Monday, May 18, 2026

Unifi Cloud Gateway WAN2 Failover Setup

Unifi Cloud Gateway WAN2 Failover Setup

Here is a complete, step-by-step guide for setting up a dual-WAN failover on a UniFi Cloud Gateway (UCG) Max or Ultra network controller!

The UCG-Max and UCG-Ultra both use standard RJ45 Ethernet ports (not SPF as found on the rack mounted Pro versions), and UniFi specifically designates LAN Port 4 as the port you can remap to act as your secondary WAN on both the Max and Ultra.

Phase 1: The Physical Connection

  1. Plug your Primary ISP (e.g., Fiber/Cable modem) into the dedicated WAN Port (Port 5).

  2. Plug your Backup ISP (e.g., Cellular/LTE modem) into LAN Port 4.


Phase 2: Remapping Port 4 & Configuring The Failover

  1. Open your UniFi Network Application on a web browser.

  2. Navigate to Settings (the gear icon) > Internet.

  3. Under the Internet overview, click to add a Secondary Internet connection.

  4. The system will prompt you to select an interface. Choose Port 4.

  5. Configure the IPv4 Connection type (usually DHCP for cellular backups, unless your provider gave you a static IP).

  6. Under the Multi-WAN or Advanced section for this new connection, ensure it is set strictly to Failover Only. Do not select Load Balancing/Distributed, or your gateway will bleed everyday background traffic over your cellular data plan.

  7. Click Apply Changes. Your UCG will provision the new port assignment (this takes a minute).


Phase 3: Building the Custom SLA Monitor

Now we create the highly responsive SLA policy we discussed earlier so your gateway knows exactly when to trigger the failover.

  1. Stay in Settings > Internet and scroll down to the SLA section.

  2. Click Create New (or "Add SLA").

  3. Name: Primary WAN Monitor

  4. Top Server Condition: Select All.

  5. Verification Server 1:

    • Type: Ping

    • Server Address: 8.8.8.8 (Google Primary DNS)

    • Ping Interval: 5 Seconds

    • Time Period: 30 Seconds

    • Packet Loss Threshold: Check the box and set to 10%

    • Latency Threshold: Check the box and set to 250ms

    • Jitter Threshold: Unchecked

    • Threshold Condition: Select Any

  6. Click Add Verification Server to build the second monitor.

  7. Verification Server 2:

    • Type: Ping

    • Server Address: 8.8.4.4 (Google Secondary DNS)

    • Match the exact same timings and thresholds (5s/30s, 10%, 250ms, Any) as Server 1.

  8. Click Add or Save to lock in the SLA policy.


Phase 4: Applying the SLA to Your Primary Connection

The final step is telling your gateway to apply these strict rules only to your main internet connection.

  1. Go back up to your Internet connection list (Settings > Internet).

  2. Look at the row for your Primary WAN (WAN1).

  3. In the SLA column (which will currently say Auto), click the dropdown.

  4. Select your newly created Primary WAN Monitor.

  5. Look at the row for your Backup WAN (WAN2) and verify that its SLA column is left on Auto.

  6. Click Apply Changes.


Your UCG-Max or UCG-Ultra should now be fully configured with a 2nd WAN Failover! It will aggressively monitor your primary line via WAN1, and if it sees 30 seconds of high latency or packet loss across both Google servers, it will automatically shift your network traffic to Port 4 (WAN2) until the primary line stabilizes!


Created & Maintained by Pacific Northwest Computers

Jon Pienkowski runs Pacific Northwest Computers, providing IT services, networking, and cybersecurity support to SW Washington and the Portland metro area.



📞 Pacific Northwest Computers offers Remote & Onsite Support Across: 

SW Washington including Vancouver WA, Battle Ground WA, Camas WA, Washougal WA, Longview WA, Kelso WA, and Portland OR 

No comments:

Post a Comment