Reliable internet connectivity is the foundation of every modern IoT deployment. Yet outages remain an unavoidable reality. Construction work damages cables, routers fail unexpectedly, and service providers occasionally experience disruptions. While a brief outage may be an inconvenience in a home environment, it can lead to data loss, interrupted workflows, and inaccessible systems in production IoT environments.
A practical solution is to equip critical infrastructure with an automatic backup connection. In this article, we'll show how to build a reliable Multi-WAN failover setup using OpenWrt, a Raspberry Pi, and a Huawei E3372 LTE modem. If the primary internet connection fails, traffic is automatically redirected through the cellular network.
Solution Architecture
The Raspberry Pi's onboard Ethernet interface (eth0) serves as the primary internet connection. A Huawei E3372 LTE modem provides backup connectivity and is recognized by the system as a second network interface (eth1).
The design goals are straightforward:
- Primary internet access via DSL, cable, or fiber
- Continuous connection monitoring
- Automatic switch to LTE during outages
- Seamless return to the primary connection once restored
Preparing the LTE Modem
Before deployment, insert the SIM card into a smartphone and permanently disable the PIN request. This allows the modem to register with the cellular network automatically after being connected to the Raspberry Pi.
The status LED on the Huawei E3372 provides a quick health check:
- Blinking green: Searching for a mobile network or SIM card is locked
- Solid cyan/turquoise: Successfully connected to the LTE/4G network
Once the LED remains cyan, the modem is ready for use.
Installing Required Packages
Recent OpenWrt releases use the apk package manager. Begin by installing the necessary USB drivers and Multi-WAN software components.
apk update
apk add kmod-usb-core kmod-usb2 usb-modeswitch kmod-usb-net-cdc-ether
apk add mwan3 luci-app-mwan3
reboot
After rebooting, both the Ethernet interface and LTE modem should be properly detected.
Configuring Network Interfaces
OpenWrt prioritizes internet connections using route metrics. Lower values have higher priority.
# Primary WAN connection
uci set network.wan=interface
uci set network.wan.device='eth0'
uci set network.wan.proto='dhcp'
uci set network.wan.metric='1'
# LTE backup connection
uci set network.lte_wan=interface
uci set network.lte_wan.device='eth1'
uci set network.lte_wan.proto='dhcp'
uci set network.lte_wan.metric='2'
uci commit network
/etc/init.d/network restart
With this configuration, traffic uses the wired connection by default while LTE remains on standby.
Updating Firewall Rules
New interfaces must be added to OpenWrt's WAN security zone before they can be used for routing internet traffic.
uci add_list firewall.@zone.network='lte_wan'
uci commit firewall
/etc/init.d/firewall restart
This ensures the LTE connection inherits the same firewall policies as the primary WAN interface.
Configuring Automatic Failover with mwan3
The core of the solution is mwan3, OpenWrt's Multi-WAN manager. It continuously monitors connectivity and handles failover decisions automatically.
First, remove the default example configurations:
uci delete mwan3.wan6
uci delete mwan3.wanb
uci delete mwan3.wanb6
Next, configure connection monitoring:
uci set mwan3.wan=interface
uci set mwan3.wan.enabled='1'
uci set mwan3.wan.track_method='ping'
uci add_list mwan3.wan.track_ip='8.8.8.8'
uci set mwan3.wan.reliability='1'
uci set mwan3.lte_wan=interface
uci set mwan3.lte_wan.enabled='1'
uci set mwan3.lte_wan.track_method='ping'
uci add_list mwan3.lte_wan.track_ip='192.168.8.1'
uci set mwan3.lte_wan.reliability='1'
The primary WAN connection is monitored through a public DNS server. For the LTE modem, only the local gateway is monitored to minimize unnecessary mobile data usage.
Now define connection priorities:
uci set mwan3.wan_member=member
uci set mwan3.wan_member.interface='wan'
uci set mwan3.wan_member.metric='1'
uci set mwan3.wan_member.weight='1'
uci set mwan3.lte_member=member
uci set mwan3.lte_member.interface='lte_wan'
uci set mwan3.lte_member.metric='2'
uci set mwan3.lte_member.weight='1'
Finally, create the failover policy:
uci set mwan3.failover=policy
uci set mwan3.failover.last_resort='unreachable'
uci add_list mwan3.failover.use_member='wan_member'
uci add_list mwan3.failover.use_member='lte_member'
uci set mwan3.default_rule_v4.policy_assigned='failover'
uci commit mwan3
/etc/init.d/mwan3 restart
From this point forward, mwan3 automatically manages traffic across both internet connections.
Real-World Failover Testing
The current Multi-WAN status can be verified at any time:
mwan3 status
As long as the primary connection remains available, all traffic is routed through wan.
To test failover, disconnect the primary uplink by unplugging the Ethernet cable or shutting down the upstream router.
Within seconds, mwan3 detects the outage and transfers all traffic to lte_wan. Connected IoT devices continue communicating without manual intervention.
When the primary connection becomes available again, traffic is automatically routed back to the preferred WAN interface.
From IoT Projects to Enterprise High Availability
A Raspberry Pi running OpenWrt is an excellent platform for edge gateways, distributed sensor networks, smart building solutions, and smaller industrial deployments. Enterprise environments, however, often require more advanced availability and redundancy strategies.
This is where platforms such as OPNsense come into play.
Typical enterprise use cases include:
Multi-Carrier Connectivity
Multiple providers, such as fiber, business DSL, and 5G, can be combined to improve both resilience and overall throughput.
Policy-Based Routing
Traffic can be directed dynamically according to service requirements. VoIP and video conferencing can use the most stable connection, while backups and large data transfers utilize secondary links.
Redundant VPN Infrastructure
WireGuard and IPsec site-to-site VPNs remain operational even during provider failures by automatically migrating across available internet connections.
High Availability Firewall Clusters
Redundant OPNsense appliances eliminate not only internet connectivity failures but also hardware failures. In the event of a firewall outage, a synchronized secondary appliance takes over seamlessly.
Conclusion
Automatic LTE failover is one of the most effective ways to increase the resilience of IoT infrastructure. Using OpenWrt, a Raspberry Pi, and a USB LTE modem, it is possible to create a robust redundancy solution with minimal investment.
For smaller deployments, this approach provides an affordable and reliable backup internet connection. In larger enterprise environments, the same principles form the foundation of highly available network architectures featuring multiple providers, redundant firewalls, and resilient VPN connectivity.
“Automatic LTE failover is one of the simplest and most effective ways to eliminate the most common single point of failure in IoT deployments: the internet connection itself.”

