How to Configure Router Failover for Uptime

Learn how to configure router failover with wired and cellular connections, health checks and sensible rules to keep critical devices online at work.

7 min read
BackupRouters

How to Configure Router Failover for Uptime

At 06:40 a contractor's digger goes through a fibre duct two streets from a high-street shop. The shop opens at nine. The card terminals have power, the CCTV recorder is running, the alarm panel shows a green light, and none of them can reach anything. The router is working perfectly. It simply has nowhere to send traffic.

A second connection solves this, but only if you configure router failover so it takes over on its own. Failover is not a case of plugging a SIM into a router and assuming it will step in. The router needs to know which connection is preferred, how to recognise a genuine outage, what traffic should move to the backup, and when it is safe to return. Those decisions determine whether failover protects operations or creates intermittent, hard-to-diagnose problems.

What router failover actually does

A failover router uses two or more WAN connections. The primary WAN is usually fixed broadband, fibre, Ethernet hand-off or a dedicated circuit. The secondary WAN is often a cellular failover path on 4G or 5G, although it can also be a second wired connection.

Under normal conditions, traffic uses the primary path. The router continuously checks that path. If the check fails for long enough, it changes the active route and sends new traffic through the backup connection. When the primary service is stable again, the router either switches back automatically or remains on cellular until an administrator decides otherwise.

This is useful because a local router can still be powered on and connected to devices even when the upstream broadband service has failed. A security camera recorder may still be running, but without failover it cannot upload footage, send alerts or be accessed remotely. A payment terminal may have power, but cannot authorise transactions. The backup connection protects the service that depends on internet access.

There is a trade-off. A cellular backup is designed for continuity, not necessarily for matching the speed, latency or data allowance of fibre. Set expectations accordingly, especially where several cameras, guest Wi-Fi users or large cloud synchronisations share the router.

Plan the two connections before changing settings

Start by identifying the priority connection and the backup connection. In a typical installation, WAN 1 is the existing wired service and WAN 2 is a cellular modem or SIM-enabled router interface. Confirm that both can reach the internet independently before enabling failover. Router settings sit inside a wider backup connectivity plan, and they work best when that plan is decided first.

Business router and modem mounted in an open metal cabinet with patch leads and antenna cables

For the mobile connection, check signal quality where the router will actually live, not beside a window during installation. Metal cabinets, plant rooms, vehicles and rural buildings can materially reduce performance. External antennas, correctly positioned and separated where required, can make the difference between an occasional signal and a reliable fallback path.

Also consider the data behaviour of the devices on site. A backup SIM can be consumed quickly by automatic software updates, cloud backups, camera uploads and staff devices reconnecting to Wi-Fi. Decide what must remain online during an outage. A point-of-sale terminal, alarm panel and telemetry controller may be essential; a guest network and non-critical media player may not be.

For sites that cannot tolerate dependence on one mobile carrier, a non-steered multi-network SIM gives the router a broader pool of available networks. That matters in rural locations, moving vehicles and premises where one carrier performs poorly indoors. The SIM attaches to the strongest available supported network rather than holding to a single preferred one.

Configure router failover in the right order

Router menus differ, but the underlying configuration is similar across most business-grade cellular routers. Work through the following settings in sequence rather than changing everything at once.

Set WAN priority

Assign the wired connection as the preferred WAN and cellular as the secondary WAN. Some interfaces call this priority, metric, route distance or link order. The lower route metric is normally preferred, but check the router documentation because terminology varies.

Avoid load balancing unless you have a specific reason to use it. Load balancing shares traffic across both connections, while failover keeps the backup largely idle until it is needed. For a prepaid or usage-controlled mobile plan, straightforward failover is often the safer option because it prevents routine traffic using cellular data.

Behaviour Load Balancing Single-Network Failover Wave Connect Non-Steered
Traffic path when all is well Split across both connections continuously Wired only, mobile sits idle Wired only, mobile sits idle
Response to a primary outage The surviving link absorbs everything at once Switches to one mobile carrier Switches to the strongest available supported network
Mobile data used day to day Constant and hard to forecast Close to nothing until needed Close to nothing until needed
If that site is a weak spot for one carrier Half the traffic suffers all the time The backup is weak exactly when it matters The SIM has other networks to try

Configure meaningful health checks

A router should not treat an active Ethernet port as proof that the internet works. A broadband modem can remain connected while its upstream service, DNS resolution or routing has failed. Configure the router to test an external destination beyond the local modem.

