How to Configure Dual WAN Failover in Cisco IOS (IP SLA & Route Maps)
In today’s always-on world, losing your internet connection isn't just an annoyance—it brings work to a standstill. If you have a primary ISP and a backup ISP (like a cellular or secondary broadband link), you can configure your Cisco router to automatically failover if the primary link goes down.
It is important to note that failover is different from load balancing. In a failover setup, all your traffic runs through the primary ISP. The router only switches to the backup ISP when a failure is detected. Once the primary link comes back online, the traffic switches back.
In this guide, I’ll show you how to set up this "bad boy" router using Cisco IOS XE. We will use IP SLA for link monitoring, Route Maps to direct traffic, the Track command for reachability, and Cisco EEM (Embedded Event Manager) to clear our NAT cache automatically.
Let’s dive into the configuration!
Step 1: Define Your Interfaces (Inside and Outside)
First, we need to tell the router which interfaces connect to the internet (Outside) and which connect to your local network (Inside).
Primary ISP (Fiber):
Cisco CLI
interface GigabitEthernet0/1/0
description WAN_ISP
ip nat outside
Backup ISP : (Note: Apply ip nat outside to this interface as well).
Local Network (LAN):
Cisco CLI
interface GigabitEthernet0/0/2
description Interface_To_Local
ip nat inside
Step 2: Set Up IP SLA for Link Monitoring
We need a way for the router to know if the primary internet is actually working. We do this using IP SLA. There are many parameters you can use for IP SLA (like UDP, DNS, HTTP), which you can see if you type ? in the CLI:
Cisco CLI
idjelamcrr0(config-ip-sla)#?
IP SLAs entry configuration commands:
dhcp DHCP Operation
dns DNS Query Operation
ethernet Ethernet Operations
exit Exit Operation Configuration
ftp FTP Operation
http HTTP Operation
icmp-echo ICMP Echo Operation
icmp-jitter ICMP Jitter Operation
...
For this setup, we just need ICMP Echo (a simple ping). We want to target a stable public IP address, like the Google Public DNS:
Google Public IP DNS
8.8.8.8
8.8.4.4
Alternatively, you can ping the ISP's default gateway. Here is the configuration targeting my ISP gateway (103.119.63.129) out of my primary WAN interface:
Cisco CLI
ip sla 1
icmp-echo 103.119.63.129 source-interface GigabitEthernet0/1/0
ip sla schedule 1 life forever start-time now
You can verify it is running successfully with this command:
idjelamcrr0#show ip sla summary
IPSLAs Latest Operation Summary
Codes: * active, ^ inactive, ~ pending
All Stats are in milliseconds. Stats with u are in microseconds
ID Type Destination Stats Return Last
Code Run
-----------------------------------------------------------------------
*1 icmp-echo 103.119.63.129 RTT=4 OK 31 seconds ago
Step 3: Track the IP SLA
Next, we tie a track object to our IP SLA. This allows the router's routing table to react to the IP SLA's status.
Cisco CLI
idjelamcrr0# track 8 ip sla 1 reachability
Check the status to ensure it is up:
idjelamcrr0#show track
Track 8
IP SLA 1 reachability
Reachability is Up
10 changes, last change 1d16h
Latest operation return code: OK
Latest RTT (millisecs) 5
Step 4: Create the IP Access List (The "VIP Pass")
Before we translate traffic to the internet, we must define who is allowed to access the internet using an Access Control List (ACL).
If you want to restrict internet access to a specific subnet (like 192.168.10.0):
Cisco CLI
ip access-list standard NAT_ACL_LOCAL
description MyLocalSubnet
permit 192.168.10.0 0.0.0.255
If you have a simple setup and want to allow all local traffic, use this instead:
Cisco CLI
ip access-list standard NAT_ACL_LOCAL
description ALL_LocalSubnet
permit any
Step 5: Configure Route Maps
Route maps tie your Access List to a specific outgoing WAN interface. We need two: one for the Primary ISP and one for the Backup ISP.
Primary Route Map:
Cisco CLI
route-map NAT_ISP_PRIMARY permit 10
match ip address NAT_ACL_LOCAL
match interface GigabitEthernet0/1/0
Backup Route Map:
Cisco CLI
route-map NAT_ISP_BACKUP permit 10
match ip address NAT_ACL_LOCAL
match interface GigabitEthernet0/0/2
Step 6: Set Up Static Routing
Now we inject our tracking object into our routing table. We will set the primary route to rely on track 8. We will also add a secondary route with a higher metric (e.g., 10) so it only becomes active if Track 8 goes down.
Cisco CLI
ip route 0.0.0.0 0.0.0.0 103.119.63.129 track 8
ip route 0.0.0.0 0.0.0.0 192.168.8.1 10
Step 7: Apply the NAT Configuration
Next, we apply the NAT statements using the Route Maps we created. Don't forget the overload keyword to enable PAT (Port Address Translation).
Cisco CLI
ip nat inside source route-map NAT_ISP_PRIMARY interface GigabitEthernet0/1/0 overload
ip nat inside source route-map NAT_ISP_BACKUP interface GigabitEthernet0/0/2 overload
Step 8: Pro-Tip: Use Cisco EEM to Prevent Sticky NAT
Your dual WAN failover will work at this point! However, I highly recommend one final step.
When a link fails over, existing sessions in the NAT translation table can get "stuck" trying to use the dead ISP. We can use Cisco Embedded Event Manager (EEM) to automatically clear the NAT cache whenever our tracked link goes up or down.
Cisco CLI
event manager applet ISP_PRIMARY_Down
event track 8 state down
action 1.0 cli command "clear ip nat translation forced"
event manager applet ISP_PRIMARY_UP
event track 8 state up
action 1.0 cli command "clear ip nat translation forced"
Conclusion
And that’s it! Your Cisco router is now fully configured for automatic dual WAN failover. If your main fiber line gets cut, your router will automatically dump the NAT table and swing all traffic over to your backup cellular connection seamlessly.