Case Study

Multi-Site Palo Alto Firewall Refresh Across China

Between July and September 2025, GreenITService supported a multi-site Palo Alto firewall refresh across 14 Chinese cities. Sites received one or two PA-440 appliances according to their requirements; locations with two appliances used an active/passive design. Remote engineers migrated the configuration, security policies, and VPN services while onsite engineers supported installation and testing.

14 cities across ChinaInfrastructure Hands / Network DeploymentTechnology Distribution
Representative network rack environment for a multi-site firewall refresh
Project location14 cities across China
Onsite scopeInfrastructure Hands / Network Deployment
Delivered evidenceSite and city deployment references

Project Context

A coordinated firewall refresh across 14 China cities

The customer needed a consistent replacement approach for a distributed office network while keeping remote engineering control and reliable onsite execution at every location.

  • Customer: A confidential global technology distribution company
  • Project period: July-September 2025
  • Coverage: Beijing, Chengdu, Dalian, Guangzhou, Hangzhou, Nanjing, Shanghai, Shenyang, Shenzhen, Suzhou, Tianjin, Wuhan, Xi'an, and Zhuhai
  • Existing platform: Palo Alto PA-220
  • Target platform: One or two Palo Alto PA-440 appliances per site, based on site requirements
  • High availability: Active/passive pair at sites where two appliances were required

Delivery Challenge

One migration plan, many different site conditions

The project combined hardware replacement with logical service migration and required close coordination between remote and onsite engineering teams.

The firewall refresh covered offices in multiple cities, each with its own access arrangements, equipment location, cabling condition, local contacts, and change window. A replacement shipment alone would not be enough: each site needed physical preparation, controlled installation, remote configuration, and service validation.

The migration scope also included firewall configuration, security policies, and VPN services. The remote engineering team led the logical migration, while onsite engineers provided physical access, checked links and cabling, reported live device status, and supported testing during the change window.

The target hardware quantity was determined by the requirements of each site. Some locations received a single PA-440, while sites requiring redundancy received two PA-440 appliances in an active/passive relationship. Peer connectivity and failover validation therefore applied to the high-availability sites rather than to every location.

Migration Planning

Preparing each site for a controlled cutover

GreenITService coordinated the physical and operational prerequisites before the remote engineering team began migration work.

  1. Confirmed the city-level site register, local contacts, access requirements, and approved change window
  2. Prepared rack or cabinet space, power availability, network cabling, and console or remote-access requirements
  3. Verified the target PA-440 quantity for each location and identified sites requiring an active/passive pair
  4. Aligned the physical installation sequence with the remote configuration and migration plan
  5. Prepared a validation and rollback checklist for the change window
  6. Recorded site-specific prerequisites and open items before equipment installation
Representative field engineer working in a network rack environment
Representative network infrastructure image. Customer-specific equipment photos and network details are not disclosed publicly.

Remote and Onsite Coordination

Remote migration expertise supported by local hands

The delivery model separated logical migration ownership from physical implementation responsibility while keeping both teams connected throughout the change.

Remote engineers led the configuration migration, security policy migration, and VPN migration. They prepared the target configuration and directed the cutover and validation sequence.

Our onsite engineers installed and connected the PA-440 appliances, checked physical links, provided console or local access when needed, and communicated the live device condition to the remote team. During testing, the onsite team followed the remote instructions and reported the results from the physical site.

This split of responsibilities allowed the customer to retain centralized technical control while still having qualified local support available at each location.

Installation and Testing

Installing and validating the PA-440 deployments

Each location followed a repeatable installation and validation sequence for either a single PA-440 or a two-appliance active/passive design.

  1. Installed one or two PA-440 appliances at the approved site location according to the site requirement
  2. Connected power, management, and network links, plus peer links where a second appliance was deployed
  3. Verified interface status, cabling, device reachability, and peer connectivity
  4. Supported remote migration of firewall configuration, security policies, and VPN services
  5. Validated expected network and application access after cutover
  6. Completed an actual active/passive failover test at sites with a high-availability pair
  7. Recorded test results, open items, and completion evidence for handover

Service Validation

Testing the services that matter after migration

The team validated both connectivity and resilience before considering each site complete.

Post-migration checks covered appliance reachability, interface and link status, security policy behavior, VPN connectivity, and expected network or application access. The onsite engineer provided local observations while the remote team reviewed the logical state of the migrated configuration.

At sites with two appliances, the active/passive pair was also tested through an actual failover exercise. The team confirmed that the standby PA-440 could take over the active role as expected and recorded the result as part of the site completion evidence. Single-appliance sites followed the applicable connectivity and service validation sequence without an HA failover step.

This approach gave the customer a practical confirmation that the new hardware was installed, the required services were migrated, and the high-availability design worked at locations where redundancy was part of the approved site design.

Project Outcome

A repeatable target design for the China office network

The project delivered a consistent firewall refresh model across the full 14-city scope.

Between July and September 2025, PA-220 appliances were replaced with PA-440 deployments sized to each site's requirements. Some locations received one appliance, while sites requiring redundancy received two-appliance active/passive pairs. Remote engineers completed the configuration, security policy, and VPN migrations, while onsite engineers provided installation support, physical checks, live coordination, and failover testing where an HA pair was deployed.

  • Site and city deployment references
  • PA-440 appliance records and active/passive pair records where applicable
  • Configuration, security policy, and VPN migration validation
  • Physical installation and connectivity checks
  • Actual failover test results for sites with an active/passive pair
  • Completion notes and follow-up records

Project Records

What well-documented onsite work includes

Good project records give remote teams a reliable account of the onsite visit while protecting customer information and site confidentiality.

Clear project context

Document the site type, city, task, access conditions, and the purpose of the onsite visit.

Onsite confirmation

Return the useful details from the visit: work completed, photos, serial checks, labels, test notes, and open items.

Completion records

Provide the agreed ticket notes, report extracts, asset records, WiFi findings, certificates, or sign-off documents.

Customer confidentiality

Customer names, site details, photos, and project outcomes are shared publicly only when approved.

Related Service

Related onsite service

Review the onsite work, support options, records, and information to send before a visit.

China field engineer working on rack cabling and network equipment

Smart Hands

Smart Hands and Network Migration Support in China

When your infrastructure is in China and your team is elsewhere, Smart Hands or Remote Hands provide the local physical execution while your remote team keeps technical control. Our engineering pool includes CCNA, CCNP, and CCIE certified engineers for data center checks, rack and stack, structured cabling, firewall replacement, network cutovers, and clear completion records.

Explore Smart Hands in China

FAQ

Questions about this firewall refresh model

How many PA-440 appliances were deployed at each site?

The deployment used one or two PA-440 appliances depending on the site requirement. Sites with two appliances used an active/passive high-availability pair.

Who completed the configuration and policy migration?

Remote engineers led the firewall configuration, security policy, and VPN migrations. GreenITService onsite engineers supported physical access, installation, live checks, and testing.

Was failover testing completed?

Yes. At sites with an active/passive pair, the team completed an actual failover test and recorded the result as part of the site handover evidence.

Why are the customer and detailed addresses not shown?

The customer is confidential. The public case study shows the project scope at city level and excludes office addresses, network diagrams, device serial numbers, and other sensitive records.

Next Step

Send the work order or Smart Hands checklist

Smart Hands work should be controlled by a clear checklist, site access plan, device list, remote bridge, and agreed closeout records.

  • Rack, room, device, port, serial, and cable details
  • Maintenance window, remote bridge, and authorization steps
  • Photo, label, test, and completion-record requirements