--- title: "Configuring a Redundant WAN Connection - icom OS Routers" slug: "configuring-a-redundant-wan-connection-en" updated: 2026-08-06T14:07:40Z published: 2026-08-06T14:07:40Z canonical: "docs.insys-icom.com/configuring-a-redundant-wan-connection-en" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.insys-icom.com/llms.txt > Use this file to discover all available pages before exploring further. # Configuring a Redundant WAN Connection - icom OS Routers Various routers of INSYS icom provide the option to set up a redundant WAN connection (secondary or fallback connection) to increase the availability. This Configuration Guide shows how to configure a redundant WAN connection. ## Situation An INSYS router has a primary WAN connection over Ethernet, for example to an Internet router. It is necessary to configure a secondary WAN connection that can be used in case the primary WAN connection fails. This can be realised using the connection check function. ## Solution It is prerequisite that you have access to the web interface of the router and the router has been commissioned for Internet access via WAN over Ethernet using the Startup Wizard. The Startup Wizard configures a WAN interface and a local LAN network for your router. You’ll now add an additional Internet connection (secondary WAN connection) and configure the connection check of the primary WAN connection. A WAN chain defines a WAN connection. It is the sequential arrangement of interfaces that defines the establishment of a WAN connection. > [!NOTE] > Please note! > > Depending on the router, a wide variety of combinations of primary and secondary WAN connections are possible, including connections to alternative cellular providers or [satellite connections](/kb/docs/configuring-a-redundant-satellite-connection-en) in the event of a failure of the primary WAN connection—for example, due to a provider failure. The configuration is similar to the example configuration described in this Configuration Guide, which uses a **primary Ethernet connection** and a **secondary cellular connection**. > > Our versatile routers and the wide selection of plug-in cards for modular routers enable the following **redundancy combinations**, **among others**: > > | Primary WAN connection | Secondary WAN connection | Supported by | > | --- | --- | --- | > | Ethernet | Cellular | MOROS.neo-E.4G, MOROS.neo-EW.4G, MIRO, ECR-L, SCR-L, MRX.neo and MRX with MRcards MSI.5G, MSI.4G, PL, PLS, PL450 or PL450D | > | DSL | Cellular | MRX.neo and MRX with MRcard PD + MRcard MSI.5G, MSI.4G, PL, PLS, PL450 or PL450D | > | Cellular SIM1 | Cellular SIM2 | MOROS.neo-E.4G, MOROS.neo-EW.4G, ECR-L, SCR-L, MRX.neo and MRX with MRcards MSI.5G, MSI.4G or two of the MRcards PL, PLS, PL450 or PL450D Only [DSSS](/kb/docs/dual-sim-dsss-what-does-dual-sim-mean-and-why-can-only-one-sim-be-online-one-tim) with MRcard MSI.5G and MSI.4G | > | Glass fiber | Cellular | MRX.neo and MRX with MRcard Fiber + MRcard MSI.5G, MSI.4G, PL, PLS, PL450 or PL450D | > [!NOTE] > Please note for possible differences in the naming of the cellular interface! > > The cellular interfaces have been renamed from `lteX` to `cellularX` with version **icom OS 10.0**. Depending on the version, the following description may therefore differ from your router. For security reasons, we recommend that [you regularly update your router](/kb/docs/updating-a-router-manually-en) to the latest version anyway. See [FAQ](/kb/docs/how-does-the-renaming-of-the-cellular-interface-from-ltex-to-cellularx-affect-my) for more information. 1. Open the user interface of the router: [https://insys.icom](https://insys.icom) 2. Click on behind the LTE interface *lte2* on the *Network* → *Interfaces* page to edit this LTE interface. ![cg en m3 redundant wan connection v2 01](https://docs.insys-icom.de/assets/cg_en_m3_redundant_wan_connection_v2_01.png) 3. Enter a *Description* and the *APN* of your provider. 4. Click on SUBMIT. 