Peplink Balance and SpeedFusion Cutover Runbook
Peplink Balance enterprise routers combine multiple WAN types, routing, VPN and SpeedFusion capabilities, while InControl provides centralized management. A field cutover must distinguish ordinary load balancing, session persistence, Hot Failover, WAN Smoothing and bandwidth bonding and validate only the features licensed and approved for the site.
Make each dispatch repeatable and recoverable
Define prerequisites, remote ownership, method of procedure, acceptance evidence and rollback before technicians arrive onsite.
InControl, firmware and configuration staging
Confirm the customer-controlled InControl organization, group, subscription or PrimeCare status, router model and approved firmware. Reconcile serials before claiming or moving devices. Export a protected baseline and review release notes and hardware-specific support before upgrades.
Stage WAN interfaces, VLANs, DHCP, DNS, routing, NAT, firewall, VPN, QoS, health checks and outbound policies through the approved change process. Document which applications need persistence, public allowlists, inbound services or SpeedFusion behavior.
Settle the firmware decision and the change window with the customer before anyone claims a device into the organization, and confirm who holds the InControl administrator role that day. Arriving to find the group locked or the subscription lapsed turns a scheduled cutover into a return visit nobody budgeted.
- Authorized InControl group
- Model, license and firmware
- Protected baseline backup
- WAN and application dependencies
Rack, circuit and router cutover
Verify rack space, power, UPS, grounding, provider handoffs, optics, Ethernet ports, SIMs and antennas before moving production cables. Photograph and label the existing router and every WAN/LAN connection. Keep console or local management access available.
Move connections in the method-of-procedure sequence and pause for remote confirmation after each WAN and LAN milestone. Confirm InControl visibility and configuration synchronization before enabling production traffic. Preserve the old router and addressing until rollback criteria expire.
Keep the previous WAN handoffs patched and labeled through the sequence, because a provider circuit restored late at night is easier to prove than to recall. Write each milestone confirmation into the log as it is given, naming the remote engineer who released the next step and the time it was released.
- Rack, power and circuits
- Before-state cable map
- Local recovery access
- Remote hold points
| Layer | Acceptance | Evidence |
|---|---|---|
| WAN | Addressing, health and performance | Circuit tests |
| Policy | Correct path, QoS, NAT and persistence | Application flows |
| SpeedFusion | Tunnel and approved feature behavior | Failure timeline |
| Operations | InControl, alerts, backup and ownership | Closeout record |
Policy, SpeedFusion and resilience validation
Test each WAN independently for addressing, DNS, latency, loss, throughput and required applications. Verify health-check transitions and outbound policy with evidence that traffic uses the intended path. A green dashboard icon is not proof of correct routing.
Establish and test the intended SpeedFusion tunnel. Trigger approved path failures and record detection, tunnel behavior, session impact and restoration. Distinguish Hot Failover from smoothing or bonding expectations, and review data consumption on metered cellular or satellite links.
Pair each failover observation with a capture showing the source address and the path traffic actually took, alongside the InControl event line. That combination gives a remote engineer something to reproduce when a session drops weeks later, and it helps separate a health-check tuning question from a circuit fault.
- Every WAN independently
- Policy and persistence
- SpeedFusion mode behavior
- Failure and restoration timing
Closeout, support and lifecycle ownership
Reconcile serial, ports, WAN circuits, software, InControl group, policies, SpeedFusion peers and licenses with the work order. Deliver event timelines, representative tests, photographs and every temporary rule or exception.
Transfer administrator, subscription, firmware, backup, alert and carrier-escalation ownership to named client teams. Store configurations and credentials in the client-controlled repository and link only to official Peplink firmware resources publicly.
What people hunt for months afterward is the WAN circuit reference tied to a physical port and to the policy that steers traffic across it. Capture that mapping with the firmware level running at acceptance, and flag any rule left in place temporarily along with the date it should be reviewed.
- Serial/circuit reconciliation
- Events and test evidence
- Temporary-setting log
- Support and subscription owner
How we plan and deliver the work
The final design depends on site conditions, existing systems, client policies and the selected manufacturer or platform.
Preconfigure the router
Add the unit to the management group, apply approved firmware and load the reviewed WAN and policy configuration.
Confirm licensing
Check which features the site is licensed and approved to run before any bonding or failover profile is enabled.
Cut over WANs
Move the wired and cellular circuits onto the router one at a time, verifying each WAN independently.
Prove failover
Fail each WAN deliberately and watch how sessions, voice and application traffic behave during and after recovery.
Information to gather before design
Peplink behavior at a site follows the circuits and features actually in place, so the WAN inventory and policy intent need to be settled before staging.
- WAN circuits and carrier accounts
- SIM cards and cellular plans
- Applications needing session persistence
- Peer sites for bonded tunnels
- Management group and firmware target
Frequently asked questions
These are common planning questions. A site-specific answer should be confirmed during discovery and design.
Is load balancing the same as SpeedFusion bonding?
No. Outbound policies distribute sessions; SpeedFusion features operate within configured tunnels and depend on licenses and endpoints.
Should cellular WAN be tested only as backup?
Test registration and service independently, then trigger the approved failover and review data use.
When should firmware be updated?
After checking the exact model, release notes, compatibility, support policy and rollback plan.
What must remain until acceptance?
The prior router or recovery configuration, cable map, addressing, access path and authorized rollback decision.
Manufacturer software, firmware and technical files remain on the manufacturer’s official website. We do not mirror firmware files locally.
Talk through your Peplink site cutover
Bandwidth bonding, Hot Failover and ordinary load balancing are different jobs onsite. Outline the circuits at each location, which applications cannot drop a session, and how many sites belong to the wave.