A wireless refresh does not fail on the day you buy the gear. It fails on the day you cut over. I have walked into too many sites where the new access points were mounted and configured, yet users still lost sessions. Therefore the cutover deserves as much planning as the design. Below is how I plan a wireless cutover so the network stays up while the old gear comes down.
Map every SSID to a VLAN before you touch anything
First, build a table of every SSID, the VLAN it rides on, and the subnet behind it. Do this for the old network and the new one side by side. Additionally, mark which SSIDs must stay live during the transition, such as the production network your handheld scanners depend on. In practice, most outages I trace back to a cutover come from an SSID that pointed at the wrong VLAN. As a result, clients associated fine but passed no traffic. Notably, a device showing full signal and zero throughput is almost always a VLAN or DHCP mismatch, not an RF problem. Therefore confirm the mapping on paper before anyone climbs a ladder.
Decommission the old radios, do not just unplug them
Decommissioning is not “pull it later.” I have seen a single forgotten access point take down a floor. Specifically, an old radio left powered on a live switch port kept broadcasting the production SSID while stranded on a dead VLAN. Consequently, devices roamed onto it, hit a dead end, and dropped. For this reason, treat every old radio as a live threat until you prove it is dark. Confirm the port is shut, the power is off, and the SSID is gone from a scan. In addition, keep a running list and check off each unit physically. Meanwhile, do not trust the controller to tell you a rogue is gone. Walk the floor with a scanner and verify.
Cut over in phases and validate as you go
Never flip the whole site in one night. Instead, cut over one zone at a time and prove it before you move on. Generally I start with a low risk area, bring up the new access points, and test roaming, throughput, and authentication with a real client. Furthermore, I test the actual devices that live in that space. A laptop passing traffic tells you little about a handheld scanner or a VoIP phone. For example, older clients often cannot see DFS or 6 GHz channels, so they will not roam onto them at all. In that case the coverage you planned never reaches the device. Subsequently, once a zone passes, I document the result and move to the next one. This way a problem stays contained to one area instead of spreading across the building.
Keep a rollback path open
Every phase needs a way back. Before you cut a zone, know exactly how to restore the old path if the new one fails. Moreover, do the work during a real maintenance window and tell the client when it is happening. That said, a rollback is only useful if the old gear is still reachable, so do not decommission a zone until the new one has passed its tests. Ultimately, the goal is simple. No user should lose more than a few minutes, and no one should lose data mid task.
Validate the whole site before you call it done
A cutover is not finished when the last access point comes online. Finally, walk the full site with a survey tool and confirm coverage, roaming, and signal to noise across every zone. Similarly, check that no old SSID still lingers and that every VLAN maps where it should. In fact, this final pass is where I catch the leftover radio nobody remembered. Overall, a clean cutover is boring by design. Nothing dramatic happens because you removed the surprises ahead of time.
At Baiden Group, this is the work we do every week. We design wireless networks, run RF site surveys, plan and validate cutovers, and troubleshoot the ones that went sideways. Whether you are refreshing a warehouse, a hospital, or a campus, we can help you move to new gear without taking your users down. Have questions about how these developments affect your network? Reach out to the Baiden Group team.