Many routers use ICMP ping by default. That can work, but choose more than one reliable test target where the router supports it. A DNS lookup or HTTP/HTTPS check can add useful context, particularly if the connection is live but name resolution has failed. The goal is to detect a genuine loss of usable connectivity, not a brief delay or one unreachable server.

Set an interval, timeout and failure threshold that fit the site. A very aggressive configuration may switch to mobile data during a momentary packet loss event. A slow configuration may leave a business without service for several minutes. For many installations, checking every few seconds and requiring several consecutive failures is a sensible starting point. Test and adjust based on real behaviour.

Add failback delay and stability rules

Failback is the return from cellular to the primary WAN. Immediate failback sounds efficient, but it can cause flapping when a wired service repeatedly drops and returns. Each switch can interrupt calls, VPN sessions, payment authorisations and live video streams.

Use a recovery threshold or hold-down period so the primary connection must pass health checks consistently before the router moves traffic back. A few stable minutes is often more useful than quicker recovery. On sites with unreliable fixed lines, manual failback may be preferable, as it leaves the known-good cellular path in place until someone verifies the original fault is resolved.

Control backup-data traffic

Create policies for traffic that should be restricted when cellular is active. The exact options depend on the router, but common controls include disabling guest Wi-Fi, blocking operating system updates, limiting cloud backup traffic, reducing camera bitrates, or allowing only selected devices and ports.

Do not block services blindly. A camera system may need specific cloud connectivity to send alarms, while an industrial controller may rely on a VPN tunnel. Review the operational purpose of each device first. A good policy preserves critical traffic while preventing background activity from consuming the entire data allowance.

Account for IP addresses, VPNs and remote access

Failover changes the public-facing connection, so existing sessions will usually drop. This is normal. Web browsing recovers quickly, but a VPN, remote desktop session, live camera feed or payment transaction may need to reconnect.

Inbound access needs particular care. Mobile networks commonly use carrier-grade NAT, meaning the SIM may not receive a publicly reachable IP address. Port forwarding that works on a fixed broadband connection may therefore not work on cellular. For remote management, secure outbound VPN connections, cloud-managed access or a suitable private IP arrangement are generally more dependable than relying on an open inbound port.

If the router maintains a site-to-site VPN, confirm that the tunnel can re-establish over both WANs. Some platforms require separate peer settings, dynamic DNS handling or route rules for each uplink. Test this before deployment, not during the first broadband outage.

Test the failure, not just the configuration

Once the settings are saved, simulate a real outage. Disconnect the primary WAN from the router or disable it in the interface. Check how long it takes for the cellular connection to become active, then verify the services that matter: a transaction test, camera alert, remote access session, telemetry message or VPN tunnel.

External cellular antennas on a pole bracket mounted to a rural building with weatherproofed cable drop

Reconnect the primary WAN and observe failback. Look for repeated switching, unusual data use and devices that fail to reconnect. It is also worth testing during normal operating hours, with the real number of endpoints online. A router may fail over perfectly with a laptop attached yet struggle when a recorder begins uploading high-resolution footage.

Monitor usage and connection events after installation. The most useful evidence is not a green status indicator but a record showing when the primary failed, whether cellular took over, how much data was used and when the primary became stable again. Centralised management makes this practical across multiple sites, especially for installers and fleet operators.

Common failover mistakes to avoid

The most common mistake is treating signal bars as a capacity test. A backup connection may register on a network yet have insufficient throughput for the workload. Test upload as well as download, because cameras, remote monitoring and cloud reporting often depend more heavily on upstream performance.

Another is using only the router's gateway as a health-check target. This detects a local cable or modem issue but may miss a provider-side outage. Equally, using a single distant target can create false failures. Use sensible external checks and thresholds.

Finally, do not forget power resilience. Router failover cannot help when the router, modem, antenna amplifier or local switch has lost power. At critical sites, pair connectivity planning with an appropriately sized UPS and verify that the cellular equipment stays powered during an outage.

Configure router failover as a policy, not a setting

The temptation is to treat failover as a box ticked during installation. It is closer to an operational decision: which services must survive an outage, how much interruption each can absorb, and how much mobile data you are prepared to spend keeping them running. Those answers differ between a shop, a construction compound and a vehicle, and the router settings should follow from them rather than the other way round.

A well-configured backup connection is quiet almost all of the time. That is exactly the point. Wave Connect supplies non-steered multi-network SIMs and centralised usage visibility for this job, so the backup path stays ready and accountable rather than being discovered, unhelpfully, on the morning it is needed.