ZTP at pre staging state.

  • Staging—Select this to configure URL ZTP at staging state.

  • Controller—Select a controller for which URL ZTP is applied.

  • VPN Profile—Select this to setup the IPSec VPN tunnel with the controller.

  1. Click OK to save the changes and enable URL based ZTP on an existing device group.


Onboarding and Deploying Versa Devices

Versa Director provides workflows to onboard devices. Follow this workflow to onboard a device:

  1. Select Director Context > Workflow tab > Deploy Controller to add a controller. Refer to Onboarding Controllers in the Versa Software Defined WAN Configuration Guide for more information.

  2. Select Workflow tab > Create Organization to add and associate an organization with the controller.  Refer to Onboarding Organizations in the Versa Software Defined WAN Configuration Guide for more information.

  3. Select Workflow tab > Create Template to provision a staging and post staging template and associate it with a branch group.  Refer to Creating Templates in the Versa Software Defined WAN Configuration Guide for more information.

  4. Select Workflow tab > Add Device to onboarding a branch device. Enter all the associated parameters for each branch device. Refer to Onboarding Devices in the Versa Software Defined WAN Configuration Guide for more information.
    For URL based ZTP:

    • Select the + Device Group from the Add Device window.

    • Select the Basic tab and generate a serial number for the device that is associated with a ZTP enabled device group.

    • Click the +Device Group to open the Create Device Group window.

      • Select URL Based ZTP tab and:

      • Select the URL Based ZTP checkbox to enable URL Based ZTP for the device.

      • Select either Pre Staging or Post Staging option for using URL based ZTP.

      • Select the Controller to which this device belongs.

      • Select the VPN Profile to associate with the controller for IPSec authentication.

    • Select Location Information tab and enter the location related details and coordinates.

    • Select Bind Data tab and enter the device IP address and other related details. 

    • Select the URL Based ZTP to check the auto-populated URL ZTP information.



    • Click Deploy to onboard and deploy the device.

Editing URL ZTP Parameters

After deployment, the CPE device is available in the Inventory. Follow these steps to edit the URL ZTP parameters:

  1. Select Administration > Inventory > Hardware and select the CPE device to further customize the URL based parameters.


     

  1. Make the changes in the Edit Hardware window.

  2. Click OK to save the configuration.


Accessing the URL to Activate a Versa Device

Use one of these options to access the URL:

  1. From the AMQP server configured on the Versa Director. The URL is posted to the AMQP server post the device onboarding and deployment.

  2. Query the URL using Restful API.  For example,

http://x.x.x.x:9182/vnms/sdwan/device-url-mappings/device-url-mapping/Branch2

  1. Copy the URL from Administrator > Inventory > Hardware window. 

    • Select a Branch and click the highlighted option as shown in this image.


                   



Activating Versa Device


The site administrator selects any CPE device that is running on the Versa FlexVNF and prepares it for deployment. 

The site administrator has to follow these steps to activate the Versa device:

  1. Connect their laptop to the LAN port on the Versa branch device to bootstrap the device.

  2. Enter http://192.168.1.1:80 in the web browser to access the default login page. The device has a DHCP and Web Server running on 192.168.1.1.

File:Notes edit.svgVersa recommends you to use Chrome (version 36 and above) to access the Device Management page.


         

Use these credentials to login to the device management window:

  1. Connect the WAN port to the internet to access the email and get the the URL to bootstrap the device.

           


4. Click on the URL in the email or paste the URL in the web browser and initiate the device activation process.

       

5. Click Activate to start the ZTP configuration on the device.
    The device then:

 

6. (Optional) Claim your device If you have enabled two factor authentication. Follow these steps to claim your device:

         

 

7. The device reboots on completion of ZTP.

       

8. Verify the device activation status on Versa Director.
Versa Appliance UI allows you to program static IP addresses and DNS servers using the URL. YOU can also manually configure the address and DNS servers from the Configuration tab.

       




Debugging Instructions for Site Administrators to Start Using the URL Based ZTP


Follow these instructions to use URL Based ZTP:

  1. Port 1 is eth0.

  2. On Port 2, allocate a WAN IP. It will be empty if not connected.

  3. Also, note that the default gateway in the global routing instance should be via the WAN port.

  4. On Port 3, the LAN IP is received via DHCP. Use http://192.168.1.1:80  to access the device or directly use the generated URL.

  5. Paste the URL in the browser to get started with the bootstrap process.

  6. Once done you can monitor progress on the Versa-Director.


Debugging Instructions for SEs to Demo and Test the URL Based ZTP

Follow these instructions to use demonstrate and test URL Based ZTP:

  1. Install new .bin file. This is not required on a newly shipped device.

  2. Run the /opt/versa/scripts/versadevice-factoryreset.sh file on the branch device to install the factory default configuration. This allows the laptop that you connect to the branch device to access internet.This is not required on a newly shipped device.

