Independent · not affiliated with SpaceX or StarlinkReport: logger not startedFacts checked

Blog · Backup & failover

What automatic failover does in the seconds after an outage

A dual-WAN router doesn’t make an outage invisible. It turns a long outage into a short one. Here is what happens in each second, and which parts of your workday notice.

Research-based, not measured by us

Status card for automatic failover: the router detects the outage in seconds, new connections use the backup line, existing calls and VPN sessions reconnect, and failback causes one more blip.

Key takeaways

  • Failover has three phases: the router notices the main line stopped answering, marks it down, and sends new connections out the backup line.
  • Detection is not instant. Routers test the line on a schedule and wait for several failures in a row, so expect seconds of silence before the switch.
  • Your backup line has a different public IP, so existing connections can’t move. Calls and VPNs reconnect; web pages and email just carry on.
  • Only bonding or tunnel services that keep one outside IP (for example Peplink’s SpeedFusion) can carry a session across the switch, at extra cost and complexity.
  • Failback, when the main line returns, is a second switch. Many routers let you delay it so you aren’t knocked off twice.
On this page
  1. The short version: what each part of your day notices
  2. Second by second: what the router does
  3. What can keep a session alive across the switch
  4. Starlink-specific notes
  5. Failover or load balancing?
  6. Test it in ten minutes
  7. Common mistakes
  8. When failover isn’t worth it
  9. What we don’t know
  10. What to do next
  11. Questions people ask
  12. Sources

Automatic failover switches you to a backup line within seconds of an outage, but it doesn’t make the outage invisible. The router first has to notice that the main line stopped answering, then it sends new traffic out the backup. Because the backup line has a different public IP address, connections that were already open, like a video call or a VPN tunnel, break and reconnect. Web browsing and email barely notice. A call or VPN sees a few seconds of “reconnecting” instead of a long outage, which for most remote workers is the whole point.

The short version: what each part of your day notices

Activity During a failover Why
Web pages, email, chat A short pause; the next click works Each request opens fresh connections on the new line
Zoom, Teams, Meet calls Freezes, shows “reconnecting,” rejoins The call’s media path was tied to the old address
Work VPN Drops and reconnects The tunnel was built on the old line’s address
Large uploads and downloads May fail and need resuming A long transfer is one connection that can’t move
Remote desktop, SSH Disconnects; reconnect by hand or automatically Same reason
Things on your home network (printer, NAS) Unaffected They don’t use the internet line

The reason sits in how the internet identifies a connection. The TCP standard defines a connection by “a pair of sockets”: your IP address and port plus the far end’s IP and port. When your public address changes, the far end sees packets from a stranger. Nothing can quietly move an open connection to a new address unless something in the middle keeps the outside address the same (more on that below).

Second by second: what the router does

Times below are illustrative. Every brand’s defaults differ, and most let you change them.

Illustrative timeline: main line stops at 0 seconds, health checks fail over the next seconds, the router marks it down and switches new connections to the backup, apps reconnect, and later the main line recovers and the router fails back.
Most of the gap is the router making sure the line is really down, not the switch itself.

1. The outage starts

Your main line (here, Starlink) stops passing traffic. Your computer doesn’t know yet. Calls freeze, pages hang.

2. Health checks fail

A dual-WAN router tests each line on a schedule. GL.iNet, for example, uses “ping or httping” to track the connection to a destination IP and offers normal, low-data and strict detection modes. TP-Link’s Omada ER605 lists “Online Detection.” Peplink lists “Link Health Check.” The router won’t switch on one missed reply, because one lost ping happens on healthy lines too. It waits for several failures in a row.

That is the trade-off you control: check often and switch after few failures, and you switch fast but may flap between lines during a brief blip. Check rarely and require many failures, and you switch late but rarely by mistake.

Worked example (illustrative settings): if the router checks every 5 seconds and needs 3 failures in a row, the line is marked down 10 to 15 seconds after it actually failed. Halve the interval and you roughly halve the wait.

