A customer premises device (CPE) is never configured in the unit and nobody ever types into the router. It is prepared at the bench, labelled, put into stock, mounted by the technician with the job sheet in hand, and the platform binds and activates it on its own. This page is the single procedure behind Devices & inventory and Installs & field service; the short version lives in the dashboard under CPE Fleet → Bench guide.
CPE Fleet page with the Bench guide and Print stickers buttons

CPE Fleet — Bench guide, Print stickers, Discover now and Full sweep live here; devices appear as rows once discovery has seen them

Decisions this procedure rests on: the device owns its Wi-Fi sticker (not the unit), the bench password is rotated per device by the platform, binding happens only on a port the unit register knows, and the operator view shows the ISP at a port, never the end customer. Details below.

Who does what

Where to bench — the port, not the switch

A bench port is defined by its VLANs, not by the switch it sits on. Any managed switch works as long as the port:
  • carries the captive VLAN untagged and the CPE management VLAN tagged — exactly the profile every subscriber port has in the golden configuration;
  • sits in the same layer-2 domain as the netinstall server and the platform’s management path;
  • is not mapped to a unit in the unit register. That is what keeps a bench device in stock: binding only happens on register ports, and it is also why a bench port must never become a unit port later without clearing it first;
  • is copper at the device end — Etherboot only runs over the CPE’s ether1. From an SFP switch port that means a copper SFP (1000BASE-T) or a short DAC/fibre into a small copper switch.
The exact port, optic and fallback per site are NOC-internal and live in the dashboard under CPE Fleet → Bench guide → Where to bench, behind the operator login. Customer ports on the same switch are off limits.

Phase 1 — Bench provisioning

Why the bench: RouterBOOT loads a fresh system only over ether1 copper (Etherboot). Unit ports are SFP, so a device cannot be reset and reloaded inside the unit. One device takes three to five minutes at the bench.
1

Check the bench

The bench port is a copper port on the captive VLAN (captive VLAN untagged, CPE management VLAN tagged). The netinstall server must be up — if in doubt ask the NOC first; a device that Etherboots with no server answering just sits there. Have Network → CPE Fleet open: that is where the device will appear. The seven bench steps are also in the dashboard under Bench guide, written for the person at the bench.
Bench provisioning guide page in the dashboard

Bench guide in the dashboard

2

Cable ether1 only

Device powered off. Patch ether1 (the copper WAN/PoE-in port next to the SFP cage) to the bench port. Nothing in the SFP cage, nothing on ports 2–5.
3

Etherboot: hold reset while powering on

Hold the reset button, plug in power while holding. After ~5 s the user LED starts blinking — keep holding (releasing now only resets the configuration). After ~15 s the LED goes off — release. The device is in Etherboot. If the LED never goes off or the device simply boots, power off and repeat.
4

Netinstall runs by itself

The server formats the device, writes RouterOS 7.21 long-term (plus the Wi-Fi package on a hAP ax S) and bakes in the Kurnl golden configuration (management VLAN, bench password, captive bridge, SNMP identity). One to two minutes; the device reboots on its own. Do not unplug — an interrupted run leaves the device without a system, repeat from the previous step.
5

Wait for the fleet row

Discovery on the management VLAN finds the device within two minutes, or immediately with Discover now. It logs in with the bench password, reads model, serial, MAC and firmware, sets a per-device admin password and registers the row: identity CPE-<serial>, status stock, location Unassigned; status turns online within a couple of minutes. Check model and serial against the label. This row is the go signal — it proves system, configuration and management path. Nothing after five minutes: Discover now, then Full sweep, then hand the serial to the NOC.
6

Sticker, then power off

CPE Fleet → Print stickers lists every device not yet bound to a unit. Print this device’s label (Wi-Fi name, password, QR and port legend for a hAP ax S; port legend only for a hEX S) and stick it on top of the housing. Power off, unplug ether1. The device is now stock: provisioned, registered, labelled, waiting for a unit. It keeps its configuration and its sticker pair across installs and factory resets.
Sticker print page listing unbound devices

Print stickers — every device not yet bound to a unit

Etherboot does not work over the WireGuard/VXLAN tunnel (TFTP does not survive the path). A remote building either gets devices pre-provisioned at the Victoria bench or a local netinstall host. This is the open item for Estoya and every HSIA-connected site.

Phase 2 — Stock, job and kit

A pending install becomes a dispatch on Installs & Dispatch. The dispatch carries the visit’s scope, derived from the building’s line type and the unit’s patch state and overridable per card:
Dispatch board

Installs & Dispatch — the dispatch board with the per-job scope

The job sheet lists what to bring: the switch-end optic (BX-D, FS SFP-1G43-BX10) for the panel/switch port, the CPE-end optic (BX-U, FS SFP-1G34-BX10) for the device’s SFP cage, a patch cord, and a stock CPE of the building’s planned model (set planned_cpe_model on the building, the kit is derived from it). We use BiDi optics: the two ends are different parts, one of each per line.

