Cisco Catalyst Zero-Touch Field Activation
Cisco Catalyst 9000 Zero Touch Provisioning can bootstrap an unconfigured switch using DHCP and a referenced script or configuration path. Successful field activation depends on factory-default state, DHCP options, routing, name and time services, reachable resources, trusted artifacts and a technician prepared to stop or recover the process.
Make each dispatch repeatable and recoverable
Define prerequisites, remote ownership, method of procedure, acceptance evidence and rollback before technicians arrive onsite.
ZTP workflow and site prerequisite validation
Confirm whether the project uses IOS XE ZTP, Catalyst Center Plug and Play or another approved automation path; these are not interchangeable workflows. Reconcile serial, model, modules, software, stack plan and site profile with the automation inventory.
Validate DHCP, option values, gateway, DNS, NTP, firewall and bootstrap server reachability in the staging network. Protect scripts and configurations and verify integrity and change approval. Define what the technician should see and when to stop.
The remote team should supply the site identifier, approved design, equipment list, configuration status, contacts, access window and success criteria. The field technician verifies serials, labels, damage, accessories and prerequisites before changing production service.
- Correct automation method
- Serial/model/site mapping
- DHCP and service reachability
- Approved artifacts and integrity
Physical installation and controlled bootstrap
Rack, power, stack and label the switch, then connect only the designated bootstrap uplink and console according to the method. Confirm factory-default or intended startup state before initiating. Avoid attaching production access ports until the correct site configuration is verified.
Observe DHCP, download, script execution, reloads and controller or management registration. Record timestamps and messages. If the device loops, downloads the wrong profile or loses reachability, stop and use the approved recovery rather than repeatedly erasing it.
Use a written method of procedure with hold points for configuration-sensitive actions. Photograph and label the before state, preserve known-good cabling or configuration, and keep a practical rollback path. Record deviations as they occur instead of reconstructing them after the visit.
- Console and fallback ready
- Bootstrap-only uplink first
- Observed downloads/reloads
- Stop conditions defined
| Phase | Observe | Stop or escalate when |
|---|---|---|
| Discovery | DHCP and bootstrap URL | Wrong scope or artifact |
| Execution | Script/config and reloads | Loop, errors or lost access |
| Validation | Site profile and services | Partial or incorrect configuration |
| Handoff | Inventory and source of truth | Ownership remains unclear |
Configuration, software and service acceptance
Verify hostname, management, AAA, certificates, NTP, software, license, VLANs, trunks, spanning tree, routing, telemetry and intended template. Compare the running result with the site source of truth and check for rejected commands or partial automation.
Connect and test access-port groups only after the baseline passes. Validate PoE, voice, wireless, security and representative clients. Exercise approved uplink or stack recovery when applicable and confirm automation will not overwrite authorized local exceptions unexpectedly.
Validation must cover physical status, management visibility, addressing, uplinks, power, policies and representative user traffic. When redundancy is expected, test the approved failure and restoration scenarios. Escalations should include timestamps, identifiers and reproducible evidence.
- Template/config comparison
- AAA/cert/time/software
- Ports, PoE and endpoints
- Automation exception behavior
Evidence, exception and lifecycle handoff
Deliver serial, site/profile, bootstrap service, timestamps, software, configuration comparison, port tests, logs, exceptions and recovery actions. Remove temporary bootstrap access and credentials according to the security plan.
Operations must own the automation source, certificates, images, DHCP options, templates, inventory and change process. Keep private artifacts in the client repository and link publicly only to official Cisco documentation.
Closeout combines annotated photographs, serials, port and cable records, software versions, test output, exceptions and ownership. Credentials and private configurations belong in the client-controlled repository, while public pages should point only to official manufacturer support resources.
- Activation evidence
- Temporary access removed
- Source-of-truth ownership
- Protected scripts/configuration
How we plan and deliver the work
The final design depends on site conditions, existing systems, client policies and the selected manufacturer or platform.
Prepare
Confirm access, equipment, remote readiness and rollback.
Execute
Install through the approved method and document deviations.
Test
Validate management, service, resilience and user workflows.
Close
Deliver evidence, inventory, exceptions and support ownership.
Information to gather before design
Good decisions are easier when the project team starts with complete operational and technical information. The following items help reduce assumptions, change orders and avoidable return visits.
- Site access and remote contacts
- Staging, inventory and prerequisites
- Method, maintenance window and rollback
- Acceptance tests and escalation
- Evidence and operational ownership
Frequently asked questions
These are common planning questions. A site-specific answer should be confirmed during discovery and design.
Is Cisco ZTP the same as Catalyst Center Plug and Play?
No. Confirm the exact automation architecture and prerequisites used by the client.
Must the switch be factory default?
The required startup state depends on the workflow, but conflicting saved configuration can prevent the intended bootstrap.
Why keep console access if the process is zero touch?
Local recovery is essential when DHCP, scripts, software or management reachability fail.
What proves activation succeeded?
Correct site configuration, management, software, ports, PoE, endpoints, logs and source-of-truth reconciliation.
Manufacturer software, firmware and technical files remain on the manufacturer’s official website. We do not mirror firmware files locally.
Build a repeatable field-deployment plan
Provide the site list, target schedule, equipment responsibility, change-window constraints and acceptance criteria. We will help turn them into a practical rollout and closeout workflow.