3. The router marks the line down and switches

New connections now leave through the backup line (a cellular router, a hotspot on the second WAN port, or another wired line). They get the backup line’s public address.

4. Apps reconnect

Browsers simply retry. Meeting apps detect the dead path and rejoin, which you see as a few seconds of frozen video and a “reconnecting” banner. Your VPN client notices its tunnel stopped answering and builds a new one. How quickly depends on the client’s own timers; see why VPNs drop about once an hour for how those timers work.

5. Failback

When the main line answers health checks again, most routers switch back automatically. GL.iNet’s documentation says the router “switches back automatically” when a higher-priority link is restored. That is a second switch, and your calls and VPN reconnect a second time. If your main line is the kind that drops repeatedly for short spells, consider delaying failback or requiring the line to be healthy for a few minutes first, if your router allows it.

What can keep a session alive across the switch

To survive a line change, the outside world must keep seeing the same address. Two ways do that:

  • Bonding or tunnel services. Your router builds tunnels over both lines to a server or peer device, and your traffic leaves the internet from that server’s address. If one line dies, the tunnel carries on over the other. Peplink lists “Session Persistence” and describes SpeedFusion as providing “fault-tolerant high speed Internet access” by combining connections. This costs more (hardware, and often a hosted endpoint) and adds latency because traffic detours through the endpoint.
  • Apps with their own reconnection tricks. Some modern VPNs and meeting apps resume quickly on a new address. They still pause; they just recover faster.

For most home workers, a plain dual-WAN router plus apps that reconnect is the right level. Bonding is worth pricing if you run all-day customer calls and even a 10-second drop is costly.

Comparison of three setups: manual hotspot switch takes minutes, plain dual-WAN failover reconnects calls in seconds, and bonding or a tunnel service can keep the session with one outside address.
Each step up costs more and saves a few more seconds.
  • Where the dual-WAN router plugs in. Your own router connects to the Starlink router’s LAN port, or to the Starlink with its router in bypass mode. Bypass mode (Starlink app > Settings) turns off the Starlink router's Wi-Fi so a third-party router can connect; exit by factory reset. Starlink does not guarantee performance with third-party routers; some app features may not work.
  • Ports. 2 ports The older Gen 2 router has no built-in Ethernet ports; an Ethernet adapter is sold separately.
  • Your public IP changes on failover either way. Starlink Residential IPv4 is behind CGNAT, and your cellular backup almost certainly is too, so neither address was yours alone. That matters if your employer allowlists IP addresses; ask IT before you rely on a backup line.
  • Health check targets. Point checks at a reliable outside address (not the Starlink router itself, which may still answer while the satellite link is down).

Failover or load balancing?

Most dual-WAN routers offer two modes, and they behave very differently for work.

Failover keeps the backup line idle until the main line fails. All your traffic leaves from one address at a time. That is predictable: your VPN, your bank and your employer’s systems see one address, and calls stay on one path. The cost is that the backup line’s capacity sits unused most of the time, which is fine for a cellular plan you pay for by the gigabyte or by the hour.

Load balancing uses both lines at once and spreads connections across them. GL.iNet’s documentation describes load ratios such as 1:1, and notes that live connections “are not ensured to match the load ratio.” That can raise total speed for many downloads at once, but individual sessions can land on different lines. Some websites and VPNs dislike seeing one user arrive from two addresses, and a metered backup line gets used every day.

For a remote worker, failover is usually the right default. If you want to use both lines, a middle ground is to load balance only for devices that don’t matter (a game console’s downloads, a TV) and pin the work computer to the main line.

Test it in ten minutes

Do this once after setup and then monthly, during a quiet hour.

  1. Start a continuous ping to a public address on your work computer (ping -t 1.1.1.1 on Windows).
  2. Join a test meeting by yourself, and connect the VPN if you use one.
  3. Unplug the main line’s cable at the dual-WAN router (don’t unplug the dish; you are testing the router, not stressing the kit).
  4. Count the seconds of failed pings until replies return. That is your real detection-plus-switch time.
  5. Watch the meeting rejoin and the VPN reconnect, and note how long each took.
  6. Plug the main line back in and watch failback. Count the seconds again.
  7. Check that the router’s notification (if it has one) told you it switched. If your backup is metered, you want to know when you’re on it.

