hEX Dual WAN failover in front of Orbi RBR760 primary without double-NAT

I want to use a new hEX to failover from dynamic-IP broadband to dynamic-IP LTE whenever Comcast goes down BUT I want to keep the Orbi RBR760 as primary because Netgear ARMOR will not work with Orbi in AP mode. How to config the hEX to avoid double-NAT? a VLAN or 3?

Broadband comes into an Arris Surfboard S33 DOCSIS3.1 and Verizon LTE comes into a Netgear LM1200. I tried using the built-in failover (with ping) in the LM1200 but it refused to fall back after broadband restored.

I’ve watched the Dual-WAN failover videos and read the posts/blogs, but none of them use another router AFTER the failover device. And I know that the “best” way is to put the Orbi in AP mode but that curtails the ARMOR operation. Being a lightweight RoS user, I know enough to know that I don’t know enough…

Double NAT in your case is unavoidable. However, if configured properly, it shouldn’t be a problem at all

Draw a network diagram as it will help understand your setup.

@TheCat12 “configured properly” is my question. Thanks.

It seems to me like you could apply this simple method:

further simplified:

As far as the failover config itself, I was planning on using the following scenario:
Mikrotik Failover Guide for High Availability & Business Continuity

I’m mainly seeking advice on minimizing any negative double-NAT effects from plugging the Orbi (in router mode) into the LAN port of the Mikrotik hEX. Thanks.

Yep, that one is very similar to the simple ones I posted a link to.
Double NAT is double NAT, you either have it or have it not, in your setup you need to have it.
In theory it will increase a little latency, but in practice you won’t likely notice it.