Insights · Connectivity resilience
Dual-WAN vs. Single-Path Failover: Designing Resilience for Live Events
When venue policy permits dual-WAN — and what disciplined single-path failover looks like when it doesn't. A field guide to building redundancy you can actually prove before go-live.
Every conversation about event-network reliability eventually arrives at the same question: what happens when the circuit drops at go-live? It is the right question — but most teams reach for the wrong answer. They assume that “redundancy” means a second internet connection, and they assume a second connection is always available. Neither is reliably true at a live event. Resilience is not a product you buy; it is a design you commit to, test, and sign off on before the first badge scans.
At LGL Networks, our promise is specific. We run and stand behind your event’s mission-critical network — setup to teardown — so registration, payments, production and streaming stay connected. Standing behind something means we can demonstrate it under failure, not just hope it holds. That discipline starts with an honest read of what redundancy the venue and the calendar will actually allow you to build.
Redundancy is a design choice constrained by the venue
The instinct to drop in a second WAN is correct in spirit. The trouble is that a live event is not a permanent office. The pathways, the demarcation point, the carrier options, and the right to bring in a circuit at all are controlled by the venue — not by the organizer and not by us. A second fiber run that looks trivial on paper may be impossible inside the contract, the timeline, or the building. So the first design decision is never “dual-WAN or not.” It is “what does venue policy permit, in writing, and what can be provisioned before the non-cancellable spend?”
That framing matters because resilience designed against a fantasy of the venue is worse than no plan at all. It creates the appearance of redundancy while leaving a single point of failure no one stress-tested. We would rather scope a disciplined single-path design we can prove than promise a dual-WAN architecture the building won’t allow.
Redundancy you cannot test before go-live is not redundancy — it is a hope with a wiring diagram. The resilience that counts is the failover you have already watched land inside its target window.
When dual-WAN is the right call — and when it isn’t
Where venue policy permits and the pathways exist, dual-WAN is the stronger posture for revenue-critical traffic. Two diverse upstreams — ideally with genuine path and provider diversity rather than two strands sharing one conduit — let the edge fail over without a human in the loop. For an event carrying live payments, registration, and streaming, that automatic cutover is the difference between a blip and an outage that hits the registration desk.
But “diverse” has to mean diverse. Two circuits that terminate in the same demarc room, ride the same building entrance, or trace back to the same regional carrier are not two paths — they are one path wearing two invoices. Part of the assessment is verifying that the second WAN buys you real independence rather than the comfort of a redundant-looking line item.
Dual-WAN is the wrong call when it is unauthorized, undeliverable in the setup window, or so constrained that it cannot be validated before go-live. In those cases the honest, accountable move is a single approved underlay with a clearly defined failover scope at the LAN and edge — and a written statement of exactly what that scope does and does not cover.
What disciplined single-path failover looks like
When a single underlay is the only authorized option, resilience moves inside the perimeter we control. The WAN may be one path, but the network behind it should not collapse on a single component. Disciplined single-path design typically includes:
- Hardware and power resilience at the edge — protected power and spares for the active gear we operate, so a device or supply failure does not take the event down.
- LAN-layer segmentation that contains faults — payment, production, registration, attendee, contractor and management traffic isolated so a problem in one zone does not cascade into the registration desk or the stage.
- Wired-first critical paths — payments, registration, encoders and show-control on cable, not contending for air, so resilience does not depend on RF conditions in a crowded room.
- A defined degraded-mode plan — what stays up, what queues, and who is notified if the single WAN is impaired, documented and agreed in advance rather than improvised at go-live.
- Onsite engineering and NOC monitoring — a human on site and eyes on the network remotely, because single-path designs trade automatic WAN cutover for faster, accountable human response.
The point is not to pretend a single WAN equals two. It is to be explicit about the failure modes we have engineered against, and equally explicit about the one we have not — so the organizer is making an informed decision instead of inheriting a surprise.
Comparing the two postures honestly
| Consideration | Dual-WAN (where permitted) | Approved single underlay |
|---|---|---|
| WAN-loss recovery | ✓ Automatic cutover to diverse path | — No automatic WAN backup; human + degraded-mode plan |
| LAN / edge fault containment | ✓ Segmented + redundant edge | ✓ Segmented + redundant edge |
| Requires venue authorization | ✓ Yes — second pathway in writing | ✓ Yes — underlay in writing |
| Provable before go-live | ✓ Failover drill in acceptance test | ✓ Degraded-mode + edge tests in acceptance |
| Honest limitation | Diversity must be real, not two strands in one conduit | Single WAN remains a known single point of failure |
Whatever the design, it gets signed off before go-live
The discriminating practice is not which topology you chose. It is that the resilience design — dual-WAN cutover window or single-path degraded-mode plan — is verified in a documented pre-opening acceptance test before the event opens. That test confirms segmentation holds, that failover lands inside its target window where dual-WAN exists, that the critical-system redundancy we promised is actually live, and that monitoring is reporting. Anything we cannot demonstrate in that window, we do not claim.
A note on scope, because honesty is the brand: bonded multi-carrier aggregation, LEO satellite, and tactical fiber runs are powerful resilience tools, but we treat them as capabilities engaged only when a specific contract requires and the venue permits them — not as standard inclusions we imply on every job. We stand behind the network and transport we operate — availability, redundancy and segmentation — not the vendor applications that ride on it. We would rather scope resilience we can prove than market resilience we cannot.
That is what it means to be one accountable operator instead of finger-pointing across venue, AV, payment, registration and carrier vendors. The resilience design is ours to defend — in writing, in the acceptance test, and on site through teardown.
Keep reading
Related insights
Who owns the network when the event goes down?
Why a single accountable operator beats a room full of vendors pointing at each other when revenue-critical systems fail.
Read the article →The pre-opening acceptance test
The documented checks that prove segmentation, failover and monitoring hold — before the event opens.
Read the article →How venue authorization de-risks deployment
Why written venue permission comes before any non-cancellable spend — and how it shapes what resilience you can build.
Read the article →Design resilience you can prove — not just promise
We run and stand behind your event's mission-critical network — setup to teardown — so registration, payments, production and streaming stay connected. Start with an Event Network Risk Assessment.