Zero Downtime for IoT: Automatic LTE Failover with OpenWrt on a Raspberry Pi

Internet outages can bring IoT environments to a halt within seconds. This guide demonstrates how to build a cost-effective Multi-WAN failover solution using OpenWrt, a Raspberry Pi, and a Huawei LTE modem, ensuring automatic connectivity failover and maximum uptime when the primary connection goes down.

Date
04 Aug 2026
Read
5 min

Reliable internet connectivity is the foundation of every modern IoT deployment. Yet outages remain an unavoidable reality. Construction work damages cables, routers fail unexpectedly, and service providers occasionally experience disruptions. While a brief outage may be an inconvenience in a home environment, it can lead to data loss, interrupted workflows, and inaccessible systems in production IoT environments.

A practical solution is to equip critical infrastructure with an automatic backup connection. In this article, we'll show how to build a reliable Multi-WAN failover setup using OpenWrt, a Raspberry Pi, and a Huawei E3372 LTE modem. If the primary internet connection fails, traffic is automatically redirected through the cellular network.

Solution Architecture

The Raspberry Pi's onboard Ethernet interface (eth0) serves as the primary internet connection. A Huawei E3372 LTE modem provides backup connectivity and is recognized by the system as a second network interface (eth1).

The design goals are straightforward:

  • Primary internet access via DSL, cable, or fiber
  • Continuous connection monitoring
  • Automatic switch to LTE during outages
  • Seamless return to the primary connection once restored

Preparing the LTE Modem

Before deployment, insert the SIM card into a smartphone and permanently disable the PIN request. This allows the modem to register with the cellular network automatically after being connected to the Raspberry Pi.

The status LED on the Huawei E3372 provides a quick health check:

  • Blinking green: Searching for a mobile network or SIM card is locked
  • Solid cyan/turquoise: Successfully connected to the LTE/4G network

Once the LED remains cyan, the modem is ready for use.

Installing Required Packages

Recent OpenWrt releases use the apk package manager. Begin by installing the necessary USB drivers and Multi-WAN software components.

apk update

apk add kmod-usb-core kmod-usb2 usb-modeswitch kmod-usb-net-cdc-ether

apk add mwan3 luci-app-mwan3

reboot

After rebooting, both the Ethernet interface and LTE modem should be properly detected.

Configuring Network Interfaces

OpenWrt prioritizes internet connections using route metrics. Lower values have higher priority.

# Primary WAN connection
uci set network.wan=interface
uci set network.wan.device='eth0'
uci set network.wan.proto='dhcp'
uci set network.wan.metric='1'

# LTE backup connection
uci set network.lte_wan=interface
uci set network.lte_wan.device='eth1'
uci set network.lte_wan.proto='dhcp'
uci set network.lte_wan.metric='2'

uci commit network
/etc/init.d/network restart

With this configuration, traffic uses the wired connection by default while LTE remains on standby.

Updating Firewall Rules

New interfaces must be added to OpenWrt's WAN security zone before they can be used for routing internet traffic.

uci add_list firewall.@zone.network='lte_wan'

uci commit firewall
/etc/init.d/firewall restart

This ensures the LTE connection inherits the same firewall policies as the primary WAN interface.

Configuring Automatic Failover with mwan3

The core of the solution is mwan3, OpenWrt's Multi-WAN manager. It continuously monitors connectivity and handles failover decisions automatically.

First, remove the default example configurations:

uci delete mwan3.wan6
uci delete mwan3.wanb
uci delete mwan3.wanb6

Next, configure connection monitoring:

uci set mwan3.wan=interface
uci set mwan3.wan.enabled='1'
uci set mwan3.wan.track_method='ping'
uci add_list mwan3.wan.track_ip='8.8.8.8'
uci set mwan3.wan.reliability='1'

uci set mwan3.lte_wan=interface
uci set mwan3.lte_wan.enabled='1'
uci set mwan3.lte_wan.track_method='ping'
uci add_list mwan3.lte_wan.track_ip='192.168.8.1'
uci set mwan3.lte_wan.reliability='1'

The primary WAN connection is monitored through a public DNS server. For the LTE modem, only the local gateway is monitored to minimize unnecessary mobile data usage.

