Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Setting up Dual WAN configuration in Cloud Edge

    • Updated:
    • 14 Mar 2020
    • Product/Version:
    • Platform:
    • N/A N/A

Learn how to configure the Cloud Edge Routing Mode with Dual WAN failover scenario.

Cloud Edge Routing Mode with Dual WAN failover scenario


To apply Dual WAN configuration:

  1. Connect your main ISP line to WAN1 interface of the Cloud Edge box and the backup ISP line to WAN2 (LAN1) interface.
  2. On the Cloud Edge On-Premise console, go to Network > Interfaces.
  3. Edit your WAN interfaces (WAN and WAN2/LAN1) and select DHCP/PPPoE mode.

    Select DHCP/PPPoE mode

    Supported modes for DUAL WAN are DHCP/DHCP and DHCP/PPPoE.

    Verify the Dual WAN modes

  4. Enable monitor settings to check if both WAN lines still work. You can monitor some public DNS servers or any public IP addresses that are ICMP reachable.

    It is necessary to configure two (2) monitor hosts. If you only want to configure one host, input the same IP address on both monitoring host 1 and host 2 fields. Cloud Edge appliance will redirect network traffic to the backup LAN1/WAN2 route when both monitoring hosts are ICMP unreachable.

    Monitor settings

  5. On the same page, go to Network > Routing > Policy Routing.
  6. Configure Policy Route to direct traffic more precisely. This is necessary to have your DUAL WAN environment work in active/passive mode.
    • Source Address: Any
    • Destination Address: Any
    • Service Type: Any
    • Egress Interface: WAN or LAN1 (select interface that is connected to the active line)

    Policy Routing

    If you have configured other policy route, move the "any-any" policy route to the bottom. This is to ensure other policy routes would still work.

  7. On the Cloud Edge Cloud Console, go to Gateways.
  8. Select gateway and click NAT.
  9. Configure Source Network Address Translation (SNAT) on both WAN interfaces to allow internal address access to the Internet.
    • NAT Type: Source
    • Egress interface: WAN and LAN1 for the other interface
    • Source IP translation: Egress interface IP address

    Configure SNAT

  10. Click Save and then Apply.
  11. Configure your LAN network interfaces via Cloud Edge Cloud Console. The procedure is the same on Cloud Edge single WAN mode.

To test if the active/passive mode of Dual WAN Cloud Edge setup is working, use "tracert" command on your endpoint:

  1. When both WAN1 and WAN2 are working, traffic will pass through WAN1 interface.

    Traffic will pass through WAN1

  2. When both monitoring hosts of WAN1 interface are ICMP unreachable, traffic will failover on WAN2 interface.

    Traffic will failover on WAN2 interfac

Solution Id:
Did this article help you?

Thank you for your feedback!

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.