Clear project context
Document the site type, city, task, access conditions, and the purpose of the onsite visit.
Case Study
Between July and September 2025, GreenITService supported a multi-site Palo Alto firewall refresh across 14 Chinese cities. Sites received one or two PA-440 appliances according to their requirements; locations with two appliances used an active/passive design. Remote engineers migrated the configuration, security policies, and VPN services while onsite engineers supported installation and testing.
Project Context
The customer needed a consistent replacement approach for a distributed office network while keeping remote engineering control and reliable onsite execution at every location.
Delivery Challenge
The project combined hardware replacement with logical service migration and required close coordination between remote and onsite engineering teams.
The firewall refresh covered offices in multiple cities, each with its own access arrangements, equipment location, cabling condition, local contacts, and change window. A replacement shipment alone would not be enough: each site needed physical preparation, controlled installation, remote configuration, and service validation.
The migration scope also included firewall configuration, security policies, and VPN services. The remote engineering team led the logical migration, while onsite engineers provided physical access, checked links and cabling, reported live device status, and supported testing during the change window.
The target hardware quantity was determined by the requirements of each site. Some locations received a single PA-440, while sites requiring redundancy received two PA-440 appliances in an active/passive relationship. Peer connectivity and failover validation therefore applied to the high-availability sites rather than to every location.
Migration Planning
GreenITService coordinated the physical and operational prerequisites before the remote engineering team began migration work.

Remote and Onsite Coordination
The delivery model separated logical migration ownership from physical implementation responsibility while keeping both teams connected throughout the change.
Remote engineers led the configuration migration, security policy migration, and VPN migration. They prepared the target configuration and directed the cutover and validation sequence.
Our onsite engineers installed and connected the PA-440 appliances, checked physical links, provided console or local access when needed, and communicated the live device condition to the remote team. During testing, the onsite team followed the remote instructions and reported the results from the physical site.
This split of responsibilities allowed the customer to retain centralized technical control while still having qualified local support available at each location.
Installation and Testing
Each location followed a repeatable installation and validation sequence for either a single PA-440 or a two-appliance active/passive design.
Service Validation
The team validated both connectivity and resilience before considering each site complete.
Post-migration checks covered appliance reachability, interface and link status, security policy behavior, VPN connectivity, and expected network or application access. The onsite engineer provided local observations while the remote team reviewed the logical state of the migrated configuration.
At sites with two appliances, the active/passive pair was also tested through an actual failover exercise. The team confirmed that the standby PA-440 could take over the active role as expected and recorded the result as part of the site completion evidence. Single-appliance sites followed the applicable connectivity and service validation sequence without an HA failover step.
This approach gave the customer a practical confirmation that the new hardware was installed, the required services were migrated, and the high-availability design worked at locations where redundancy was part of the approved site design.
Project Outcome
The project delivered a consistent firewall refresh model across the full 14-city scope.
Between July and September 2025, PA-220 appliances were replaced with PA-440 deployments sized to each site's requirements. Some locations received one appliance, while sites requiring redundancy received two-appliance active/passive pairs. Remote engineers completed the configuration, security policy, and VPN migrations, while onsite engineers provided installation support, physical checks, live coordination, and failover testing where an HA pair was deployed.
Project Records
Good project records give remote teams a reliable account of the onsite visit while protecting customer information and site confidentiality.
Document the site type, city, task, access conditions, and the purpose of the onsite visit.
Return the useful details from the visit: work completed, photos, serial checks, labels, test notes, and open items.
Provide the agreed ticket notes, report extracts, asset records, WiFi findings, certificates, or sign-off documents.
Customer names, site details, photos, and project outcomes are shared publicly only when approved.
Related Service
Review the onsite work, support options, records, and information to send before a visit.

Smart Hands
When your infrastructure is in China and your team is elsewhere, Smart Hands or Remote Hands provide the local physical execution while your remote team keeps technical control. Our engineering pool includes CCNA, CCNP, and CCIE certified engineers for data center checks, rack and stack, structured cabling, firewall replacement, network cutovers, and clear completion records.
Explore Smart Hands in ChinaRepresentative Media
The image below represents the type of onsite environment and physical work involved. It is not a disclosed customer site image from this project.
FAQ
The deployment used one or two PA-440 appliances depending on the site requirement. Sites with two appliances used an active/passive high-availability pair.
Remote engineers led the firewall configuration, security policy, and VPN migrations. GreenITService onsite engineers supported physical access, installation, live checks, and testing.
Yes. At sites with an active/passive pair, the team completed an actual failover test and recorded the result as part of the site handover evidence.
The customer is confidential. The public case study shows the project scope at city level and excludes office addresses, network diagrams, device serial numbers, and other sensitive records.
Next Step
Smart Hands work should be controlled by a clear checklist, site access plan, device list, remote bridge, and agreed closeout records.