Now define connection priorities:

uci set mwan3.wan_member=member
uci set mwan3.wan_member.interface='wan'
uci set mwan3.wan_member.metric='1'
uci set mwan3.wan_member.weight='1'

uci set mwan3.lte_member=member
uci set mwan3.lte_member.interface='lte_wan'
uci set mwan3.lte_member.metric='2'
uci set mwan3.lte_member.weight='1'

Finally, create the failover policy:

uci set mwan3.failover=policy
uci set mwan3.failover.last_resort='unreachable'
uci add_list mwan3.failover.use_member='wan_member'
uci add_list mwan3.failover.use_member='lte_member'

uci set mwan3.default_rule_v4.policy_assigned='failover'

uci commit mwan3
/etc/init.d/mwan3 restart

From this point forward, mwan3 automatically manages traffic across both internet connections.

Real-World Failover Testing

The current Multi-WAN status can be verified at any time:

mwan3 status

As long as the primary connection remains available, all traffic is routed through wan.

To test failover, disconnect the primary uplink by unplugging the Ethernet cable or shutting down the upstream router.

Within seconds, mwan3 detects the outage and transfers all traffic to lte_wan. Connected IoT devices continue communicating without manual intervention.

When the primary connection becomes available again, traffic is automatically routed back to the preferred WAN interface.

From IoT Projects to Enterprise High Availability

A Raspberry Pi running OpenWrt is an excellent platform for edge gateways, distributed sensor networks, smart building solutions, and smaller industrial deployments. Enterprise environments, however, often require more advanced availability and redundancy strategies.

This is where platforms such as OPNsense come into play.

Typical enterprise use cases include:

Multi-Carrier Connectivity

Multiple providers, such as fiber, business DSL, and 5G, can be combined to improve both resilience and overall throughput.

Policy-Based Routing

Traffic can be directed dynamically according to service requirements. VoIP and video conferencing can use the most stable connection, while backups and large data transfers utilize secondary links.

Redundant VPN Infrastructure

WireGuard and IPsec site-to-site VPNs remain operational even during provider failures by automatically migrating across available internet connections.

High Availability Firewall Clusters

Redundant OPNsense appliances eliminate not only internet connectivity failures but also hardware failures. In the event of a firewall outage, a synchronized secondary appliance takes over seamlessly.

Conclusion

Automatic LTE failover is one of the most effective ways to increase the resilience of IoT infrastructure. Using OpenWrt, a Raspberry Pi, and a USB LTE modem, it is possible to create a robust redundancy solution with minimal investment.

For smaller deployments, this approach provides an affordable and reliable backup internet connection. In larger enterprise environments, the same principles form the foundation of highly available network architectures featuring multiple providers, redundant firewalls, and resilient VPN connectivity.

“Automatic LTE failover is one of the simplest and most effective ways to eliminate the most common single point of failure in IoT deployments: the internet connection itself.”
Authors

Jitendra Bodmann

Owner & Marketer

Trained marketing expert with over a decade of experience in web development. At Wedima he brings analytical thinking and a creative streak into the open. When he is not online, he reconnects with his Nepalese roots and spends his free time at dizzying heights.

02

Angelo Milde

Systems & Development

A trained systems integrator with Red Hat certification and a sharp eye for IT security. Across cloud environments, data centers, and complex systems, he keeps infrastructure stable, secure, and scalable. He has gained experience with international service providers such as Equinix. For him, security isn't an afterthought to tick off a list, but something built in from the very first line of configuration.

Next step

Something to write about together?

Bring a brief, a bottleneck, or a half-formed idea. We’ll sharpen it with you.