Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What should I consider with a network appliance?

A router, firewall, switch or gateway may hold volatile connection and security evidence while controlling access for an entire site or service.

Preserve role, state and connections

Photograph the appliance, rack position, displays, lights, labels, serials, ports and cables. Record any visible clock, uptime, interface, connection count, alarm or warning.

Identify its likely function and the systems connected to it. A single cable can support many users, security controls or other evidential sources. Do not disconnect it solely to isolate the device in front of you.

Restart or reset can clear connection tables, temporary configuration and logs. Logging into a management interface adds authentication and navigation events and can accidentally change configuration.

Live network evidence decays quickly

Active sessions, routing state and alerts may be short-lived, particularly during a cyber incident. Engage network, incident-response or forensic specialists promptly so capture and containment can be coordinated.

Where immediate isolation is necessary, record the original state and use the narrowest effective action. Attribute every login, command, cable change and restart. The review-required smart and embedded device guidance follows a separate device-role boundary and must not be treated as an automatic extension of network-appliance handling.

Key takeaway

Preserve a network appliance's volatile state and wider service role before any login, reset or disconnection changes both the evidence and the network.

Reference: FRP-040First Response & Preservation