Write the numbers down. If detection takes far longer than you expected, shorten the check interval or the failure count, and test again.

Common mistakes

  • Expecting zero downtime. A plain dual-WAN router shortens outages; it doesn’t erase them.
  • Load balancing calls across two lines. Spreading connections can send parts of one session over different lines and confuse VPNs and some websites. Use failover mode for work, or pin the work computer to the main line.
  • Never testing it. Unplug the main line once a month during a quiet hour and watch what happens.
  • A backup that shares the same weak point. A cellular router plugged into the same power strip as the dish fails in the same power cut. Power backup sizing is outside this site’s scope, but plan it.

When failover isn’t worth it

If outages at your house are rare and a phone hotspot covers you in two minutes, a manual switch may be enough. If your work can pause for a few minutes without harm, skip the router. If your job is customer-facing calls all day, failover is close to essential, and fiber or cable as the main line is better still. The backup risk check helps you decide.

What we don’t know

We haven’t timed failover on specific routers over a Starlink line, and default check intervals vary by brand and firmware. The 10-to-15-second example above is arithmetic on illustrative settings, not a measurement. The Work-Day Reliability Report will show how often a logged connection has outages long enough to trigger failover once data exists.

What to do next

Questions people ask

How fast is automatic internet failover?

It depends on how often the router checks the line and how many failed checks it needs before switching. Settings vary by brand; with typical setups, expect several seconds to under a minute rather than an instant switch.

Will my Zoom or Teams call survive a failover?

Usually the call drops for a few seconds and reconnects by itself, because your traffic suddenly comes from a different public IP. Meeting apps are built to rejoin; you may see a reconnecting message.

Will my VPN stay connected when the router switches lines?

Usually not. The VPN tunnel was built on the old line’s address, so it has to reconnect on the new one. Most clients do that automatically within seconds to a minute.

What is the difference between failover and load balancing?

Failover keeps the backup idle until the main line fails. Load balancing uses both lines at once and spreads connections across them. For calls and VPNs, failover is usually the calmer choice.

Can a dual-WAN router keep a call alive during an outage?

Only with a bonding or tunnel service that gives your traffic one stable outside address, such as Peplink SpeedFusion with a peer or cloud endpoint. A plain dual-WAN router reconnects calls rather than keeping them.

Do I need bypass mode on Starlink to use a dual-WAN router?

Not necessarily, but many people use it so only one router does address translation. Starlink notes it doesn’t guarantee performance with third-party routers and some app features may not work.

Sources

  1. What is bypass mode? (Starlink support), checked Oct 5, 2026
  2. Can I add a third-party router or mesh system? (Starlink support), checked Oct 5, 2026
  3. Does the WiFi router have any ethernet (LAN) ports to connect wired devices? (Starlink support), checked Oct 5, 2026
  4. GL.iNet Docs: Multi-WAN (failover and load balance, link tracking), retrieved Oct 6, 2026
  5. Peplink: B One product page (health check, session persistence, SpeedFusion), retrieved Oct 6, 2026
  6. TP-Link Omada: ER605 product page (link backup, online detection), retrieved Oct 6, 2026
  7. IETF RFC 9293: Transmission Control Protocol (connection identified by a socket pair), retrieved Oct 6, 2026

Research-based: written from vendor documentation, Starlink support pages and standards, not from our own measurements. Starlink rules and prices on this page come from our dated fact file and show the day they were checked; they change, so confirm before you rely on one.Links to Starlink’s plan pages here use the site owner’s own referral link; the owner may get a referral reward and your price is the same. No affiliate links (how we make money). General information, not professional IT, legal or medical advice. Independent · not affiliated with SpaceX or Starlink. Spotted an error? Tell us.