Zero-Touch Provisioning in the Alps –– Oktopus & Tirolnet Success Case

Published by
Felipe Farias
on
July 20, 2026

Zero-Touch Provisioning in the Alps

Every ACS vendor claims zero-touch provisioning. It's on nearly every landing page in the industry, ours included. But "zero-touch" means something different depending on the network it's running on, and it's only really tested the moment a customer with unchangeable PPPoE credentials factory-resets a router in a village with no technician nearby, and expects it to just work.

That's the requirement Tirolnet brought to the table, and it's a useful example of what zero-touch provisioning actually takes in practice, beyond the pitch.

Who Tirolnet Is

Tirolnet has been building fiber across Tyrol, Austria since 2012. Today the company serves over 14,000 customers in more than 170 municipalities, with a large share of that footprint growth carried out by roughly 50 independent installation partners rather than a single centralized field team. Its customer-facing hardware is almost entirely AVM Fritzbox, and every one of those units authenticates to the network over PPPoE with credentials the customer cannot change.

That constraint shapes the whole requirement: if credentials can't be changed after the fact, provisioning has to be corrected the first time, automatically, with no manual step at the CPE.

Tirol | Austria, Map, History, & Facts | Britannica
Tyrol region in Austria

The Requirement Wasn't "Support TR-069"

Tirolnet's NOC didn't approach this as a protocol checkbox exercise. The requirements were defined around how the network actually operates day to day, which is generally where the harder engineering work lives — not in the protocol itself, but in what has to happen around it.

Three requirements shaped the deployment. The NOC needed full visibility across every managed device at all times. Installation partners needed to see only the devices assigned to them, both as sound operational practice and to stay aligned with GDPR data-minimization principles. And because PPPoE credentials are fixed at the network level, onboarding a factory-fresh Fritzbox had to happen without any manual configuration step whatsoever.

Underlying all three was a deployment preference: run the platform on Tirolnet's own infrastructure rather than shared cloud, keeping customer credentials inside the ISP's own network boundary.

On-Premises Deployment GDPR Compliant

Building the Onboarding Flow

The proof of concept centered on getting a Fritzbox to authenticate against the ACS end-to-end. From there, the integration work focused on the AVM Fritzbox data model specifically. A custom RPC was developed to switch a Fritzbox's WAN connection to PPPoE, which was incorporated into a boot script triggered the moment a factory-reset CPE connects to the ACS for the first time. The CPE's serial number, pre-registered in the platform, is used as the mapping key to set PPPoE credentials automatically — no technician on site, no manual configuration step.

Where Things Stand

TR-069 is now running in production, with Tirolnet steadily expanding the number of managed devices and onboarding its support team to the platform. In parallel, the ISP has begun testing TR-369 over MQTT on greenfield hardware. This positions Tirolnet to migrate toward TR-369 on its own timeline, device by device, rather than facing a disruptive protocol cutover later.

"I like your flexibility and ability to adapt to our workflow. Always willing to make changes to match our needs." — Sebastian Tilg, CTO at Tirolnet

That summarizes the engagement well. What made the deployment work was fitting each of them precisely to how a regional ISP with a distributed partner network actually operates, rather than asking the network to adapt to the platform.

Published by
Felipe Farias
felipe-farias
GET STARTED

Take control of your
network today

The world’s most widely used USP Controller and TR-069 ACS, with
enterprise-class features and no vendor lock-in.