  3. Run the show interfaces brief CLI command.

admin connected from 10.0.0.27 using ssh on versa-flexvnf
admin@versa-flexvnf-cli> show interfaces brief
NAME       MAC            OPER  ADMIN  TENANT  VRF IP
---------------------------------------------------------------------------
eth-0/0    00:90:0b:43:10:42  upup     0   global
vni-0/0    00:90:0b:43:10:43  upup     -   -
vni-0/0.0  00:90:0b:43:10:43  upup     1   global  10.0.0.23/16
vni-0/1    00:90:0b:43:10:44  upup     -   -
vni-0/1.0  00:90:0b:43:10:44  upup     1   global  192.168.1.1/24
 [ok][2016-08-19 14:50:55]
  1. Continue with steps provided in the previous section to start using the URL based ZTP.


Web Portal Based Auto-Provisioning

Versa provides a Manual Form where the onsite installer can fill in the required parameters and provision the branch device. 

These parameters are available in the manual form:

The user experience with this activation process is similar to the previously described ZTP activation methods.

File:Notes edit.svgRefer to Step 6 Activating Versa Device in URL Based Zero-Touch Provisioning (URL-ZTP) for two factor authentication.



CLI Based Auto-Provisioning 

This section covers:


Onboarding Versa Devices

Versa Director provides workflows to onboard devices. Follow this workflow to onboard a device: 

  1. Select Director Context > Workflow tab > Deploy Controller to add a controller. Refer to Onboarding Controllers in the Versa Software Defined WAN Configuration Guide for more information.

  2. Select Workflow tab > Create Organization to add and associate an organization with the controller.  Refer to Onboarding Organizations in the Versa Software Defined WAN Configuration Guide for more information.

  3. Select Workflow tab > Create Template to provision a staging and post staging template and associate it with a branch group.  Refer to Creating Templates in the Versa Software Defined WAN Configuration Guide for more information.

  4. Select Workflow tab > Add Device to onboarding a branch device. Enter all the associated parameters for each branch device. Refer to Onboarding Devices in the Versa Software Defined WAN Configuration Guide for more information.
    Once, the workflow has progressed to the last stage, the administrator can start onboarding branch devices, create device groups.  


Preparing a Branch Configuration 

Use this configuration to prepare the branch:

admin@VNF:/$ sudo /opt/versa/scripts/staging.py -h
[sudo] password for admin:
usage: staging.py [-h] [-l LOCAL_ID] [-r REMOTE_ID] [-c CONTROLLER]
[-t {staging,prestaging}] [-d] [-w {0,1,2,3}] [-v VLAN]
[-s STATIC] [-g GATEWAY]
Setup branch staging config
optional arguments:
-h, --help        show this help message and exit
-l LOCAL_ID, --local-id LOCAL_ID
Local id-string/email
-r REMOTE_ID, --remote-id REMOTE_ID
Remote id-string/email
-c CONTROLLER, --controller CONTROLLER
Controller IP address (x.x.x.x)
-t {staging,prestaging}, --staging {staging,prestaging}
Staging type (default=staging)
-d, --dhcp        Use DHCP for WAN link
-w {0,1,2,3}, --wan-port {0,1,2,3}
   WAN port number
-v VLAN, --vlan VLAN  VLAN id
-s STATIC, --static STATIC
Static IP/mask for WAN link (x.x.x.x/y)
-g GATEWAY, --gateway GATEWAY
Default gateway IP address (x.x.x.x)


Sample Script with Arguments


To use this sample script:

  1. Run the sudo /opt/versa/scripts/staging.py -l branch104@nms-org.com -r controller@nms-org.com -c 10.10.10.10 -t prestaging -w 0 -s 10.10.10.20/24 -g 10.10.10.10 script to onboard the branch-device.

File:Notes edit.svgRefer to Step 6 Activating Versa Device in URL Based Zero-Touch Provisioning (URL-ZTP) for two factor authentication.

  1. Check the Tasks window in the Versa Director to verify successful deployment of the device.

     



Security Considerations

These security considerations were considered for device bootstrapping:

  1. The URL that is published is encrypted to avoid exposing the parameters that are required for configuring the branch device to initiate the bootstrapping.

  2. Communication to the Staging-Controller is over IKE/IPSec. Each branch-device must authenticate with the Staging-Controller before completing the IKE. Use one of these to authenticate IKE:

    • Pre-Shared Key (PSK)—The local-auth and peer-auth parameters are sent via the URL.  The parameters are not exposed because the URL is encrypted.

    • Public-Key Infrastructure(PKI)—Each device has a Versa-CA signed certificate. You can issue a Versa-CA signed certificate to the staging controller.
      The controller runs Online Certificate Status Protocol (OCSP) to ensure that the branch issues a valid certificate. You can revoke the certificate, if the branch is stolen, to prevent the branch from connecting to the controller.
       For subsequent IKE connections after staging the device, the provider can switch to its own CA-signed certificates.

             In addition, the private key is never exposed in memory. It is protected by a TPM chip.

  1. The staging process in itself does not last beyond a few minutes. IKE/IPSec rekey are not necessary. However, after staging the device, IKE/IPSec re-keys for control and data path connections. The rekey interval is configurable.

  2. During staging, once the Versa Director is notified, a 2-factor authentication process ensures that the administrator permits the device to be staged.

  3. You can add the device to device blacklist to prevent a rogue device from connecting to the controller. At any point, you can disconnect a rogue device from the network.