Devices and Networks Network Configuration – WAN Aggregation + Failover with Mikrotik + Firewall

Hello everyone,

I’m trying to finalize my network setup, but so far, I’ve received conflicting opinions, and I’d like to clarify things. Specifically, many seem to struggle when discussing Starlink, which is essential for me as I live in a mountainous area.

Current Network Setup:
• Primary Connection: Starlink Residential Gen 2, which I want to manage without the provided router.
• Backup Connection: INTRED FWA 100 Mbps, distributed across multiple locations via a radio link.
• Switches: 2x Mikrotik CRS326-24G-2S+RM (one actively handling traffic).
• Router (Planned Installation): Mikrotik L009UIGS-RM on the INTRED network.
• Firewall: I have added MikroTik L009UIGS-RM devices for security, but I’ve received mixed feedback on their effectiveness.

Main Issues:

  1. WAN Aggregation (Starlink + INTRED): Improve speed and stability.
  2. Efficient Failover: Currently, if one connection drops, the entire network collapses instead of seamlessly switching.
  3. Firewall: Some say Mikrotik switches cannot act as firewalls, while others disagree. I need clarity.
  4. VLAN or IP Reorganization: To prevent network congestion.

I’d like to find the best approach to achieve a stable and efficient network while avoiding unnecessary complexity or excessive investments.

If anyone has direct experience with this setup or can offer guidance, I’d appreciate any input!

Thanks!

WAN aggregation does not improve speed.
Any singular sessions speed is limited by the WAN being used for that session.
What you get is MORE bandwidth overall to share with users, so that there is less bottleneck.
Additionally you get redundancy in that being separate Providers, if one is not available you have a backup.

You do not need any additional firewall the l009 router is quite capable of handling firewall responsibilities.
My only beef with the L1009 is the limited throughput for routing of around 300ish Mbps with a reasonable set of firewall rules in place.
I have no idea what the two ISP provide in terms of bandwidth.
Certainly if greater than 300 in total, I would move to an AX3 budget choice or RB5009.