Jump to:navigation, search
Wiki








































Zero-touch profiles for UTMs in the Unified Security Console

Last adaption: 11.2025

New:
notempty
This article refers to a Beta version
-
Access: portal.securepoint.cloud  Unified Security Console  UTM Zero-Touch

Prerequisite

  • The use of a zero-touch profile is only possible from UTM version 14.0.2 onwards.
  • For UTMs purchased directly from Securepoint, the serial number and zero-touch PIN are visible in advance on the invoices in the reseller portal. Further details can be found in the article on Ordering a zero-touch UTM

  • Introduction

    • Zero-Touch allows you to transfer a complete configuration to a UTM, e.g., from a cloud backup, without having to make any entries on the device itself
    • A UTM Zero-Touch profile must first be stored in the Unified Security Console (USC), linked to the serial number and PIN from the start screen, as well as a license and, if necessary, a configuration file
    • The UTM attempts to establish a connection to the portal (assuming a DHCP server is available on LAN1 / A0) and automatically downloads this Zero-Touch profile
    • The UTM restarts with the stored license and, if applicable, the stored configuration, and can be accessed via the USC via a web session
    • The QR code displayed enables our shipping department to transmit the serial number and PIN to a reseller in advance


    Welcome page

    If no zero-touch profile is available, the following welcome page is displayed. This describes the principle of UTM Zero-Touch and the enrollment procedure. More details can be found in the wiki article UTM Zero-Touch.
    Click the  Add Zero-Touch Profile Now button to add a new Zero-Touch profile.



    UTM Zero-touch Dashboard

    The dashboard displays an overview of the UTM Zero-Touch profiles.
    Details can be found under General Options.

    General options

    Name Sorts the tiles by profile name
    Ascending Sorts the tiles in ascending or descending order according to the selected criterion
    Search Filters on profile tiles that contain the search text
     Add profile Creates a new profile. For details, see below.
     Show expired profiles

     Hide expired profiles
    Profiles that have reached their expiration date can be shown or hidden again. These profiles have the label  Expired
    Show/hide details If there are a large number of profiles, it may be helpful to hide the most important details for clarity
    Switch to list view/grid view Switch between list and grid view
    Update Refreshing the display

    Tile options

    The following options are available in the hamburger menu for a zero-touch profile
     Edit Allows you to edit this profile. This can also be done by clicking on the respective profile tile.
    notempty
    Only possible as long as the profile has not yet been applied
     Delete The profile will be deleted.
    Expired profiles only have this option.

    Tile information

     Start date: Date from which the zero-touch profile is valid
     Expiration date: Date on which the zero-touch profile expires
     accessed on: Displays the date and time when this profile was applied
     accessed on: Displays the public IPv4 address of the UTM that retrieved this profile
     Error: If an error occurs, a corresponding error message is displayed. The label  Error applying is displayed on the tile.



    Add zero-touch profile

     Add profile Create a new zero-touch profile
    Caption Value Description
    Name AnyIdeas Name of the profile
    Serial number 1234567890 Unique serial number of the UTM
    Enrollment-PIN A B C D E F G H Enrollment-PIN of the UTM notempty
    The PIN is generated when the UTM is started for the first time after initial or new installation.
    notempty
    The combination of the serial number and PIN must be unique. If a profile with this serial number and PIN already exists, no new profile can be created.
     The serial number and enrollment PIN are displayed on the UTM boot screen or on the Securepoint delivery note.
    Start date 25.11.2024 Date from which the zero-touch profile should be valid
    Expiration date 25.11.2025 Date on which the zero-touch profile expires
    Websession PIN 1 2 3 4 5 6 Web session PIN for the UTM
    Lizenz Lizenz aus Reseller-Portal auswählen
    TTT-Point AG (xxxxxxx)
    The license can be transferred directly from the reseller portal.
    In this case, a drop-down menu appears for selecting the licenses stored in the RSP.
    Only an existing license can be selected if the login was made via a reseller account.
  • Die Lizenz muss gültig sein!
  • Lokal gespeicherte Lizenz auswählen
    UTM-Lizenz (.pem) hier per Drag & Drop ablegen oder klicken
    Locally stored UTM license (.pem file) to be applied to the UTM
  • Die Lizenz muss gültig sein!
  • Configuration UTM-Config-TTT-Point-III.utm Optional configuration of a UTM (.utm file), which can be a local backup or an encrypted cloud backup
    Located under  Unified Security Console UTMs → UTM tile → Tab  Cloud Backup  Download button

