An edge refresh looks simple on a spreadsheet: one site, one stack of access switches, one router, replaced like for like. The difficulty is scale, and the fact that the kit being replaced carries the connection used to manage the change. The planning problem is less about hardware than about sequencing and access.
Standardise the configuration before the hardware
Estates that grew site by site usually carry years of local exceptions: a VLAN added for one tenant, an access list nobody remembers writing, a port channel built differently at each office. Replacing hardware first means translating each exception by hand, site by site. Build templates for each site type, then compare each existing configuration against them and record what does not fit. That deviations list is the real scope of work. For every exception, ask whether it is still needed and who owns it.
Pre-stage away from the site
Devices should arrive with firmware at the target version, the site configuration loaded and a label that matches the rack position. Staging centrally allows boot, licensing and uplink behaviour to be tested before an engineer travels. It also catches dull failures early: a wrong power supply, missing optics, a licence tied to the wrong serial number. Across many locations, staging, kitting and dispatch are usually run as one multi-site roll out programme, not as separate site projects.
Sequence the cutover so the path home survives
Order matters more than speed. A sound sequence keeps a management path open at every step:
- Confirm out-of-band access works before touching anything.
- Rack and power the new devices alongside the old ones where space allows.
- Move uplinks first, then verify reachability from the central team.
- Migrate access ports in labelled batches, testing each before continuing.
- Leave the old kit racked, powered down, until the site has run a full business day.
Write the rollback plan per site
A generic rollback note does not help an engineer halfway through a night window. Each site needs a specific trigger, such as loss of management access for an agreed period or a failed application test, and a decision owner reachable during the change. The plan should state which cables go back where. Photographs of the old cabling, taken before work starts, are often the most useful rollback document.
Treat out-of-band access as a prerequisite
A console server with its own cellular or independent line gives the central team a way in when the primary path drops. Test it from the operations centre before the change date, not on the night. Check that credentials, connection details and serial settings are documented and current.
When the edge is also the WAN termination
At smaller sites the router often terminates the carrier circuit and may also handle firewalling and VPN. Replacing it takes the whole site offline, and carrier dependencies can stretch the window. Some carrier handoffs cache or bind to the old router’s MAC address. PPPoE credentials or static addressing details sometimes exist only in the old device’s configuration. Confirm these with the carrier before the visit and ask whether it needs to be available during cutover. If the site has a backup circuit, move traffic onto it first and replace the primary router while the site stays up.
