Deployment, cutover and field support

Staged, deployed, validated and supported in the field

For Fortinet Security Fabric Field Cutover Runbook, TechRunz combines equipment staging with onsite installation, cutover, validation, troubleshooting, maintenance, refresh work and post-install field support. We can join during planning or take over a live rollout across western markets.

  • Equipment Staging
  • Onsite Installation
  • Cutover & Validation
  • Troubleshooting & Refresh
  • Field Support

New installation: Launching a new rollout? We can stage kits, deploy onsite, commission the technology and document acceptance.

Existing system: Supporting installed technology? We can troubleshoot, replace, refresh, maintain and close out corrective work.

Multi-site field deployment runbook

Fortinet Security Fabric Field Cutover Runbook

A Fortinet site cutover affects security policy, routing, switching, wireless and remote management at the same time. TechRunz uses a coordinated runbook that preserves the previous state, confirms supported firmware and topology, validates Security Fabric relationships and proves critical business traffic before closeout.

Make each dispatch repeatable and recoverable

Define prerequisites, remote ownership, method of procedure, acceptance evidence and rollback before technicians arrive onsite.

Compatibility baselineApproved FortiOS and managed-device versions, support status, licenses and the documented upgrade or replacement path.
FortiLink topologySupported ports, VLANs, trunks, split-interface or aggregate design and the intended FortiSwitch authorization state.
Policy dependenciesWAN, SD-WAN, routes, NAT, DNS, VPN, identity, certificates, security profiles and third-party allowlists.
Recovery packageKnown-good configuration, console path, cable map, decision thresholds and authorized rollback owner.

Firmware, licensing and configuration readiness

Confirm the exact FortiGate, FortiSwitch and FortiAP models, support entitlements, subscriptions and approved firmware combination using current Fortinet documentation. Review release notes and the supported upgrade path rather than assuming the newest release is appropriate for every component.

Stage interfaces, zones, VLANs, routing, SD-WAN, NAT, DHCP, DNS, VPN, identities, policies and logging through client change control. Identify public-address dependencies, partner tunnels, certificates and services that could fail even when general internet access works.

The remote team should supply the site identifier, approved design, equipment list, configuration status, contacts, access window and success criteria. The field technician verifies serials, labels, damage, accessories and prerequisites before changing production service.

  • Supported firmware combination
  • Entitlements and subscriptions
  • Policy and dependency review
  • Console and rollback readiness

FortiGate, FortiSwitch and FortiAP cutover

Record and label the old appliance ports and provider handoffs before moving cables. Install the FortiGate with local console access available and validate management before transferring production paths. Authorize FortiSwitch and FortiAP devices only after their serials and intended sites are confirmed.

Verify FortiLink physical and logical topology, switch ports, trunks, native VLANs, PoE and managed-device state. For high availability, follow the approved member, heartbeat and synchronization sequence and do not remove the old platform until the new cluster state and rollback decision are clear.

Use a written method of procedure with hold points for configuration-sensitive actions. Photograph and label the before state, preserve known-good cabling or configuration, and keep a practical rollback path. Record deviations as they occur instead of reconstructing them after the visit.

  • Provider and port cable map
  • FortiLink and authorization state
  • HA sequence and synchronization
  • Switch, AP and PoE verification
Fortinet cutover acceptance matrix
DomainRequired proofEvidence
FortiGate edgeWAN, route, policy, NAT and VPNTests and event logs
FortiSwitchFortiLink, ports, VLANs and PoEManaged-device and port state
FortiAPAuthorization, SSID, identity and client serviceWireless tests
ResilienceHA or SD-WAN failure and recoveryTimeline and status record

Security, connectivity and failure testing

Test each WAN, route, DNS, NAT, published service, site-to-site and remote-access VPN, logging destination and critical application. Verify that traffic is inspected by the intended policy and profile; successful reachability through an unintended rule is not acceptance.

Validate FortiSwitch client ports, voice or device VLANs, FortiAP SSIDs, authentication and representative users. Exercise approved SD-WAN, HA, uplink or power recovery scenarios, observing event logs and session impact. Escalate with timestamps, policy IDs and diagnostic evidence.

Validation must cover physical status, management visibility, addressing, uplinks, power, policies and representative user traffic. When redundancy is expected, test the approved failure and restoration scenarios. Escalations should include timestamps, identifiers and reproducible evidence.

  • WAN, NAT, VPN and DNS
  • Intended security-policy match
  • Client and SSID workflows
  • HA and SD-WAN recovery

Secure closeout and support ownership

Capture installed serials, port and VLAN mapping, managed-device authorization, HA state, firmware, licensing, VPN status and acceptance results. Record temporary policies, disabled profiles, unresolved warnings and the owner and deadline for each exception.

Place encrypted backups, certificates, private keys and administrator information in the client-controlled repository. Operations should own FortiCare and FortiGuard accounts, firmware policy, configuration backup, alerting and change approval. Public closeout material should link to official support rather than expose protected files.

Closeout combines annotated photographs, serials, port and cable records, software versions, test output, exceptions and ownership. Credentials and private configurations belong in the client-controlled repository, while public pages should point only to official manufacturer support resources.

  • Serial, port and firmware record
  • Temporary settings and exceptions
  • Protected backup and certificates
  • Support and change ownership

How we plan and deliver the work

The final design depends on site conditions, existing systems, client policies and the selected manufacturer or platform.

Prepare

Confirm access, equipment, remote readiness and rollback.

Execute

Install through the approved method and document deviations.

Test

Validate management, service, resilience and user workflows.

Close

Deliver evidence, inventory, exceptions and support ownership.

Information to gather before design

Good decisions are easier when the project team starts with complete operational and technical information. The following items help reduce assumptions, change orders and avoidable return visits.

  • Site access and remote contacts
  • Staging, inventory and prerequisites
  • Method, maintenance window and rollback
  • Acceptance tests and escalation
  • Evidence and operational ownership

Frequently asked questions

These are common planning questions. A site-specific answer should be confirmed during discovery and design.

Should every Fortinet component run the newest firmware?

Not automatically. Use the approved, supported combination and review release notes and upgrade paths for the exact models.

Is internet access enough to approve the firewall cutover?

No. Validate intended policy, VPNs, published services, logging, identity and critical business applications.

Why keep console access during the change?

Management or routing mistakes can remove remote access; a tested local recovery path makes the cutover recoverable.

Where should FortiGate backups and certificates be stored?

In a protected, client-controlled repository with restricted access—not on a public website or general field report.

Manufacturer software, firmware and technical files remain on the manufacturer’s official website. We do not mirror firmware files locally.

Build a repeatable field-deployment plan

Provide the site list, target schedule, equipment responsibility, change-window constraints and acceptance criteria. We will help turn them into a practical rollout and closeout workflow.

Contact TechRunz