Phase 3 — The technician’s visit

Technicians sign in to the operator portal with the technician role and land on My jobs (/field/jobs); every other page redirects them back. The operator creates the sign-in once: Installs & Dispatch → Technicians → Set up sign-in sends a mail that lets the technician choose a password. No MFA is required for this role.
Technicians tab in Installs & Dispatch

Technicians tab — Portal sign-in state, Re-send link, coverage per technician

My jobs list for a technician

My jobs — what the technician sees after signing in

Each job opens a job sheet with five numbered steps; it also prints on one page (A4 or US Letter) for a paper copy:
Job sheet header and step 1

A job sheet — line status strip, customer contact, window, then the numbered steps

1

1 · On site

Stamp the arrival. It tells the NOC and the provider that the visit has started; the sheet’s status strip stays visible in every step.
2

2 · Patch plan (MER)

Shown when the scope includes the MER: room, rack and access notes, the NetBox cable path (switch port → panel port), a rack view. Front panel port = the work, rear port = documentation. Put the BX-D optic into the named switch port, patch the front port, press Patched — the platform writes the cabling into the register (a 409 means another unit already holds that switch port; stop and call the NOC).
3

3 · Device (unit)

Mount the stock CPE: BX-U optic into the SFP cage, the fibre from the wall into it, power on, ether1 stays empty in a fibre/DAC building (copper buildings use ether1 as the uplink), customer devices on ports 2–5. The device card is read-only and fills itself once discovery has seen the device — “waiting for the CPE to phone home” is normal for up to two minutes.
Job sheet device step with the port schematic

Steps 2–4 on the sheet: patch plan (here: nothing to do in the MER), device with the optic and the port strip, photos

4

4 · Photos

Take the photos in the app: the mounted device with its sticker, the patched panel, anything unusual. Photos are bound to the CPE, not just to the job, and show up on the device page afterwards.
5

5 · Work done

Stamp it. This is documentation only — the line does not activate from the stamp, it activates from the device’s first contact (next phase). If the device did not bind before you leave, say so in the notes.
The technician’s sheet shows the on-site contact’s name and phone because someone has to ring the bell. The operator’s own views never show the end customer — they show the ISP that owns the line.

Phase 4 — Binding and activation, on their own

Within the next discovery pass (≤ 2 min) the switch reports the device’s MAC on the unit’s port. The MAC search waits for every switch and places a device only at a port that the unit register maps to a unit; uplinks and trunks never count. The platform then:
  1. binds the device to the unit — location Building · Unit, identity renamed to the canonical …|UNIT-xx|CPE, status stays online;
  2. moves the unit’s port from the captive VLAN to the provider’s VLAN once the subscription is there, so the resident leaves the captive portal and gets the ISP’s service;
  3. records the install as completed for the subscription and fires the install.completed event — wire follow-ups in Automations.
Nothing to assign by hand. A device seen anywhere else (a trunk, the bench) stays stock — that is deliberate.

Credentials, identities and labels — the decisions

  • Bench password: baked in by netinstall, known only to the server and the middleware, rotated to a per-device password on first discovery. No technician ever needs or sees a router password; the operator portal is the only way in. A handover reset (the 5-second reset in the unit) restores the golden configuration and the device’s sticker pair and keeps the per-device admin password.
  • Identity: CPE-<serial> at the bench, the canonical REGION|SITE|ROOM|UNIT-xx|CPE after binding. The technician does not name anything.
  • Sticker (Wi-Fi name + password + QR + port legend): belongs to the device, issued at the bench, printed from CPE Fleet before the device leaves the bench. It follows the device into the next unit after a move-out; a unit never has a sticker of its own. “New sticker…” on a device rotates the pair and reprints.
  • Device label from the factory: stays; the serial on it is what the bench technician checks against the fleet row.

Troubleshooting

Operator notes (NOC)

  • Discovery: lease probe on the management VLAN every two minutes, full pool sweep once a day; Discover now runs one pass, Full sweep the whole pool.
  • Stock per building: keep at least one provisioned device of the building’s planned model in stock before a truck roll is booked — the dispatch’s kit list assumes it.
  • Host, service and log names of the netinstall server, the seed script and the bench port per site are NOC-internal: dashboard → CPE Fleet → Bench guide → Operator notes (operator login).

Still to settle

  • Remote buildings without a bench (Estoya via HSIA, later CCI): pre-provision in Victoria and ship, or a small netinstall host on site.
  • NOC bench port at Harbour Road: confirm the profile on the live switch and fit the copper SFP; decide whether a small copper bench switch replaces it.
  • Who prints and applies stickers when devices are shipped rather than carried by the installing technician.
  • Spare-device policy per building (how many stock CPEs travel with the technician).