Two Internet Circuits Are Not Redundancy Until You Prove the Paths
Buying a second internet circuit feels like a clean continuity decision. One carrier fails, the other takes over, and the business keeps moving.
That is the plan, anyway.
The trouble is that two services can still share the same failure. They may enter the building through the same conduit, ride the same local fiber, depend on the same upstream network, terminate on the same equipment, or lose power together. The carrier names on the invoices can be different while the actual path is not different enough.
Do not buy backup internet by counting logos. Buy it by identifying failure domains and requiring evidence.
Start with the business requirement, not the circuit quote
Before asking providers for options, decide what the backup connection must keep running.
A secondary circuit sized for email and basic web access may be fine for a small office. It may be useless for a contact center, warehouse, clinic, retail location, or cloud-dependent operation that needs voice, payment processing, cameras, VPN traffic, and line-of-business applications during an outage.
Document four things:
- Which workflows must continue when the primary circuit fails
- How long those workflows can tolerate disruption
- How much bandwidth and what network behavior they require
- What the business is willing to pay for that continuity
That last point matters. Full physical diversity can require construction, a different building entrance, wireless service, or a second provider with its own facilities. Not every site needs the most expensive design. Every site does need an honest design.
NIST’s contingency-planning guidance recommends evaluating systems and operations to determine continuity requirements and priorities. Apply that principle to connectivity. Protect the workflows that cannot tolerate the outage instead of buying the same backup package for every location.
Different carrier names do not prove diversity
A quote usually tells you the provider, bandwidth, term, access type, estimated install interval, and monthly price. It may not tell you who owns the local facilities or where the physical route runs.
One provider may resell another carrier’s circuit. Two providers may lease facilities from the same underlying network operator. Separate fibers may sit in the same cable. Separate cables may share the same conduit, utility pole line, bridge crossing, manhole, or building entrance.
None of this means the services are bad. It means the word “diverse” needs a definition.
Ask each provider:
- Who owns the last-mile facility serving this address?
- Is any part of the access circuit resold or delivered by another carrier?
- Do the proposed primary and backup services share a central office, point of presence, local fiber segment, conduit, pole route, or building entrance?
- Can the provider supply a route-diversity statement or design diagram?
- Which parts of the answer are confirmed, and which are based on preliminary engineering?
- Can the committed diversity requirement be included in the order or contract?
A salesperson saying “it should be diverse” is not evidence. A serviceability check is not a route survey. A map drawn before engineering may change during construction.
Write down what the provider is promising and when it will confirm the final design.
Check the building, not only the carrier network
Carrier diversity can disappear in the final hundred feet.
Both circuits may enter through one underground conduit and terminate in the same building telecom room. A construction cut near the property, water damage in the entrance facility, or a power problem in that room can take out both services.
Walk the site with facilities and the network team. Confirm:
- Where each service enters the property
- Whether the entrances use separate conduits or physical sides of the building
- Which telecom rooms, risers, and internal cable paths they use
- Where the provider handoff and your equipment sit
- Which electrical panels, UPS units, and generators support the path
- Whether a single maintenance event could interrupt both circuits
You may discover that true entrance diversity is not practical at a leased office. Fine. Do not hide that fact inside the word “redundant.” Use a connection with a different physical dependency, such as cellular or fixed wireless, if it meets the site’s continuity needs.
The point is not to create a perfect network diagram. The point is to know which incident can still take everything down.
Separate the transport from the failover design
A second circuit does nothing by itself. Your firewall, router, SD-WAN platform, DNS, identity controls, and application dependencies still have to move traffic correctly.
Decide whether the design needs active-passive failover, active-active traffic steering, or a manual continuity process.
Active-passive is often simpler. The backup sits ready until monitoring declares the primary unavailable. Active-active can use both links and shift traffic around degradation, but it adds policy and operational decisions. Neither approach fixes two circuits that share the same physical failure.
If you are still choosing the transport mix, compare DIA, broadband, and SD-WAN before deciding that a second DIA circuit is automatically the answer. SD-WAN can manage multiple paths. It does not manufacture path diversity underneath them.
Your design also needs to answer:
- What condition triggers failover?
- Does the device detect total loss only, or also severe latency and packet loss?
- Which applications receive priority on the backup?
