Dual WAN router or load balancing router: which one you actually need
Record your outage procedure and the results of your tests in the business continuity plan template.
A second connection does not survive a blackout on its own
Worth separating two failures people treat as one. An internet outage is the line going down while the power stays on, and that is what a second connection is for. A blackout is different, and most of a second connection is useless in one.
The reason is that the network needs power at your end and sometimes in the street. NBN Co sets this out by technology: on Fibre to the Premises the connection box in your building needs power, and a battery back up is something your provider may supply as part of the power supply unit but you have to ask them for it. On Fibre to the Curb, Fibre to the Node and HFC, the landline phone and internet will not work during a power outage in that network or in your premises, and NBN Co says restoring power with an alternative option is not possible where the network itself has lost power (NBN Co, what happens in a power blackout).
So a battery on the router keeps the router alive and nothing else. Work along the whole chain instead: the connection box, the router, the switch, the access points, the phone handsets and the payment terminal. Each one either has power in a blackout or it does not, and the answer decides what your business can still do.
Two things that catch people. A mobile based backup connection genuinely does keep working in a blackout, provided the equipment running it has power, which is why a charged phone is the realistic fallback NBN Co suggests. And alarms, lifts, medical alarms and payment terminals are their own question, because they may depend on the same line and the same power.
Test the two failures separately. Unplug the internet one day. Kill the power on another, deliberately and briefly, and write down what stopped.
Most businesses who ask me for dual WAN load balancing actually want failover. They're not chasing speed; they want the EFTPOS, the phones and the cloud apps to stay up when the NBN drops. Failover does exactly that: the second connection sits idle until the first one dies, then carries the load until it comes back. Load balancing runs both links live and splits your traffic between them, which sounds strictly better and usually disappoints. I've built both, on MikroTik and on pfSense, and about nine jobs in ten end up as failover. Here's what each one really does, when balancing genuinely earns its keep, and the traps on both paths.
What each one actually does
Failover is a spare tyre. You have a primary link and a backup, and the backup does nothing while the primary is healthy. The router watches the primary, and the moment it decides that link is dead, everything moves to the backup. When the primary recovers, everything moves home again. At any given moment your traffic leaves through one connection, from one public IP.
Load balancing keeps both links live all the time and deals new connections out across them. The key word is connections. Balancing splits sessions, not packets: each download, video call or browser tab picks a link when it starts and stays on it. Your traffic leaves from two public IPs at once, which matters more than most people expect.
Why load balancing disappoints people
The expectation is simple maths: a 100Mbps link plus a 50Mbps link should feel like 150Mbps. It doesn't, because a single session rides a single link. Your big file download tops out at whichever link it landed on. A speed test does the same, which is usually the moment the phone rings.
Then there's the two-IP problem. Plenty of services tie your session to your public IP. Internet banking is the classic: half your connections arrive from one address and half from the other, the bank decides something is off, and you're logged out or flagged. VoIP is worse, which is why the guide to business VoIP phone systems has a whole section on the internet link. A call is set up through one IP, and if the audio flaps to the other link mid-call, the call goes one-way or drops. The fix is policy rules pinning banking and voice to one link, and once you've pinned everything sensitive, you've mostly rebuilt failover with extra steps.
When load balancing is the right call
Balancing shines when the load is lots of people doing lots of small things. An office of twenty or thirty staff has hundreds of parallel sessions open: mail, browser tabs, cloud sync, a guest WiFi full of phones. Spread across two links, that aggregate load really does get 150Mbps of headroom, and the 2pm slowdown disappears. The test I use: if the complaint is "the internet crawls for everyone in the afternoon", balancing can fix it. If the complaint is "my upload is too slow", it can't. Buy a faster link for that.
When failover is right: almost everyone else
A small business doesn't lose money because the internet is 40 percent slower. It loses money because the internet is down, the terminal is offline and the phones are dead. If that describes your risk, you want failover: a boring, cheap second link that does nothing 364 days a year and saves the day on day 365. Pair your main business NBN service with a mobile backup, test it properly, and you've removed your single most expensive outage.
The detection problem: how the router knows a link is dead
This is where most DIY dual WAN setups quietly fail. Failover only works if the router can tell the link is down, and the obvious method, pinging the gateway, is wrong. The gateway is usually the NBN connection box or modem on your wall, and that box answers ping happily while the carrier behind it is completely dead. Gateway up, internet down, and the router keeps shovelling traffic into a black hole. The failover never fires and you find out from an angry phone call.
The right way is to check something out on the actual internet through each specific link: a couple of well-known public addresses, tested independently per WAN. Use more than one target, because one site being down is not an outage. And require several consecutive misses before declaring the link dead, because a single lost ping is just Tuesday. The opposite failure is flapping: a marginal link bouncing up and down every minute drags every session back and forth with it, which is worse than staying on the backup. A good setup fails over quickly and fails back cautiously.
