Network devices such as firewalls, switches and wireless controllers are configured through long lists of settings: addresses, rules, network segments, passwords and more. Those settings are what make the network work, and they often exist only on the device itself. If a change goes wrong, or the device fails, someone has to remember or reconstruct what was there before. Saving a copy of the configuration before every change is one of the cheapest and most valuable habits in IT operations.
Fast rollback. If a change breaks something, you can restore the previous settings in minutes, instead of hours of troubleshooting.
Faster replacement. If a device fails, a saved configuration lets you set up the replacement quickly, often without a long outage.
A record of what changed. Comparing versions shows exactly what is different, which helps find the cause of problems.
Resilience after an incident. If a device is tampered with or reset, a known-good copy is the starting point for recovery.
Support for audits and insurance. Documentation of your configurations and change history helps demonstrate sound practice.
Include any device that carries important settings:
Firewalls and routers.
Core and access switches.
Wireless controllers and access point configurations.
VPN appliances.
Load balancers or other network appliances.
Phone system gateways and other voice equipment.
Printers and similar devices, when settings are complex or hard to recreate.
Also record device details: model, serial number, firmware version, location and purpose. A configuration backup is far less useful if you do not know which device it belongs to.
Make this a standard step in your change process.
Announce and schedule the change. Follow your change management steps, including approval and communication.
Save the current configuration. Use the device's export or backup function, and give the file a clear name that includes the device, date and reason, such as "main-firewall_2026-09-26_before-vpn-change."
Store it somewhere safe and separate. Do not keep the only copy on the device or on a laptop that might be lost. Use a secured location with limited access.
Verify the file. Open it or confirm it is the expected size, since a failed export sometimes produces an empty file.
Make the change. Keep notes of exactly what you did.
Test. Confirm that the change works and that nothing else broke.
Save the new configuration. After a successful change, export the new version as well, so your latest copy is current.
If something goes wrong, you know exactly where to go back to.
A manual routine is a great start, but also consider scheduled automatic backups. Many devices can export their configuration on a schedule to a server, and there are tools that collect configurations from multiple devices, keep versions and highlight differences. Automatic backups catch changes that someone forgot to record, including unplanned ones.
Whatever method you use, test a restore at least once. A backup that has never been restored is an assumption.
Configuration files can contain sensitive information, such as network layouts, shared secrets, passwords or keys. An attacker who obtains them gains a map of your network. Treat them accordingly:
Restrict access to those who need it.
Store them in an encrypted location, and use strong sign-in controls.
Do not email them or leave them in shared folders.
Include them in your regular backup and retention plan.
Remove or rotate credentials if a file is ever exposed.
For each critical device, write a brief document describing how to restore the configuration: where the backup is, how to access the device, which firmware version it should run and who to call. Print a copy and keep it where you can find it if your network and files are unreachable.
Keep a history rather than only the latest file, so you can go back more than one step. Use consistent names, and note what changed in each version. Remove very old copies according to a retention schedule, but keep enough history to cover your typical troubleshooting needs.
Configurations and firmware are linked. A backup from one firmware version may not restore cleanly on another, so record the version alongside each backup, and check vendor guidance before restoring across versions.
UnityCare IT manages network device backups, change records and recovery procedures for healthcare and senior-living organizations. If your firewall or switch configurations are stored only on the devices, we can help you fix that before it matters.
Wi-Fi, switching, firewalls and internet that hold up across a whole facility.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172