Change package
The change package turns findings into changes the client’s engineers can implement through their own change process.
- Least-privilege exceptions for the flows production actually uses; logged drops for everything else.
- Rules repeated across plants handled once, with each plant’s own addressing.
- For each change: risk assessment, CLI, web steps, pre-checks, verification and rollback.
- Global changes go to a pilot plant first.
The CLI is a suggestion and can disable production rules. Stage it in a lab or non-production device-group and follow your change advisory process. After the change, load the next traffic log to verify each plan.