Network Upgrade Checklist
Steps a sysadmin or MSP engineer runs to plan, execute, and verify a network infrastructure upgrade — switch refresh, firewall replacement, or core routing change — with backup, change-window, and rollback discipline.
Pre-Upgrade Planning
-
Document the existing network topology
Export current configs from every switch, router, and firewall (Meraki, FortiGate, Cisco Catalyst, etc.). Capture VLAN assignments, subnet ranges, OSPF/BGP neighbors, and trunk configurations. Pull a current diagram from Auvik, NetBox, or Visio — most environments have drift between the diagram and reality.
Collects file -
Identify hardware and licensing requirements
Confirm SKUs, transceiver types (SFP+/SFP28/QSFP), PoE budget on new switches, and licensing tier (Meraki Enterprise vs. Advanced, FortiGate UTP vs. ATP). Flag long-lead items — Cisco and Meraki licensing co-terms are a common scheduling gotcha.
-
Confirm change category with the CAB
Submit a change request (RFC) to the Change Advisory Board. Most network upgrades are normal changes requiring CAB approval; standard pre-approved templates apply only for like-for-like swaps. Capture the approved change window and any client-facing maintenance notification requirements.
Collects list -
Verify compatibility with downstream systems
Check 802.1x/RADIUS, NAC, VoIP QoS markings, printer DHCP reservations, and any hardcoded device IPs against the new platform. WireGuard or IPsec VPN cipher suites and SD-WAN overlay compatibility are common breakage points when replacing a firewall.
-
Notify users and stakeholders of the maintenance window
Send the notification one week ahead and again 24 hours before. Include start/end times in user-local timezone, expected impact, and the IT escalation contact. For MSP clients, route through the account manager and PSA notification template.
Backup and Rollback Preparation
-
Export running configs from all affected devices
Pull running-config and startup-config from every device in scope. Store in version control (Git) or the config backup tool (RANCID, Oxidized, SolarWinds NCM). Two copies, one offsite — config files are tiny; there is no excuse for losing them.
Collects file -
Validate backup restorability on a lab device
Load the backup onto a spare or virtual instance (EVE-NG, GNS3, or a lab switch) and confirm it boots clean. A backup nobody has ever restored is a hypothesis, not a backup.
-
Write the rollback runbook
Document the named rollback decision point and time budget — typically 30 minutes from window start. Include exact commands to revert configs, console cable pinouts, OOB/iDRAC access notes, and the named on-call engineer authorized to call rollback.
-
Stage tools and out-of-band access
Console cables, USB-to-serial adapters, laptop with TFTP server, cellular hotspot for OOB access if the upgrade kills primary internet. Verify iDRAC/iLO/IPMI credentials work — if you lock yourself out mid-window, the cellular hotspot is your only path back in.
Cutover Execution
-
Open the maintenance window and notify on-call
Page PagerDuty/Opsgenie that the window is open so monitoring alerts route correctly and don't wake the wrong engineer. Confirm the NOC has eyes on the affected sites in PRTG, Auvik, or LogicMonitor.
-
Rack new hardware and apply base configs
Mount the device, label patch cables to match the cutsheet, and load the pre-staged config via console. Verify management VLAN reachability before cutting any user traffic over.
-
Migrate VLANs, routing, and firewall rules
Apply VLAN trunking, OSPF/BGP neighbors, and firewall policy in the order documented in the upgrade plan. Watch for any-any rules being recreated as a shortcut — that's how flat networks happen.
-
Run smoke tests against critical services
Test DNS, DHCP, AD authentication, M365 reachability, VPN client connection, and at least one VoIP call. Verify QoS markings survive the new switch — softphones drop voice quality fast when DSCP gets stripped.
Collects list -
Execute the rollback runbook
If smoke tests fail and remediation will exceed the change window, restore the prior configs from backup and reseat the legacy hardware. Notify the CAB chair and the affected stakeholders that rollback was invoked. A clean rollback is a successful change; a partial cutover that limps into Monday morning is not.
Post-Upgrade Verification
-
Verify monitoring coverage on new devices
Confirm SNMP, syslog, and NetFlow exports land in the SIEM and monitoring platform (Splunk, Sentinel, PRTG, Auvik). Devices the NOC can't see are devices the NOC can't fix.
-
Update the network documentation and CMDB
Update IT Glue, Hudu, or Confluence with new asset tags, IPs, serial numbers, and warranty terms. Refresh the topology diagram. Stale docs cost the next on-call engineer an hour at 2am.
-
File the post-change report
Summarize for the CAB and stakeholders: window duration, deviations from plan, incidents triggered, rollback invoked or not, lessons learned. Required artifact for SOC 2 change-management evidence.
Collects list Collects paragraph Collects signature -
Collect end-user feedback at 48 hours
Pull the helpdesk ticket queue (ConnectWise, Freshservice, Jira Service Management) for any tickets tagged to the upgrade window. Slow-WiFi and printer-can't-find-server tickets often show up Day 2, not Day 1.
-
Schedule the 30-day follow-up review
Hold a 30-day review with the network team and (for MSP engagements) the vCIO. Review monitoring trends, ticket volume, and any deferred follow-up items from the post-change report.
Use this template
Copy it to your account, customize the steps, and run it with your team in minutes.
Browse hundreds of free templates across every team and industry.
Back to template libraryRun Network Upgrade Checklist with your team
Customize the steps, assign roles, set a schedule, and keep a complete record for every run.