# STEP_036B vpn2/slot202 repair preflight

No remote changes were made.

Goal:
- repair/load vpn2 as slot 2
- create/restore table 202 default via vpn2
- create/restore fwmark rule 0x202 -> table 202
- do not touch legacy table 200
- do not touch existing proven vpn3/vpn4/vpn5 mapper

Possible next actions after this preflight:

A. If UCI network.vpn2 is valid and only link is down:
   - guarded ifup vpn2
   - add runtime-only table202/rule202
   - observe route 0x202 -> vpn2

B. If UCI network.vpn2 is missing/broken but config source exists:
   - use /root/hmn/hmn-load-egress-slot.sh vpn2 <config> load-up
   - add runtime-only table202/rule202

C. If selected vpn2 candidate is bad:
   - choose a replacement candidate from ok-awg1-strict-foreign/all cache
   - load vpn2 with generic loader
   - then table202/rule202

Do not extend selector/multiclass mapper to cs5 until vpn2 route/traffic is proven.
