The following article documents our experience configuring Inseego FX3100 and FX4100 devices as backup WAN connections behind a SonicWall firewall. This represents a relatively uncommon deployment scenario and is not how most organizations use these devices.

Our experience with the Inseego FX3100 and FX4100 as standalone 5G Internet gateways and wireless access devices has been overwhelmingly positive. Throughout our testing, we found them to be reliable, cost-effective, and easy to deploy. The observations and recommendations contained in this article relate specifically to the use of these devices in a SonicWall failover WAN configuration and should not be interpreted as a reflection of their overall performance or reliability.

Configuring Inseego as a SonicWall WAN Backup

When using Inseego as a wireless hot spot, it’s an easy to set up, low-cost and extremely reliable solution. You can even request a static IP address from your preferred mobile carrier. For this reason, I figured they would make great redundant WAN backup devices when combined with a Sonicwall device that could seamlessly switch between WAN links. I have them rolled out across multiple locations for one of our clients, where they work great! I am able to monitor them using ICMP, but it took a little bit of trial and error. I am publishing this information for others who wish to make use of the same network architecture, and hopefully help streamline their installation.

If you are configuring an Inseego device for use as a SonicWall backup WAN connection, there are two options available: Bridged Mode and NAT Mode.

Inseego Bridged Mode as a SonicWall Failover WAN

I experienced significant issues at the time of this writing (June 2026) when using Inseego in Bridged Mode when connected to a SonicWall firewall as a backup WAN link. If you are interested in bridged mode setup, there is more information available here.

Using NAT Mode with SonicWall Failover

If you do not mind running a double NAT configuration, an Inseego device configured in NAT Mode functions quite well as a failover WAN connection. I have found it to be an extremely low cost, easy to set up and reliable Internet redundancy solution. You can even configure the device to respond to ICMP requests, allowing you to remotely monitor the backup link’s availability.

There are a few caveats to consider:

• With double NAT in place, you will not be able to access the SonicWall management interface remotely over the backup WAN

• Your Sonicwall router cannot have any interface configured on the 192.168.1.0/24 subnet.

At the time of this writing, Inseego maintains a management interface with the static IP address 192.168.1.1. Even if you change the device’s LAN IP address, the management interface remains active on this address and it will appear in broadcasts. The device also broadcasts Layer 2 packets announcing the presence of this IP address. If your SonicWall has any interface configured within the 192.168.1.0/24 subnet, it may interpret this behavior as IP spoofing or a network attack and block all traffic originating from the Inseego’s MAC address. As a result, failover WAN functionality may not operate correctly.

When configuring your Inseego device, ask your carrier to provide a static IP address. This allows you to monitor the backup WAN connection using ICMP (ping). In any redundant firewall deployment, it is important to monitor the health of the backup link. The last thing you want is to discover a problem with the backup connection when the primary Internet circuit fails.

If you prefer not to purchase a static IP address, you can use SonicWall’s built-in alerting features to notify you by email when the backup connection goes down. However, in my experience, most Network Operations Centers (NOCs) use monitoring software that relies on ICMP, HTTP, or HTTPS requests to continuously verify link availability. In my opinion, this is the preferred monitoring method because it provides proactive visibility into the status of the backup connection.

To allow the device to respond to ping requests, enable WAN Pings under Advanced > Firewall, as shown below.

image

Connect the Inseego’’s LAN port to the SonicWall X2 interface, or whichever interface you have designated as the backup WAN connection. Configure the SonicWall interface to obtain an IP address automatically.

Important: Ensure that none of the SonicWall interfaces are configured with the 192.168.1.0/24 subnet. If any interface uses this subnet, the backup WAN connection may be blocked and traffic will not pass through the Inseego device correctly.

image

You may notice that the Inseego configuration allows you to change the LAN IP address and DHCP range. While these settings will be reflected in the IP address assigned to the SonicWall interface, you still cannot have another SonicWall interface configured on the 192.168.1.0/24 subnet. This limitation remains in place even if you change the Inseego LAN IP address.

Leave a comment

Your email address will not be published. Required fields are marked *

error: Sorry, copy/paste is disabled