- What traffic gets blocked or throttled when backup capacity is limited?
- Do public IP addresses change?
- Will vendor allowlists, VPN tunnels, voice services, and cloud security policies still work?
- What happens when the primary returns?
A circuit can be healthy while the application path is broken. Monitor far enough through the workflow to detect the failure users care about.
Size the backup for emergency operations
The easy buying mistake is matching the primary circuit’s advertised speed without checking what the business needs during an outage. The opposite mistake is buying the cheapest backup and discovering it cannot carry the critical load.
Build an emergency traffic profile.
List each protected workflow, its normal and peak demand, and whether it can run in a reduced mode. During failover, you may pause guest Wi-Fi, large backups, software downloads, video streaming, and other nonessential traffic. Voice, payment, customer service, core SaaS, and security traffic may need priority.
Do not use download speed as the whole capacity model. Check upload capacity, latency, jitter, packet loss, data caps, overage terms, network address translation, static IP support, and any carrier policy that can affect sustained use.
Cellular may be a strong backup where wired paths share too much infrastructure. It also introduces signal, indoor antenna, carrier coverage, capacity, and power questions. Fixed wireless may avoid a local trench but still depend on rooftop equipment and line of sight. Broadband may be cost effective but share more local infrastructure than the proposal makes obvious.
Every option has a failure mode. Pick the combination whose failure modes match the risk you are trying to reduce.
Put evidence and acceptance into the order
Procurement should not treat route diversity as a friendly implementation detail. If the business is paying for it, define what must be delivered.
The order package should identify:
- The intended primary and backup roles
- Required carrier or last-mile independence
- Required path or entrance diversity, where available
- Bandwidth and performance requirements
- IP addressing and routing requirements
- Demarcation locations
- Power and equipment responsibilities
- Installation dependencies
- Acceptance tests
- The remedy if the delivered design does not match the committed design
Have legal or procurement review contractual language and remedies. A technical requirement in an email may not survive a conflict with the signed order.
Also watch the schedule. A secondary circuit may require construction, permits, landlord approval, inside wiring, equipment, or site access. Do not disconnect an existing service because the new provider accepted the order. Keep the old path until the new one is installed, documented, tested, and accepted.
If a carrier dispute or renewal deadline is already compressing the timeline, use a two-track continuity and evidence plan instead of waiting for the incumbent issue to settle.
Test the outage you are buying protection from
The final proof is a controlled failover test.
Do not stop at unplugging one cable and watching a dashboard turn green. Test the business path.
During the test, verify:
- Detection and switchover time
- Critical application access
- Inbound and outbound voice
- VPN and remote access
- Payment or customer transactions, where applicable
- DNS behavior
- Public IP and allowlist dependencies
- Security inspection and logging
- Backup-link utilization
- Monitoring and alert delivery
- Failback behavior
Record the result, including what failed, what required manual work, and how long recovery took. Fix the gaps and run the test again.
Repeat the test after material firewall, SD-WAN, routing, carrier, application, or identity changes. A test from two years ago does not prove today’s path.
Use a simple buying scorecard
Score every proposal against the same evidence:
| Decision area | Evidence to require |
|---|---|
| Business fit | Protected workflows and recovery target |
| Carrier independence | Last-mile owner and upstream dependencies |
| Physical diversity | Route, conduit, entrance, riser, and demarcation details |
| Infrastructure resilience | Separate equipment, power, UPS, and generator dependencies |
| Backup capacity | Emergency traffic profile and performance requirements |
| Failover operation | Detection, routing, prioritization, monitoring, and failback design |
| Contract protection | Written commitments, acceptance criteria, and remedies |
| Production proof | Completed end-to-end failover test |
Mark each item confirmed, partially confirmed, unknown, or unacceptable. Unknown is a real status. Do not quietly convert it into “probably fine” because the renewal date is close.
Two circuits can be a smart purchase. Two provider logos can also create false confidence.
Map the failure domains. Require the provider to show what is actually separate. Test the applications after installation. Then decide whether the remaining shared risk fits the business.
If you are reviewing connectivity contracts or planning a backup circuit, request a Contract & Spend Risk Review. Bring the quotes, current invoices, and network requirements. Catch Advisors will help you identify what is confirmed, what is missing, and what to question before you sign.