I like the way you are approaching this option, but I would change the methodology slightly: 1) configure the new ports on the switch in your VLAN and wire it to the new ports on the firewalls (with the switchports SHUT) 2) setup the new FW ports as just standard members of the VLAN (untagged or access-port depending on your terminology) and push policy 3) when the maintenance window begins, SHUT the VLAN Trunk Interface on the switch, NO SHUT the standard access ports 4) once you verify everything is functioning, remove the VLAN from the trunk ports on the switch 5) once you verify everything is functioning, remove the VLAN tagging from the FW ports and push policy The roll back is a quick - SHUT of the new ports and NO SHUT of the old ports. Very similar process to Joe, but slightly different focus.
... View more