The short version
5G failover is automatic when the site has a router or firewall that watches the main connection and moves traffic to the 5G service when the main one stops working. Nobody has to unplug or reboot anything.
The switch itself can take a couple of seconds or several minutes, depending almost entirely on how the router is set up. A gap of a minute or more is usually fixable. What ordinary failover cannot do is keep a call or VPN session alive through the switch, because the site’s public address changes. If that matters, you need SD-WAN or bonding.
And failover that has never been tested is an assumption. Test it outside trading hours, with a plan and a way back.
How does 5G failover actually work?
A dual-WAN router has two internet connections plugged into it: the fixed line (NBN or fibre) and a 5G service, either through a built-in cellular modem or a separate 5G router. Three things happen:
- Health checks. The router keeps testing the fixed line by sending pings or DNS lookups to servers on the internet. UniFi gateways, for example, ping one Ubiquiti server and run DNS lookups through Cloudflare and Google, and mark the connection down when two of the three fail.
- Failover. After a set number of failed checks, the router sends traffic out the 5G service instead.
- Failback. When the fixed line passes its checks again, the router moves traffic back. Good routers wait a little first so a flaky line does not bounce back and forth.
The router has to see the problem to act on it. A hard failure, where the cable or modem goes dead, is obvious and is detected almost instantly. A soft failure, where the modem still shows a link but nothing gets through, is only caught by the health checks. Soft failures are common on NBN faults, and they are where slow failover comes from.
Why is there a cut-over gap?
The gap people notice is the sum of several delays:
| Delay | What causes it | Typical fix |
|---|---|---|
| Detection | Health-check interval multiplied by the number of failed checks before the link is declared down | Shorter intervals and sensible thresholds |
| Soft-failure handling | Some routers wait much longer when the link light is still on | Health checks that test real internet reachability, with tighter timing |
| 5G link not ready | A modem that is idle, powered down or not kept connected has to attach before it passes traffic | Keep the 5G link connected and checked all the time |
| New public IP | Traffic now leaves with a different address, so existing sessions end | SD-WAN or bonding through a cloud gateway |
| Phones re-registering | Cloud phones keep talking to the old address until they notice | Keepalive and NAT timers set to the phone platform’s guidance |
| VPNs and apps reconnecting | Tunnels and logged-in sessions rebuild on the new address | Faster dead-peer detection; apps that reconnect cleanly |
Vendor defaults show how much the detection step varies:
- Fortinet FortiGate SD-WAN health checks default to a probe every 500 ms and five failures before a link is lost, so about 2.5 seconds to detect. Recovery uses the same count.
- Peplink routers default to a 5-second health-check interval and three retries, so roughly 15 seconds.
- Cisco Meraki MX fails over immediately when the physical link is lost. For a soft failure, Meraki’s documentation says it “can take approximately five minutes”. It then waits about 15 seconds before failing back to the primary.
- UniFi gateways use the two-out-of-three probe rule by default, and let you create custom SLAs with your own probe interval and packet loss, latency and jitter thresholds.
Then there are all-in-one modems with a built-in 4G or 5G backup, supplied with some business NBN plans. They are convenient, but you usually cannot see or change their detection settings at all.
Can a 90-second gap shrink, or is it physics?
Mostly it is configuration, not physics. Here is how we work through it:
- Find out what kind of failure you are testing. If the gap only happens when the NBN drops but the modem stays up, it is soft-failure detection. Check what the router does in that case.
- Tighten the health checks. Use more than one reliable target, a shorter interval and a sensible failure count. Too aggressive and the link flaps on a single dropped ping, so test the setting rather than guessing.
- Keep the 5G link warm. The 5G service should be connected, monitored and passing health checks all the time, not waiting to be woken.
- Check where the 5G service connects. A separate 5G router in front of your main router adds its own address translation and its own delays. Bridge or passthrough mode, where the 5G router hands its address straight to your main router, is usually cleaner.
- Tune the phones. 8x8 notes its phones register every 660 seconds and recommends matching router NAT timers to that. The SIP standard for client connections, RFC 5626, says a phone should re-register when it detects that its connection or NAT mapping has changed, with keepalives every 24 to 29 seconds on UDP. Phones that send keepalives notice the change in seconds rather than minutes.