If you want the same test in a form the whole office can read, a $10 box that shows whether it is your gear or your ISP runs exactly this split all day and shows the answer as two lights on a shelf.
Mixing NBN with 4G or 5G
A mobile service is the natural second link, and for failover it's excellent, because it only carries traffic during an outage and a modest data allowance covers you. Two gotchas though. First, data caps and balancing don't mix: balance across NBN and 5G and the mobile link carries real traffic all month, so the bill arrives before the benefit does. Second, CGNAT. Mobile carriers almost never hand you a public IP, so while you're running on the backup, anything inbound stops working: the VPN into the office, remote access to cameras, anything you host on-site. Outbound keeps flowing and staff barely notice, but if inbound services matter, plan around it or pay for a fixed-IP mobile service.
Two tricks that don't make the textbooks
First, there's a third option between balancing and failover: dedicate a link. Instead of pooling everything, give one WAN, often the mobile path, purely to voice and whatever else genuinely can't hiccup, and let everything else share the main link. The phones get a connection no staff download can congest, the two-IP problem disappears for calls because voice always leaves through the same address, and the mobile allowance is spent on the traffic that actually deserves it. On plenty of small sites this one rule beats both textbook modes, and it's the practical answer to "ok, but how do I set the policy".
Second, if either link is metered, schedule the heavy lifting off-peak. OS updates, cloud sync and big backups don't care when they run, so push them into the quiet hours instead of letting them land in the middle of trade. The gigabytes are the same; the bill and the 2pm congestion aren't. A metered link stays affordable when the big transfers are scheduled rather than accidental.
MikroTik vs pfSense in practice
Both do this properly. I've run dual WAN on MikroTik routerboards and on pfSense boxes for years, and the difference is philosophy, not capability.
MikroTik ties link health to the routing table. Check-gateway marks a route dead when its gateway stops responding, and recursive routing takes it further: a route can depend on reaching a far-off internet target through that specific link, which sidesteps the gateway-up-internet-down trap neatly. It's powerful and it's terse, and six months later the config reads like it. RouterOS rewards people who use it weekly.
pfSense wraps the same job in gateway groups. Each WAN gets a monitor IP out on the internet, gateways are grouped into tiers, and traffic follows the group: same tier means balance, different tiers means failover. Same logic, friendlier handles, and much easier to hand to the next person.
On sizing, the honest answer: at NBN speeds this is not a hardware problem. An RB4011-class MikroTik or a small pfSense box runs dual WAN for a whole office with headroom to spare. Spend the savings on the second link and an hour of proper failure testing.
Dual WAN is one job of several on a proper business gateway. The others, separated networks, a lane for voice and a VPN that terminates on the router, are laid out in what a proper small-business router and firewall build looks like.
Which dual WAN router to buy for a small business in Australia
Most of the people who land on this page want a product name, so here is the shortlist by class rather than by price. All of these are sold as dual WAN routers; what separates them is how each one decides a link is dead, and who is going to maintain it afterwards.
MikroTik hEX S or RB4011 (RouterOS). Detection is check-gateway on the route plus recursive routing to a far internet target, so a route is marked dead when a real address stops answering through that WAN rather than when the box on the wall does. It is powerful and assumes RouterOS experience; buy it if the person maintaining your network uses RouterOS regularly.
Netgate appliance or a small box running pfSense. Each WAN gets a monitor IP out on the internet, and a background daemon (dpinger) measures loss and latency to it continuously, marking the gateway down when either crosses the thresholds you set. Gateway groups then decide whether a second link balances or waits in reserve; buy it if you want the config readable by the next IT provider.
Ubiquiti UniFi gateway (Cloud Gateway, UDM or UXG). Dual WAN lives in the UniFi console as a simple failover-or-balance choice, and the gateway probes each WAN on a timer so it can tell a dead carrier from a live modem. The detection tuning is shallow compared with the two above; buy it if the site is already a UniFi site and one dashboard matters more than knobs.
TP-Link ER605 or another Omada router. Per-WAN online detection checks a ping target and a DNS lookup, so a port that still has link to a modem with a dead carrier behind it is correctly counted as down. It is the budget option with a proper GUI; buy it for a small office that needs failover without a specialist on call.
Peplink Balance. The only one of the five built around bonding: its SpeedFusion tunnel wraps both links so a single session can survive one of them failing. Its per-WAN health check can use ping, DNS or HTTP with its own retry and recovery counts; buy it when a dropped call or a dropped VPN mid-session is unacceptable and the budget follows.
