Troubleshooting & Security

18. Troubleshooting Evidence Package

When troubleshooting connectivity, collect evidence before and after changes. Evidence should be timestamped and tied to the device, VLAN, source IP, destination, and firewall policy involved.

Evidence item Purpose Owner
Firewall rule export Proves policy configuration Firewall engineer
Firewall traffic log Shows allow/deny and rule hit Firewall engineer
DNS lookup output Proves resolution path MSP or network engineer
NTP query output Proves time service availability MSP or network engineer
WAN failover record Proves policy symmetry Network operations
Endpoint inventory Maps device to VLAN, IP, owner, and role Customer IT

19. Security Standards

  • Apply least privilege for outbound access and default deny for lateral movement.

  • Restrict management interfaces to named administration sources.

  • Review firewall rules at launch, after integration changes, and at a defined recurring interval.

  • Log security-relevant events where feasible and retain evidence according to customer policy.

  • Remove temporary implementation rules after acceptance testing.

Change Control

Every production firewall, DNS, NTP, WAN, or segmentation change should include requestor, approver, implementation window, validation evidence, and rollback plan.