Get One Month of Starlink FreeSPECIAL OFFER: GET A FREE MONTH OF STARLINK >
Ethernet cables connected to a network switch for a Starlink dual-WAN failover setup

How to Set Up Starlink Automatic Failover With a 4G or 5G Backup

Tips & Tricks

Back to Tips & Tricks

Automatic failover can keep essential internet access available when Starlink is temporarily offline. The usual arrangement is a dual-WAN router with Starlink as the primary connection and a 4G or 5G router as the backup.

This guide is for ordinary outbound internet use: browsing, messaging, work tools and calls. It does not promise that an active call, VPN tunnel or download will survive a WAN change without reconnecting.

Router menus and Starlink hardware vary by model and country. Use the labels in your router's current documentation, and record your original settings before changing bypass mode or cabling.

Decide whether you need automatic failover

Automatic failover is useful when someone needs a connection during a short Starlink interruption and manual hotspot switching is not practical. It adds another router, a mobile plan, configuration and a test routine.

A simple phone hotspot may be enough for one person. Consider dual-WAN failover when several devices need the backup, the connection must be available without finding a phone, or another person needs to activate it without troubleshooting.

Failover is different from bonding. Failover uses one connection at a time and changes the path when the primary fails. Bonding combines connections and needs different equipment or services. Start with failover unless you have a specific reason to bond traffic.

Gather the equipment

You normally need:

  • a Starlink kit with a usable Ethernet path;
  • a 4G or 5G router, hotspot with Ethernet output, or supported tethering method;
  • a dual-WAN router that supports failover;
  • Ethernet cables and suitable power supplies; and
  • an active mobile plan with usable signal at the router location.

Check the cellular router's data allowance, SIM status and tethering rules before relying on it. A coverage map is not a substitute for a test at the actual installation point.

Keep the two internet connections physically separate where practical. If a power cut is part of the risk you are trying to cover, plan backup power for the Starlink equipment, dual-WAN router and mobile router together.

Choose the network layout

The target layout is:

  1. Starlink provides the primary WAN connection.
  2. The mobile router provides the secondary WAN connection.
  3. The dual-WAN router provides one shared home or office LAN.
  4. Phones, computers and other devices connect only to that shared LAN.

Do not connect the LAN ports of the Starlink router and mobile router together. Each service should reach a separate WAN port on the dual-WAN router. A LAN-to-LAN connection can create competing DHCP servers or an accidental network loop.

Option A: Starlink router in normal mode

Connect the Starlink router's Ethernet output to WAN 1 on the dual-WAN router. Connect an Ethernet port on the 4G or 5G router to WAN 2.

This is often the quickest arrangement, but the dual-WAN router may sit behind the Starlink router's local NAT. That extra layer is usually acceptable for normal outbound browsing and calls. It can complicate inbound access, port forwarding and some VPN arrangements.

Option B: Starlink bypass mode

If your Starlink hardware supports bypass mode, the dual-WAN router can become the main router for the local network. Connect the Starlink Ethernet path to WAN 1 and the mobile router to WAN 2, then follow the Starlink and dual-WAN router instructions for bypass mode.

Before changing anything, save or photograph the current settings and make sure you know how to restore the original arrangement. Bypass mode can change which device provides Wi-Fi, DHCP and routing. Do not enable it merely because a setup diagram online uses it; use it when the network design benefits from one router being in charge.

Configure primary and backup WANs

Open the dual-WAN router's Internet, WAN or Multi-WAN settings. The names differ by manufacturer, but the logic is similar:

  1. Set WAN 1 to the Starlink connection.
  2. Set WAN 2 to the 4G or 5G connection.
  3. Choose failover or primary/secondary mode, not load balancing for the first test.
  4. Set the Starlink WAN as the preferred route.
  5. Set the mobile WAN as the backup route.
  6. Leave the LAN DHCP service on the dual-WAN router only.
  7. Save the configuration and wait for both WANs to report their actual status.

If the router asks whether the mobile service is Ethernet, USB tethering or another type, select the method you are actually using. If the backup router has an option for bridge or modem mode, use it only when its documentation confirms that the dual-WAN router can receive the resulting connection. Otherwise, leave the mobile router routing normally and accept the extra NAT layer for outbound use.

For health checks, use the router's built-in method or more than one stable public test target if it allows that choice. A single target can be unavailable even when the internet is usable. The router should declare Starlink failed only after a few failed checks, not after one lost ping, or brief satellite interruptions may cause unnecessary switching.

Check the LAN before testing

From a device connected to the dual-WAN router, confirm:

  • it receives one local IP address from the dual-WAN router;
  • the default gateway is the dual-WAN router;
  • normal browsing works through Starlink;
  • the mobile router is reachable only where the design requires it; and
  • no second router is advertising itself as the LAN gateway.

Do not change port forwarding, remote access or advanced IPv6 settings as part of the first failover test. Get basic outbound connectivity stable first. If remote access is important, review it separately after failover works because the public path and address can change.

Test failover without waiting for an outage

Tell other users before you test. Use one laptop or phone for the first pass and keep the router's status page open if possible.

  1. Confirm that Starlink is the active WAN.
  2. Start a simple task such as loading a page or sending a message.
  3. Disconnect only the Starlink WAN cable from the dual-WAN router, or use the router's documented WAN-disable control.
  4. Wait for the health-check interval and confirm that the mobile WAN becomes active.
  5. Test the tasks that matter: a work site, a short call, a message and any essential dashboard.
  6. Reconnect the Starlink WAN and confirm that it returns as the preferred path.
  7. Repeat the test once later, when you can observe the normal failback behaviour.

The first device may lose an active TCP connection, VPN tunnel or call while the route changes. That is normal for many failover designs. The goal is to restore service quickly, not to guarantee that every session survives.

Record how long detection and failback take, which devices recovered automatically, and whether the mobile data use was reasonable. If the router switches back and forth, increase the failure threshold or recovery delay according to its documentation.

Troubleshoot the common failures

The backup WAN never becomes ready: check the SIM, mobile signal, data allowance, Ethernet link and the mobile router's own internet status. Test the mobile router by connecting one laptop to it directly.

Both WANs work, but the LAN has no internet: check that the dual-WAN router has one active DHCP service, that its default route is automatic, and that the WAN cables are not connected to LAN ports.

Failover causes repeated switching: the health check may be too sensitive, or the Starlink connection may be briefly impaired rather than fully offline. Use a sensible delay and test again.

Remote access stops working: a WAN change can change the public path and address. Starlink CGNAT, mobile-provider NAT and double NAT can all affect inbound access. Use a private mesh VPN or another outbound method when appropriate instead of exposing router administration or cameras to the internet.

Calls still drop: failover cannot guarantee session continuity. Test the call application, VPN and DNS behaviour on the backup path, and keep a manual hotspot option for genuinely urgent work.

Keep a recovery note

Write down the WAN port assignments, router login location, mobile-router admin address, SIM details, bypass-mode status and the steps for returning to the original Starlink-only setup. Store it securely and review it after changing hardware, mobile provider or Starlink equipment.

A dual-WAN setup is successful when another authorised person can understand it, test it and restore the primary connection. If the extra router makes the network harder to support than a tested hotspot, simplify the design.

Related Starlink guides