Peplink Balance and SpeedFusion Cutover Runbook
Peplink Balance enterprise routers combine multiple WAN types, routing, VPN and SpeedFusion capabilities, while InControl provides centralized management. A field cutover must distinguish ordinary load balancing, session persistence, Hot Failover, WAN Smoothing and bandwidth bonding and validate only the features licensed and approved for the site.
Make each dispatch repeatable and recoverable
Define prerequisites, remote ownership, method of procedure, acceptance evidence and rollback before technicians arrive onsite.
InControl, firmware and configuration staging
Confirm the customer-controlled InControl organization, group, subscription or PrimeCare status, router model and approved firmware. Reconcile serials before claiming or moving devices. Export a protected baseline and review release notes and hardware-specific support before upgrades.
Stage WAN interfaces, VLANs, DHCP, DNS, routing, NAT, firewall, VPN, QoS, health checks and outbound policies through the approved change process. Document which applications need persistence, public allowlists, inbound services or SpeedFusion behavior.
The remote team should supply the site identifier, approved design, equipment list, configuration status, contacts, access window and success criteria. The field technician verifies serials, labels, damage, accessories and prerequisites before changing production service.
- Authorized InControl group
- Model, license and firmware
- Protected baseline backup
- WAN and application dependencies
Rack, circuit and router cutover
Verify rack space, power, UPS, grounding, provider handoffs, optics, Ethernet ports, SIMs and antennas before moving production cables. Photograph and label the existing router and every WAN/LAN connection. Keep console or local management access available.
Move connections in the method-of-procedure sequence and pause for remote confirmation after each WAN and LAN milestone. Confirm InControl visibility and configuration synchronization before enabling production traffic. Preserve the old router and addressing until rollback criteria expire.
Use a written method of procedure with hold points for configuration-sensitive actions. Photograph and label the before state, preserve known-good cabling or configuration, and keep a practical rollback path. Record deviations as they occur instead of reconstructing them after the visit.
- Rack, power and circuits
- Before-state cable map
- Local recovery access
- Remote hold points
| Layer | Acceptance | Evidence |
|---|---|---|
| WAN | Addressing, health and performance | Circuit tests |
| Policy | Correct path, QoS, NAT and persistence | Application flows |
| SpeedFusion | Tunnel and approved feature behavior | Failure timeline |
| Operations | InControl, alerts, backup and ownership | Closeout record |
Policy, SpeedFusion and resilience validation
Test each WAN independently for addressing, DNS, latency, loss, throughput and required applications. Verify health-check transitions and outbound policy with evidence that traffic uses the intended path. A green dashboard icon is not proof of correct routing.
Establish and test the intended SpeedFusion tunnel. Trigger approved path failures and record detection, tunnel behavior, session impact and restoration. Distinguish Hot Failover from smoothing or bonding expectations, and review data consumption on metered cellular or satellite links.
Validation must cover physical status, management visibility, addressing, uplinks, power, policies and representative user traffic. When redundancy is expected, test the approved failure and restoration scenarios. Escalations should include timestamps, identifiers and reproducible evidence.
- Every WAN independently
- Policy and persistence
- SpeedFusion mode behavior
- Failure and restoration timing
Closeout, support and lifecycle ownership
Reconcile serial, ports, WAN circuits, software, InControl group, policies, SpeedFusion peers and licenses with the work order. Deliver event timelines, representative tests, photographs and every temporary rule or exception.
Transfer administrator, subscription, firmware, backup, alert and carrier-escalation ownership to named client teams. Store configurations and credentials in the client-controlled repository and link only to official Peplink firmware resources publicly.
Closeout combines annotated photographs, serials, port and cable records, software versions, test output, exceptions and ownership. Credentials and private configurations belong in the client-controlled repository, while public pages should point only to official manufacturer support resources.
- Serial/circuit reconciliation
- Events and test evidence
- Temporary-setting log
- Support and subscription owner
How we plan and deliver the work
The final design depends on site conditions, existing systems, client policies and the selected manufacturer or platform.
Prepare
Confirm access, equipment, remote readiness and rollback.
Execute
Install through the approved method and document deviations.
Test
Validate management, service, resilience and user workflows.
Close
Deliver evidence, inventory, exceptions and support ownership.
Information to gather before design
Good decisions are easier when the project team starts with complete operational and technical information. The following items help reduce assumptions, change orders and avoidable return visits.
- Site access and remote contacts
- Staging, inventory and prerequisites
- Method, maintenance window and rollback
- Acceptance tests and escalation
- Evidence and operational ownership
Frequently asked questions
These are common planning questions. A site-specific answer should be confirmed during discovery and design.
Is load balancing the same as SpeedFusion bonding?
No. Outbound policies distribute sessions; SpeedFusion features operate within configured tunnels and depend on licenses and endpoints.
Should cellular WAN be tested only as backup?
Test registration and service independently, then trigger the approved failover and review data use.
When should firmware be updated?
After checking the exact model, release notes, compatibility, support policy and rollback plan.
What must remain until acceptance?
The prior router or recovery configuration, cable map, addressing, access path and authorized rollback decision.
Manufacturer software, firmware and technical files remain on the manufacturer’s official website. We do not mirror firmware files locally.
Build a repeatable field-deployment plan
Provide the site list, target schedule, equipment responsibility, change-window constraints and acceptance criteria. We will help turn them into a practical rollout and closeout workflow.