Troubleshooting & Security
18. Troubleshooting Evidence Package
When troubleshooting connectivity, collect evidence before and after changes. Evidence should be timestamped and tied to the device, VLAN, source IP, destination, and firewall policy involved.
| Evidence item | Purpose | Owner |
|---|---|---|
| Firewall rule export | Proves policy configuration | Firewall engineer |
| Firewall traffic log | Shows allow/deny and rule hit | Firewall engineer |
| DNS lookup output | Proves resolution path | MSP or network engineer |
| NTP query output | Proves time service availability | MSP or network engineer |
| WAN failover record | Proves policy symmetry | Network operations |
| Endpoint inventory | Maps device to VLAN, IP, owner, and role | Customer IT |
19. Security Standards
-
Apply least privilege for outbound access and default deny for lateral movement.
-
Restrict management interfaces to named administration sources.
-
Review firewall rules at launch, after integration changes, and at a defined recurring interval.
-
Log security-relevant events where feasible and retain evidence according to customer policy.
-
Remove temporary implementation rules after acceptance testing.
Change Control
Every production firewall, DNS, NTP, WAN, or segmentation change should include requestor, approver, implementation window, validation evidence, and rollback plan.