How to replace a core switch with a rollback path: configuration and validation checklist for enterprise cutovers

Core-switch replacement is more than copying configuration. Verify VLANs, trunks, gateways, STP, link aggregation, optics, routing, ACLs, DHCP relay and uplink relationships, then execute staged validation with a defined rollback plan.

Inventory first, change secondInfrastructure changes affect business continuity. Keep configuration backups, maintenance windows, validation checks and rollback criteria before production changes.

1. The real risk is hidden dependency

An old core may host VLAN gateways, static routes, the STP root, LAGs, ACLs, DHCP relay, management, server uplinks, wireless, firewall and branch connections. Copying a configuration file is not enough when port numbering, optics, software behavior or vendor syntax differs.

2. Build a port-to-business map

Record uplink destinations, speed, copper/fiber media, optic type, trunk VLANs, LAG membership, native VLAN/PVID, critical servers, AP/PoE devices and standby links. Capture SVIs, routes, ARP, DHCP relay, ACL and STP state as well.

3. Preconfigure the replacement offline

Create VLANs, management, trunks, aggregation, STP priorities, routing and required ACLs before connecting production. Test what can be simulated. For cross-vendor migrations, rebuild function by function rather than relying on text conversion.

4. Cut over in dependency order

Back up configuration and status, freeze ad-hoc changes, then migrate uplinks, gateways, servers, access switches, wireless and edge services in a planned sequence. Validate each stage. If critical services cannot be recovered within the window, execute the rollback plan.

5. Acceptance testing goes beyond ping

Validate AD sign-in, DNS, DHCP, ERP/MES, file/print, internet, VPN/branches, VDI, backup, monitoring and management. Compare routing, MAC/ARP, STP, interface errors and link negotiation, then update topology and port records.

Remote or on-site?Logs, configuration, policy review and small-scope validation can often start remotely. Physical hardware, cabling, core-network cutovers, production changes and recovery drills are better scheduled in controlled on-site windows. On-site service is available by project in Zhejiang, Shanghai and Jiangsu; other regions can start remotely.

Frequently asked questions

Does a core-switch replacement always require downtime?

Usually there is a short cutover window, but preconfiguration, staged migration, redundant uplinks or temporary parallel operation can reduce disruption.

Can I import the old configuration if the vendor is the same?

Still verify software versions, port layout, modules, stacking/aggregation and defaults. Cross-model or cross-vendor changes need even more review.

PreviousHow should a factory network be redesigned? Segmenting office, production and server networks with VLANs and firewallsNextWhat is the risk of broad ANY firewall rules, and how can enterprises tighten them without breaking production?

Need an assessment for your actual environment?

Share the current topology, device models, system versions, symptoms, impact, maintenance windows and available configuration/backup information. We can first assess risk, scope and rollback needs, then define remote, on-site or project work.