Skip to main content

TR-069 / ACS

TR-069 (CWMP) lets your CPEs call home so the portal can read their parameters and queue actions. LipaNet runs its own ACS: every ISP gets an isolated tenant with a stable inform URL, and each router gets its own management VLAN, DHCP scope and NAT rules that never touch your customer traffic. Navigate to: Sidebar → Networking → TR-069 / ACS → Dashboard Screenshot 2026 10 05 092825

The dashboard

The header shows whether TR-069 is enabled and whether the ACS answered. Below it, the ACS tenant card holds everything a CPE needs:
The inform URL is http only. CPE firmware has no CA bundle, so an https:// URL fails the TLS handshake and the device goes offline with no visible error.
Under the card you get the fleet view:
  • Managed CPEs, Online now, Pending tasks and Failed tasks.
  • Fleet by product class — how many CPEs of each model have informed.
  • Recent tasks — the actions queued for devices and their status.
  • Recent CPE events — informs, faults and parameter changes.
Screenshot 2026 10 05 093332
If the banner says TR-069 is disabled or the ACS could not be reached, no CPE will ever appear. Ask your platform administrator to enable TR-069 and set the ACS URL and API token on the orchestrator.

Devices

Networking → TR-069 / ACS → Devices lists every CPE that has informed. Click a row to open that device by its id. Screenshot 2026 10 05 093503 Each device page has tabs for what it reported: Screenshot 2026 10 05 094750
On the Network tab the TR-069 WAN profile is easy to spot — a name such as 1_TR069_R_VID_ with an address inside the ACS DHCP pool. If that interface has no address, the CPE never reached the ACS.

Provision the ACS network on a MikroTik

Press Provision MikroTik on the dashboard, pick the router, and LipaNet builds the whole management network on it. Screenshot 2026 10 05 094853

Settings

Only free ranges are offered. The picker lists subnets that do not overlap the OpenVPN, WireGuard, hotspot, static or PPPoE ranges on that router, and picking one fills the field for you. Screenshot 2026 10 05 095047
A range that overlaps anything already in use is rejected outright, so the ACS network can never take an address away from a customer or a tunnel.

Preview and apply

The preview shows every command that will run, the RouterOS script and the exact objects that will be created:
  • an /interface vlan tagged with the VLAN id, on the parent interface
  • the gateway /ip address on that VLAN
  • the /ip pool for the CPE addresses
  • an /ip dhcp-server and its /ip dhcp-server/network
  • srcnat masquerade rules for the management subnets
  • an optional /queue/simple for the bandwidth cap
Apply runs them on the router and records the run in Apply history. Removing the network runs the same objects in reverse.

What customers may change

The Customer access tab of a device decides what the customer sees in their portal (/cp → My router). Every capability can be Inherit, Allow or Deny, and Wi-Fi visible by default controls new networks. Networks that are not marked visible stay on the device and are hidden from the customer. Screenshot 2026 10 05 095232

Set up a CPE

Use the guide for the brand the customer has: Each page lists the exact URL, credentials, VLAN and inform interval to enter, step by step.

Troubleshooting

The CPE never appears. Check the inform URL is http://, the inform interval is 100 seconds or more, the VLAN id on the CPE matches the one provisioned on the MikroTik, and the ACS VLAN, pool and DHCP server exist on the router.
The CPE appears but stays offline. Read its Network tab: the TR-069 WAN profile should hold an address inside the ACS pool. Nothing in the pool means the management VLAN is not reachable from the CPE.
Never point a CPE at an https:// ACS URL. The TLS handshake fails, the inform never arrives, and the device may be blacklisted by the ACS after repeated failures.