Replacing network equipment is rarely as simple as unplugging one box and connecting another.
Routers, firewalls, switches and wireless access points may support phones, printers, cameras, remote work, cloud applications, access-control systems and other business-critical devices.
A successful replacement begins with understanding what the network already does.
The main point
Plan the environment before selecting the equipment.
A newer wireless standard, larger port count or higher advertised speed does not automatically solve coverage, reliability, security or configuration problems.
CISA emphasizes supported network equipment, current software, secure configuration and the replacement of edge devices that have reached the end of vendor support.
Once a device is no longer supported, its manufacturer may stop monitoring it for defects, developing fixes or providing normal technical assistance.
Document the existing environment
Before purchasing equipment, record:
- Internet providers, circuit speeds and account information
- Router and firewall models, licenses and support dates
- Switch locations, port use and Power over Ethernet requirements
- Wireless access point locations and known coverage problems
- Network names, guest access and authentication methods
- Voice, camera, printer and building-system connections
- Remote-access and VPN requirements
- Public internet addresses, DNS settings and vendor allowlists
- Network segments and special device rules
- Rack space, power, cooling and battery backup
- Existing cabling and known problem areas
Create protected configuration backups before the change. These backups are useful for reference and rollback, but they should not be restored blindly to incompatible equipment or a redesigned network.
Treat configuration files as sensitive because they may contain network details, credentials or security settings.
Plan for actual capacity
Internet speed is only one part of the decision.
Consider:
- The number of wired and wireless devices
- Expected growth
- Simultaneous users
- Voice and video traffic
- Cloud applications
- Security inspection features
- Remote-access traffic
- Cameras and other high-bandwidth devices
A firewall or router should be sized for the services that will be enabled, not only the maximum speed printed on the box.
Security inspection, VPN use and other enabled features may affect real-world performance.
Plan wireless coverage around the building
Wireless performance depends on the physical environment.
Walls, construction materials, neighboring networks, floor layout, device density and access point placement may matter more than the theoretical speed of the wireless standard.
A coverage plan should identify:
- Where employees regularly work
- Areas with weak or inconsistent service
- High-density meeting or training spaces
- Guest and public areas
- Devices that need reliable roaming
- Areas where cabling can support access points
Adding more access points without coordinating their placement and configuration can create new problems rather than solving existing ones.
Review ports and power requirements
Switches should provide enough ports for current devices, planned additions and a reasonable reserve.
When switches power phones, cameras or access points, review both:
- The number of Power over Ethernet ports
- The total available power budget
A switch may have enough physical ports but insufficient power for every connected device.
Plan the change
Choose a maintenance window and communicate what may be unavailable.
A practical change plan should include:
- A verified equipment and configuration inventory
- Required licenses and administrator access
- Current firmware and approved settings
- A documented installation sequence
- A rollback path
- Tests for internet, internal systems, wireless, voice, printing and remote access
- Updated diagrams, labels and support records
Confirm how phones, payment systems, cameras, remote employees and other essential services will be affected.
Secure the new environment
Before the equipment enters normal service:
- Replace default credentials.
- Limit administrative access.
- Require MFA where supported.
- Install approved firmware.
- Disable unnecessary services.
- Protect remote-management interfaces.
- Confirm logging and time settings.
- Record support and end-of-support dates.
Do not leave old equipment connected as an undocumented backup. If old equipment must be retained temporarily, record its purpose, configuration and removal date.
What to avoid
Do not purchase equipment solely because it is familiar, inexpensive or marketed as fast.
Avoid consumer equipment in a business environment unless its support, security, management and warranty capabilities have been reviewed against the organization’s needs.
Do not:
- Retain default passwords.
- Expose administrative interfaces unnecessarily.
- Ignore license or subscription requirements.
- Assume wireless problems are always caused by internet speed.
- Restore an old configuration without reviewing it.
- Leave the final network undocumented.
When to involve IT
Involve IT before replacing a firewall, router, managed switch or organization-wide wireless system.
Professional planning is particularly important when the network supports:
- Multiple locations
- Remote access
- Voice systems
- Security cameras
- Regulated information
- Public-facing services
- Business-critical equipment
A network replacement should reduce uncertainty. When the work is complete, the organization should understand what was installed, how it is protected and how it will be supported.
Planning a network refresh or expansion? Book a consultation.