- Use active/standby, not load balancing, for voice. 8x8 recommends dual WAN in active/standby and warns that active/active load balancing can cause out-of-order packets and poor call quality.
With those in place, a simple dual-WAN failover can switch in a few seconds, with phones back shortly after. Calls in progress at the moment of failure will still usually drop.
Keeping sessions alive through the switch
When traffic moves from the fixed line to 5G, it leaves from a different public IP address. To the outside world, the site has changed address, and anything tied to the old one ends: calls in progress, VPN tunnels, some banking and payment sessions. Peplink’s manual notes that many e-banking sites end the session when the client’s internet IP changes mid-session.
Fortinet’s own guidance is that moving sessions between public internet links only works if the same public IP is used on every link, which needs dynamic routing with the carriers. That is out of reach for most small sites.
The practical way to get the same result is SD-WAN or bonding to a cloud gateway. The site’s routers build tunnels over both connections to a gateway in a data centre, and traffic leaves the internet from the gateway’s address. When one link fails, the tunnel carries on over the other and the public address does not change. Peplink’s SpeedFusion, for example, offers detection settings from about 15 seconds down to under one second, and a “WAN smoothing” mode that sends traffic over both links at once which in its normal setting uses up to double the data.
It costs more, in hardware, a gateway subscription and 5G data. It is worth it for call centres, sites taking phone orders all day and anywhere a dropped call is a lost sale. For most offices and shops, fast ordinary failover is enough.
Which broadband plans include automatic 4G failover?
At the time of writing (October 2026), several business NBN plans come with a mobile backup built into the supplied modem:
- Telstra business NBN plans with the Smart Modem switch automatically to Telstra’s mobile network. Telstra says the backup is uncapped and unshaped on eligible business NBN plans, and its terms note that some services, such as on-site services relying on a static IP, may not work in backup.
- Optus business NBN includes a built-in 4G backup on Optus’s network with a speed limit of about 25 Mbps download.
- Aussie Broadband sells a 4G backup on the Optus network that runs at 25/5 Mbps, included with some business NBN plans and an extra monthly charge on others.
These are a good start for a small office. Their limits: the modem itself is a single point of failure, the backup uses the same provider as the main service, you get little visibility of when it switched, and speeds can be capped. A business router with its own separate 4G or 5G service fixes all four. 4G versus 5G matters less than signal strength at the site.
How to test a 5G backup without putting the live business at risk
A failover test should never be the reason the shop cannot take cards on a Saturday. Do it this way:
Before the test
- Pick a window outside trading hours, and tell anyone who might be working
- Check the 5G signal, that the SIM is active and that the plan has data left
- Confirm alerts are set up and know who should receive them
- Write down how to undo the test: which cable goes back where
- Have someone on site, and the support provider’s number to hand
Step 1: check the backup on its own. Most routers show the status of the 5G link and can run a test over it. Confirm it is connected and passing health checks before you take the primary away.
Step 2: hard failure. Unplug the cable from the fixed-line modem to the router’s primary WAN port. Time how long until traffic flows over 5G.
Step 3: soft failure. Put the cable back, let the router fail back, then simulate a line that is up but not working, for example by disconnecting the incoming line from the modem while leaving the modem connected to the router. This is the failure that catches routers out.
Step 4: test what matters, on 5G. Make a phone call in and out. Run a small card transaction and refund it. Open the POS, the booking system and a cloud app. Check that remote cameras and VPNs reconnect.
Step 5: restore. Reconnect the primary, time the switch back, and watch for a few minutes to make sure it does not flap.
Step 6: record it. Date, who tested, how long each switch took, what worked, what did not and what was changed. Repeat after any change to the network or the services, and on a schedule, every few months for most businesses. Franchise and head-office backup link requirements covers why that record matters if a franchisor or auditor asks.
Get the failover set up and tested properly
Kookaburra Comms is carrier-neutral. We choose the 5G service by signal at your site, configure the router or firewall’s health checks, failover and voice priority, set up monitoring, and run the first failover test with you on site, including a real call and a card transaction. If the gap is longer than it should be on an existing setup, we can find out why. Start with business internet, or see business internet failover and redundancy for the wider design.
