Network Security

SAIMA CPC 3.5

Reliable, fast, and scalable, it minimizes errors and operating costs

Deploy your network in minutes and gain total visibility 
without technical intervention.

Network Security

SAIMA CPC 3.5

The SAIMA CPC (Centralized Provisioning Controller) application ensures reliable, fast, and scalable network deployment, dramatically minimizing manual errors and operational costs associated with traditional deployment.

02.
Image management (ZTI). Firmware verification, automatic update, restart, and validation.
01.
Detection and registration. DHCP/DNS listening, device identification, initial authentication.
04.
Startup and Monitoring. Configuration application, Connectivity and registration, Auditing and notification.
03.
Configuration provisioning (ZTP). Dynamic configuration generation, secure file delivery.
ZTP&ZTI Integration
Breakdown of SAIMA CPC application processes and tasks
Network Security

SAIMA CPC 3.5

Automated network deployment platform: ZTP & ZTI integration

Our application is a comprehensive software solution designed to fully automate the lifecycle of network device deployment (routers, switches, firewalls, etc.), eliminating the need for manual intervention on site.

This platform combines the concepts of Zero-Touch Provisioning (ZTP) and Zero-Touch Installation (ZTI) to deliver smooth, fast, and error-free software provisioning and installation.

Network Security
Centro de datos con racks iluminados gestionados para reforzar la seguridad de la red empresarial.
Cables conectados a un switch de red empresarial, garantizando conectividad y seguridad de datos.

Get answers to your questions

We have a team ready to help you take the plunge. Join our authorized PARTNERS program.

Are you an end customer and need a PARTNER?

We are waiting for you
Network Security

SAIMA CPC 3.5

Application definition

The SAIMA CPC application, which we informally refer to as CAC "Centralized Provisioning Controller", acts as the orchestrating brain of the day-zero operations process.

Its main purpose is to ensure that a device, when physically connected to the network and powered on for the first time, is automatically configured to the organization's standards and becomes operational without the intervention of a specialized technician at the remote site.

The solution leverages standard network protocols such as DHCP/DNS and file servers (HTTPS) to guide the device from its factory state to a fully functional and secure state, ensuring consistency and scalability in mass deployments.

Network Security

SAIMA CPC 3.5

Conceptual difference in the context of the Application
Although ZTP and ZTI often overlap, our application addresses them as follows.

ZTI 
(Zero-Touch Installation/Imaging)


The application manages the initial phase of installing or updating the device's operating system image (firmware), ensuring that all devices are running the correct and authorized version of the software before applying specific settings.

ZTP 
(Zero-Touch Provisioning)


Once the device has the correct software image, the application orchestrates the download and execution of site-specific configuration files, security policies, authentication credentials, and registration with the central management system (SAIWALL SD-WAN Orchestrator).

Post-provisioning: management that completes the cycle


Beyond ZTI and ZTP, deployment is not complete until the device's subsequent management is ensured. This stage integrates the SAIWALL SR equipment into monitoring, security, and continuous maintenance systems, ensuring active supervision, policy updates, and synchronization with centralized inventory.  

This turns the initial provisioning into a managed lifecycle, ensuring that the device remains operational, secure, and aligned with the SD-WAN infrastructure over time. 

Network Security

SAIMA CPC 3.5

The application manages the following key processes and their associated tasks to ensure successful deployment.

01.
Detection and recording

DHCP Listening

SAIMA CPC application responds to requests from the SAIWALL SR family device in its factory state. SAIWALL requests IP address information via DHCP, and the FTTH router responds. This allows our device to connect to the Internet correctly.

Provisioning

This task provides the address of the provisioning server and, if necessary, can also provide the URL or name of the boot file.

CPC (Centralized Provisioning Controller) connection

This provides us with information from the central server SAIWALL MS and tells us which client it corresponds to. Next, the SR devices connect to the SAIWALL MS (request and information process) and give us the final configuration (templates, settings, etc.).

Device Identification

It uses unique identifiers (MAC Address, serial number) sent by the SR device to identify it in the pre-registration database.

Initial Authentication

Validates the identity of the device to prevent unauthorized access to the provisioning process.

02.
Image management (ZTI) managed by the CPC

Firmware Verification

Check whether the current version of the device's operating system matches the required standard version.

Automatic Update

If necessary, the application orchestrates the download (via HTTPS/SCP) and installation of the correct software image.

Restart and Validation

Manage the device restart after installation and verify that it boots with the new image.

03.
Zero-Touch Provisioning (ZTP) managed by CPC

Dynamic Configuration Generation

It uses templates and site-specific data (IP addresses, VLANs, security policies, SD-WAN parameters) to generate a unique configuration file for the SR device, and does so from SAIWALL SD-WAN Orchestrator.

Secure File Delivery

Facilitates secure download (using HTTPS or other secure protocols) of the final configuration file to the device.

04.
Startup and Monitoring, managed by the CPC

Configuration Application

The device executes the script or applies the downloaded configuration.

Connectivity and Registration

The device connects to the operating network using its new configuration.

05.
Post-Provisioning Management: operational management phase after ZTI/ZTP

Operational management

After ZTI and ZTP, the platform continuously manages the device, integrating it into centralized monitoring and security. The devices automatically update their configuration and firmware using templates, enabling dynamic and unified management of the entire infrastructure and ensuring stable operation aligned with the SD-WAN architecture.