Engineering Note · EN-003

Performance wasn't the problem

A switching refresh was proposed. Packet analysis showed the hardware was not the constraint.

5 min read
Challenge
Poor application performance
Assumption
Ageing access switches were the bottleneck
Decision
Validate the traffic path before replacing hardware
Outcome
Performance restored without a switching refresh

A client was experiencing poor application performance and a six-figure switching refresh was being discussed. The explanation sounded plausible: the access layer was ageing, users were reporting delays and the network was the most visible common dependency.

We started by validating the assumption rather than accepting it. The switches still had useful support life remaining, observed utilisation did not indicate exhaustion and there was no evidence that the hardware itself was unable to meet the requirement.

Packet analysis exposed the real constraint. During the original deployment, a third-party services partner had applied a generic Cisco baseline configuration and presented it as security hardening. The client had purchased and signed off that work in good faith.

The baseline did include security controls, but it also carried highly restrictive Quality of Service settings that unnecessarily constrained application traffic. The incumbent partner had copied a template it did not fully understand, and the configuration had remained accepted because nobody had revisited the assumptions behind it.

The hardware was performing exactly as configured. Replacing it would have consumed budget, introduced disruption and reproduced the same problem if the inherited configuration had followed the new estate.

We corrected the policy, validated the traffic path and confirmed the application response. Performance returned without replacing infrastructure that was already capable of meeting the requirement.

Correcting the configuration was straightforward once the cause was known. The real value was avoiding a six-figure refresh that would have disrupted the business without solving the problem.

Engineering lessons

  • A security baseline is only valuable when its wider operational effect is understood.
  • Third-party deployment work still requires independent validation.
  • Packet analysis can prevent an expensive refresh from solving the wrong problem.

Read the engineering principles behind this work →

Confidentiality: Engineering Notes are based on real engagements. Client identities, timelines and identifying details may be changed to protect confidentiality. The engineering decisions and lessons remain representative of the work undertaken.