T The Triage ManualTechnical Guides for IT Emergencies
P1 · Network Infrastructure

Firewall / network change broke connectivity

Recent firewall or network change has caused an outage. Roll back fast, then diagnose what was wrong about the change.

Indicators

Likely causes

Diagnostic steps

  1. Confirm change happened — review change log, ask who touched what
  2. Have a tested rollback before any further change. On Fortinet: execute backup config / restore. On SonicWall: import previous .exp. On Meraki: there is no rollback — use config-versioning or revert via dashboard history
  3. If rollback restores service: diff the configs to identify the bad delta
  4. If rollback isn't safe: identify the failing flow by packet capture from each side, compare to policy
  5. Apply minimal corrected change, test, document

Resolution path

Prevention

Tools

References

firewallchangerollbackconfignetwork