5. Click on on the *Network* → *WAN / Internet* page to add a new WAN chain and enter a *Description*. ![cg en m3 redundant wan connection v2 02](https://docs.insys-icom.de/assets/cg_en_m3_redundant_wan_connection_v2_02.png) 6. Check the option *Limit lifetime*, enter a lifetime for this WAN chain and select under *WAN chain upon expiry* **wan1** as WAN chain. > [!NOTE] > Please note! > > The WAN chain for the redundant connection to the secondary instance will be disconnected after the lifetime has expired and the WAN chain **wan1** will be started, which is used to establish the connection to the normal WAN connection. 7. Click in the *Interfaces in WAN chain* section on and add above added LTE interface. 8. Click on *MORE* at the bottom of *Interfaces in WAN chain* and select the WAN chain **wan1** under *Failure WAN chain*. 9. Select under *Connection check type* **Ping**, enter under *Ping to* e. g. **www.insys-icom.com** and enter a *Connection check interval*. 10. Click on SUBMIT. 11. Click on behind the WAN chain *wan1* on the *Network* → *WAN / Internet* page to edit this. ![cg en m3 redundant wan connection v2 03](https://docs.insys-icom.de/assets/cg_en_m3_redundant_wan_connection_v2_03.png) 12. Click on *MORE* at the bottom of *Interfaces in WAN chain* and select the WAN chain **wan2** under *Failure WAN chain*. 13. Select under *Connection check type* **Ping**, enter under *Ping to* e. g. **www.insys-icom.com** and enter a *Connection check interval*. 14. Click on SUBMIT. 15. Click on the *Network* → *Firewall / NAT* page in the *IP filter* section on behind the OUTPUT rule *[Startup] DNS queries sent by the router - udp* and add above added LTE interface under *Output interface*. ![cg en m3 redundant wan connection v2 04](https://docs.insys-icom.de/assets/cg_en_m3_redundant_wan_connection_v2_04.png) 16. Click on SUBMIT. 17. Add the LTE interface to the output interfaces in the same way for the filter rules *[Startup] DNS queries sent by the router - tcp*, *[Startup] NTP queries sent by the router* and *[Startup] Traffic from local net into the WAN*, for which the interface *net3* is also specified as the output interface. ![cg en m3 redundant wan connection v2 05](https://docs.insys-icom.de/assets/cg_en_m3_redundant_wan_connection_v2_05.png) 18. Click on the *Network* → *Firewall / NAT* page in the the *Source NAT* section on behind the Masquerade rule *[Startup] Masquerading for WAN interface* and add above added LTE interface under *Output interface*. ![cg en m3 redundant wan connection v2 06](https://docs.insys-icom.de/assets/cg_en_m3_redundant_wan_connection_v2_06.png) 19. Click on SUBMIT. 20. Click on on the *Network* → *Routing* page in the *Static routes* section to add a new static route and enter a *Description*: ![cg en m3 redundant wan connection v2 07](https://docs.insys-icom.de/assets/cg_en_m3_redundant_wan_connection_v2_07.png) 21. Select the LTE interface **lte2** specified above under *Interface* and **Default route** as *Route type*. 22. Select **dynamic - use received IP address** under *Gateway*. 23. Click on SUBMIT. 24. Activate the profile with a click on ACTIVATE PROFILE . ## Result testing 1. Open the ![view dashboard outline](https://docs.insys-icom.de/assets/icons/view-dashboard-outline.png) *Status* → *Dashboard* page and observe the establishment of the WAN chain in the *WAN chain* section. 2. Disconnect the Ethernet cable used for the Internet connection in port 5 and wait for the connection check interval to verify that the WAN connection changes to the redundant WAN connection. 3. Reconnect the Ethernet cable to verify that the WAN connection changes back to the normal WAN connection after the lifetime of the redundant WAN connection has expired. ## Troubleshooting - You can temporarily disable the IP filters for IPv4 on the *Network* → *Firewall / NAT* page in the *Settings IP filter* section to find out if incorrect filter settings are the cause of problems. - Observe on the ![view dashboard outline](https://docs.insys-icom.de/assets/icons/view-dashboard-outline.png) *Status* → *Log view* page which process might fail. Standard IP address: https://192.168.1.1; login depending on configuration; default for earlier firmware versions: *User name*: **insys**, *Password*: **icom** ## Related - [Configuring a Redundant Satellite Connection - icom OS Routers](/configuring-a-redundant-satellite-connection-en.md)