    Further information can be found in the wiki article Configuration management
  • The configuration cannot be changed retrospectively! If a different configuration is to be used, a new zero-touch profile must be created.
  • Configuration password     The password to decrypt the UTM configuration
    Up­date auf die ak­tu­el­le UTM-Ver­si­on notempty
    New as of: UTM v14.1.1
      
    notempty
    Ist erst einstellbar und wird erst ausgeführt wenn bei Konfiguration eine UTM-Konfiguration hinterlegt wurden ist!
    • Ab UTM-Version 14.1.1 wird die UTM vor dem Einspielen der Konfiguration auf die aktuelle Version aktualisiert, um Inkompatibilitäten mit der hier ausgewählten Konfiguration zu vermeiden
    • Wir empfehlen dringend, diese Einstellung nur in berechtigten Ausnahmesituationen zu deaktivieren, damit das Zero-Touch Enrollment erfolgreich durchgeführt werden kann
    UTM AGB    By activating, you accept the UTM Terms and Conditions
    Privacy Policy UTM    Upon activation, the UTM privacy policy is accepted
    Privacy Policy Unified Security Console    Upon activation, the Unified Security Console (USC) privacy policy is accepted
    Close Closes the page without saving the entries
     Save Saves the entries and creates a new zero-touch tile

    Edit Zero-touch profile

    Existing zero-touch profiles can be edited by clicking on their tile. Alternatively, use the hamburger menu  Bearbeiten
    Caption Value Description
    Name ZT AnyIdeas Name of the profile
    Serial number 1234567890 Unique serial number of the UTM
    Enrollment-PIN A B C D E F G H Enrollment-PIN of the UTM notempty
    The PIN is generated when the UTM is started for the first time after initial or new installation.
    notempty
    The combination of the serial number and PIN must be unique. If a profile with this serial number and PIN already exists, the change cannot be applied.
    Start date 13.11.2024 Date from which the zero-touch profile should be valid
    Expiration date 30.04.2025 Date on which the zero-touch profile expires
    Websession PIN 1 2 3 4 5 6 Web session PIN for the UTM
    Lizenz Lizenz aus Reseller-Portal auswählen
    TTT-Point AG (xxxxxxx)
    The license can be transferred directly from the reseller portal.
    In this case, a drop-down menu appears for selecting the licenses stored in the RSP.
    Only an existing license can be selected if the login was made via a reseller account.
  • Die Lizenz muss gültig sein!
  • Lokal gespeicherte Lizenz auswählen
    UTM-Lizenz (.pem) hier per Drag & Drop ablegen oder klicken
    Locally stored UTM license (.pem file) to be applied to the UTM
  • Die Lizenz muss gültig sein!
  • Configuration notempty
    The configuration cannot be changed retrospectively! If a different configuration is to be used, a new zero-touch profile must be created.
    Up­date auf die ak­tu­el­le UTM-Ver­si­on notempty
    New as of: UTM v14.1.1
      
    • Ab UTM-Version 14.1.1 wird die UTM vor dem Einspielen der Konfiguration auf die aktuelle Version aktualisiert, um Inkompatibilitäten mit der hier ausgewählten Konfiguration zu vermeiden
    • Wir empfehlen dringend, diese Einstellung nur in berechtigten Ausnahmesituationen zu deaktivieren, damit das Zero-Touch Enrollment erfolgreich durchgeführt werden kann
    notempty
    Diese Option lässt sich nachträglich nicht verändern! Soll diese Option aktiviert oder deaktiviert sein, muss ein neues Zero-Touch Profil angelegt werden!
    Close Closes the page without saving the changes
     Save Saves the changes