How to Configure Dual WAN Failover in Cisco IOS (IP SLA & Route Maps)

How to Configure Dual WAN Failover in Cisco IOS (IP SLA & Route Maps)

In today’s always-on world, losing your internet connection isn't just an annoyance—it brings work to a standstill. If you have a primary ISP and a backup ISP (like a cellular or secondary broadband link), you can configure your Cisco router to automatically failover if the primary link goes down.

It is important to note that failover is different from load balancing. In a failover setup, all your traffic runs through the primary ISP. The router only switches to the backup ISP when a failure is detected. Once the primary link comes back online, the traffic switches back.

In this guide, I’ll show you how to set up this "bad boy" router using Cisco IOS XE. We will use IP SLA for link monitoring, Route Maps to direct traffic, the Track command for reachability, and Cisco EEM (Embedded Event Manager) to clear our NAT cache automatically.

Let’s dive into the configuration!

Step 1: Define Your Interfaces (Inside and Outside)

First, we need to tell the router which interfaces connect to the internet (Outside) and which connect to your local network (Inside).

Primary ISP (Fiber):

Cisco CLI

interface GigabitEthernet0/1/0
 description WAN_ISP
 ip nat outside

Backup ISP : (Note: Apply ip nat outside to this interface as well).

Local Network (LAN):

Cisco CLI

interface GigabitEthernet0/0/2
 description Interface_To_Local
 ip nat inside

We need a way for the router to know if the primary internet is actually working. We do this using IP SLA. There are many parameters you can use for IP SLA (like UDP, DNS, HTTP), which you can see if you type ? in the CLI:

Cisco CLI

idjelamcrr0(config-ip-sla)#?
IP SLAs entry configuration commands:
  dhcp         DHCP Operation
  dns          DNS Query Operation
  ethernet     Ethernet Operations
  exit         Exit Operation Configuration
  ftp          FTP Operation
  http         HTTP Operation
  icmp-echo    ICMP Echo Operation
  icmp-jitter  ICMP Jitter Operation
  ...

For this setup, we just need ICMP Echo (a simple ping). We want to target a stable public IP address, like the Google Public DNS:

Google Public IP DNS
8.8.8.8
8.8.4.4

Alternatively, you can ping the ISP's default gateway. Here is the configuration targeting my ISP gateway (103.119.63.129) out of my primary WAN interface:

Cisco CLI

ip sla 1
 icmp-echo 103.119.63.129 source-interface GigabitEthernet0/1/0
ip sla schedule 1 life forever start-time now

You can verify it is running successfully with this command:

idjelamcrr0#show ip sla summary
IPSLAs Latest Operation Summary
Codes: * active, ^ inactive, ~ pending
All Stats are in milliseconds. Stats with u are in microseconds

ID           Type        Destination       Stats       Return      Last
                                                       Code        Run
-----------------------------------------------------------------------
*1           icmp-echo   103.119.63.129    RTT=4       OK          31 seconds ago

Step 3: Track the IP SLA

Next, we tie a track object to our IP SLA. This allows the router's routing table to react to the IP SLA's status.

Cisco CLI

idjelamcrr0# track 8 ip sla 1 reachability

Check the status to ensure it is up:

idjelamcrr0#show track
Track 8
  IP SLA 1 reachability
  Reachability is Up
    10 changes, last change 1d16h
  Latest operation return code: OK
  Latest RTT (millisecs) 5

Step 4: Create the IP Access List (The "VIP Pass")

Before we translate traffic to the internet, we must define who is allowed to access the internet using an Access Control List (ACL).

If you want to restrict internet access to a specific subnet (like 192.168.10.0):

Cisco CLI

ip access-list standard NAT_ACL_LOCAL
 description MyLocalSubnet
 permit 192.168.10.0 0.0.0.255

If you have a simple setup and want to allow all local traffic, use this instead:

Cisco CLI

ip access-list standard NAT_ACL_LOCAL
 description ALL_LocalSubnet
 permit any

Step 5: Configure Route Maps

Route maps tie your Access List to a specific outgoing WAN interface. We need two: one for the Primary ISP and one for the Backup ISP.

Primary Route Map:

Cisco CLI

route-map NAT_ISP_PRIMARY permit 10 
 match ip address NAT_ACL_LOCAL
 match interface GigabitEthernet0/1/0

Backup Route Map:

Cisco CLI

route-map NAT_ISP_BACKUP permit 10
 match ip address NAT_ACL_LOCAL
 match interface GigabitEthernet0/0/2

Step 6: Set Up Static Routing

Now we inject our tracking object into our routing table. We will set the primary route to rely on track 8. We will also add a secondary route with a higher metric (e.g., 10) so it only becomes active if Track 8 goes down.

Cisco CLI

ip route 0.0.0.0 0.0.0.0 103.119.63.129 track 8
ip route 0.0.0.0 0.0.0.0 192.168.8.1 10

Step 7: Apply the NAT Configuration

Next, we apply the NAT statements using the Route Maps we created. Don't forget the overload keyword to enable PAT (Port Address Translation).

Cisco CLI

ip nat inside source route-map NAT_ISP_PRIMARY interface GigabitEthernet0/1/0 overload
ip nat inside source route-map NAT_ISP_BACKUP interface GigabitEthernet0/0/2 overload

Step 8: Pro-Tip: Use Cisco EEM to Prevent Sticky NAT

Your dual WAN failover will work at this point! However, I highly recommend one final step.

When a link fails over, existing sessions in the NAT translation table can get "stuck" trying to use the dead ISP. We can use Cisco Embedded Event Manager (EEM) to automatically clear the NAT cache whenever our tracked link goes up or down.

Cisco CLI

event manager applet ISP_PRIMARY_Down
 event track 8 state down
 action 1.0 cli command "clear ip nat translation forced"
 
event manager applet ISP_PRIMARY_UP
 event track 8 state up
 action 1.0 cli command "clear ip nat translation forced"

Conclusion

And that’s it! Your Cisco router is now fully configured for automatic dual WAN failover. If your main fiber line gets cut, your router will automatically dump the NAT table and swing all traffic over to your backup cellular connection seamlessly.