A rural business customer had a recurring coax outage and loses more than $1,000 per hour when they go offline. Their carrier provided a Verizon XC46BE 5G gateway as a temporary backup. It was easy to connect by Ethernet to the FortiGate, but although a direct laptop test reached roughly 220 Mbps down and 40 Mbps up, the entire office only got around 10 Mbps with approximately 500 ms latency. There were about ten active users, and the device was advertised as supporting around twenty.
The gateway has a battery, and the network equipment is already on UPS power. The customer is considering keeping it as WAN2 and configuring automatic FortiGate failover. Has anyone had better results with Verizon or another 5G gateway, Cradlepoint, Ubiquiti, or a satellite service such as Starlink? This would be strictly for business continuity rather than replacing the primary wired connection.
4 Answers
Cradlepoint is probably the most common business-oriented option for this. We use 5G Cradlepoints as secondary circuits and connect them directly to the spare WAN port on the firewall or SD-WAN appliance. They work very well when the site has a strong signal, and some models can use multiple carriers or aggregate connections. The important part is placement: put the antennas or gateway where reception is best, not necessarily beside the firewall. Speeds and latency can still vary dramatically with tower congestion and building construction.
Don’t judge every cellular backup connection by that one test. Fixed wireless gateways often perform much better than phones because they have better antennas, higher-priority business plans, and are designed to stay in one optimal location. On the other hand, a speed test directly from a laptop can look great while the office experiences poor performance because of NAT, firewall inspection, congestion, or multiple users sharing the link. Test during busy hours and measure packet loss and latency over time, not just peak download speed.
If the local Verizon tower is overloaded or the signal is marginal, try the carrier with the best coverage at that exact building. A different provider may be more useful than a more expensive modem.
Starlink is a good alternative when cellular coverage is unreliable, especially at remote or disaster-prone sites. It can provide a useful secondary WAN with reasonable throughput, but the dish needs a clear view of the sky and cannot simply be placed indoors like a cellular gateway. Weather, power, installation space, and satellite obstructions need to be considered. For a normal office with strong 5G coverage, a business cellular modem is usually simpler; for a site where every nearby tower is poor or unavailable, Starlink may be the better backup.
We use Starlink as either the primary or backup connection at several locations. It works well, but the antenna has to be outside with a clear sky view, and the firewall failover rules should account for its brief interruptions rather than switching back and forth constantly.
The FortiGate can handle this without another failover appliance. Put the cellular gateway in WAN2, disable its Wi-Fi if it is only being used as an uplink, and configure SD-WAN health checks against several reliable destinations. Fail over based on packet loss and latency, not just whether the gateway responds. Also add bandwidth limits and block nonessential traffic while on backup so one synchronization job or video stream doesn’t consume the connection. A cellular plan with a static or usable public IP may be worth considering if the business needs inbound VPN access.
We use essentially this setup with Verizon business service. It is not as good as fiber, but users generally do not notice the failover once the SD-WAN rules are tuned. Check the carrier plan carefully, since throttling and data thresholds matter as much as the modem.

That makes sense. The Verizon unit had several large external antennas, but I suspect the building location and local tower load were the real problem. I’ll look at business Cradlepoint models and better antenna placement.