NETCONF, YANG & Zero-Touch Provisioning
Modern operators don't ship boxes with golden configs on USB sticks anymore. OcNOS gives you the full model-driven config surface: NETCONF over SSH/TLS, OpenConfig and IETF YANG, candidate datastore with commit/rollback, and a Zero-Touch Provisioning flow that takes a brand-new chassis from box-open to operational state with a DHCP lease.
Day-0 Zero-Touch Provisioning Flow
A factory-fresh OcNOS router boots, requests a DHCP lease, fetches the correct image from the staging server, downloads its YANG-rendered config from the config server, commits to the running datastore, and reports operational. No operator on-site.

Why model-driven config matters
CLI scripts don't compose, don't roll back, and don't validate inputs against a schema. NETCONF + YANG gives you a typed, transactional config surface: push a candidate, validate, commit, or rollback if any leaf is rejected. OcNOS exposes both OpenConfig models (BGP, interfaces, network-instance, platform) and IETF models (ietf-interfaces, ietf-routing, ietf-system) plus IP Infusion native models for OcNOS-specific knobs. Combined with Zero-Touch Provisioning, the operations workflow becomes: rack a box, plug in management, walk away.
The OcNOS NETCONF, YANG & ZTP implementation
SSH + TLS transport
RFC 6241 NETCONF protocol, over SSH (RFC 6242) and TLS (RFC 7589), with full Get / Get-Config / Edit-Config / Commit / Validate / Lock / Discard-Changes RPC support.
OpenConfig + IETF + native
OpenConfig BGP, interfaces, network-instance, platform, telemetry; IETF system, interfaces, routing; IP Infusion native models for unique features.
Candidate + commit / rollback
Full candidate datastore with confirmed commit (RFC 6241), explicit rollback to N prior commits, and config-history retrieval.
Day-0 provisioning
DHCP option 67 / 239-driven boot: fetch image, signature-verify, install, reboot; then fetch config bundle and commit. Idempotent retry on partial failure.
Reference modules
Ansible Galaxy collection and Salt formulas for OcNOS NETCONF: idempotent BGP, interface, and EVPN role plays out of the box.
Coexistence with NETCONF
gNMI Set and NETCONF Edit-Config target the same model store. Pick the protocol that fits your tooling, the device behaves the same way.
What you get with OcNOS automation
- One config surface, two protocols. NETCONF and gNMI both target the same YANG-modelled datastore, with no protocol-specific feature gaps.
- Verified ZTP. Day-0 image fetch is signature-verified; config bundle integrity is checked before commit. Zero on-site touch with confidence.
- Open tooling. Reference Ansible collection, Salt formulas, and Python client examples published, with no proprietary SDK lock-in.
- Operational rollback. Every commit is tracked. Roll back to any prior state with a single RPC if a change goes wrong.
Standing up a model-driven operations stack?
Request a Technical Demo →Frequently asked questions
What YANG models does OcNOS support over NETCONF?
Does OcNOS support config rollback?
How does Zero-Touch Provisioning work in OcNOS?
Can I use both NETCONF and gNMI on OcNOS?
Does OcNOS work with Ansible and Salt?
Go deeper. Take it with you.
Two short, technical downloads that go further than this page: the full OcNOS-SP datasheet and the full OcNOS-DC datasheet.
OcNOS-SP Datasheet
Full OcNOS-SP specification: the access, cell site and aggregation feature set, software SKUs, supported hardware platforms, and the solution ordering guide.
Get the datasheetOcNOS-DC Datasheet
Full OcNOS-DC specification: the EVPN-VXLAN and Ethernet for AI feature set, software SKUs, supported hardware platforms, and the solution ordering guide.
Get the datasheetOcNOS-SP Datasheet
Quick form. Your PDF opens in a new tab immediately after submit.
✓ Opening your PDF in a new tab…
If it didn't open, use the link below.
OcNOS-DC Datasheet
Quick form. Your PDF opens in a new tab immediately after submit.
✓ Opening your PDF in a new tab…
If it didn't open, use the link below.