Whichever you pick, the 4G or 5G caveat from earlier still applies. CGNAT on the mobile link means inbound services pause during a failover on every one of these routers, and the router choice changes nothing about that.
DSL, cable, NBN or fixed wireless: does the link type change the answer?
No. People search for DSL failover or cable internet failover as if each needs its own recipe, but the router never sees the technology. It sees a WAN port with a gateway behind it, and the same two rules apply to every one of them: test a real internet address through that specific link, and fail back slowly. Whether the link is an FTTN service on old copper, HFC cable, FTTP, fixed wireless or a 5G modem, the detection logic is identical and the CGNAT point about mobile backups is identical.
What does change is how often the link misbehaves. Copper-based NBN connections (FTTN) flap more than fibre: the line drops, resyncs, and drops again later. On a flappy link the fail-back timer matters more than the fail-over timer, because a router that jumps home the moment the copper resyncs drags every session across twice per event. Fixed wireless has its own version of this in heavy rain. Give those links a longer recovery window before the router trusts them again, and the second connection stops feeling like a coin toss.
FAQ
What is the difference between dual WAN load balancing and failover?
Failover keeps the second connection idle until the primary fails, then moves all traffic across until it recovers. Load balancing keeps both connections live and spreads sessions across them. Failover buys uptime; balancing buys aggregate capacity for many simultaneous users. Most small businesses want failover.
Will dual WAN load balancing double my internet speed?
No. Balancing splits connections across links, not packets, so a single download or video call rides one link at that link's speed. Links of 100Mbps and 50Mbps give 150Mbps of combined headroom across many sessions, but one transfer never sees more than 100Mbps. For one fast task, buy a faster primary link.
Can I use 4G or 5G as a backup for the NBN?
Yes, and as a failover link it works well because it only carries traffic during an outage. Two catches: data caps make balancing over mobile expensive, and CGNAT means no public IP, so inbound services like a VPN into the office or remote camera access stop working while you are on the backup.
How does the router know the internet connection is down?
Not by pinging the gateway. The gateway is usually the NBN box on your wall, and it answers ping even when the carrier behind it is dead. A proper setup tests targets out on the internet through each specific link, uses more than one target, and only fails over after several consecutive misses.
Is MikroTik or pfSense better for dual WAN?
Both handle failover and balancing properly. MikroTik ties link health to routes with check-gateway and recursive routing, which is powerful but assumes RouterOS experience. pfSense wraps the same logic in gateway groups with tiers and monitor IPs, which is easier to hand over. Pick the one your support person actually knows.
Do I need expensive hardware for a dual WAN setup?
No. An RB4011-class MikroTik or a small pfSense box handles dual WAN at NBN speeds with plenty of headroom. The hardware is the cheap part. The configuration and the failure testing are where the effort belongs, so spend it there.
What is the difference between hybrid connectivity, failover and load balancing?
Hybrid connectivity is the marketing name for one router with two different link types behind it, usually NBN plus 4G or 5G. It describes the hardware, not the policy. Failover and load balancing are the two policies you then choose for how the router uses those links: failover keeps the second one in reserve, balancing runs both live. So hybrid connectivity is not a third option; it is the setup, and failover or balancing is the decision you still have to make on it.
Can I load balance NBN with 5G?
Most dual WAN routers will let you, and it is usually a mistake. Balancing puts real traffic on the 5G link all month, so a data cap arrives before any benefit does, and sessions that land on the mobile link get its variable latency and CGNAT address. Use 5G as the failover link, or dedicate it to one class of traffic such as voice, and keep the bulk of the office on the NBN service.
Can failover be completely invisible to staff?
Not with an ordinary dual WAN router. When the primary dies your public IP changes, so existing sessions such as VPN tunnels and phone calls drop and re-establish on the backup once the router has failed over. The exception is bonding. A Peplink SpeedFusion tunnel wraps both links so the far end sees one address, and a single link failing then does not break a session. It costs more and needs an endpoint on the other side, which is why almost everyone else lives with a few seconds of cutover.
The bottom line
Failover keeps you trading through an outage; load balancing adds headroom for a busy office. If you're not sure which one you need, you need failover. Set the detection up properly so the router checks the real internet and not just the box on the wall, keep the mobile backup for emergencies rather than daily traffic, and test it by actually pulling the plug. Do that once, properly, and the next NBN outage in your street is someone else's bad day.
Running a business on one internet connection is a bet that it never fails. If you'd rather not make that bet, we design and build business networks with failover that has actually been tested, on gear sized for the job rather than the invoice. Our managed IT support then watches those links day to day, so a dead line is noticed before your staff feel it. Tell us what an hour offline costs you and we'll spec the second link to match.