Drop-in Mode lets a Peplink Balance slide transparently between your existing firewall and its upstream connection — same subnet, same IP addresses, nothing renumbered. The network barely notices the new box, but from that moment on it has SpeedFusion bonding, extra WANs, and failover it never had before. This is how you add SD-WAN to a network you are not allowed to re-architect.
The problem it solves
Plenty of sites have a firewall that cannot move: it terminates the VPNs, it holds the public IP, compliance paperwork names it, or another vendor manages it. Rebuilding that edge to add cellular backup or bonding is a project nobody will approve. Drop-in Mode sidesteps the whole argument — the Balance bridges its designated WAN and its LAN onto the existing subnet, the firewall keeps its address and its job, and the Peplink quietly adds its multi-WAN intelligence in the middle.
How it works
- One WAN (typically WAN 1) and the LAN are bridged into the shared drop-in subnet — the Balance sits on that subnet like a smart patch cable.
- Your firewall keeps its public/static IP and remains the default gateway story for the LAN behind it. No device behind the Balance is renumbered.
- The other WAN ports stay fully functional: add cellular, a second ISP, or Starlink, and use outbound policy and SpeedFusion to steer or bond traffic across them.
Setting it up
- On the Balance, go to Network › LAN and enable Drop-in Mode.
- Define the shared subnet and the upstream gateway IP (your existing modem/router).
- Cable it inline: upstream connection → Balance WAN 1, Balance LAN → your firewall’s WAN port.
- Add your extra WANs (cellular, second ISP) on the remaining ports and steer traffic with outbound policy.
Field note
Drop-in is the answer we reach for in retail, healthcare, and franchise networks where the firewall is corporate-managed and untouchable. The site keeps its security stack and its paperwork; we add bonding and cellular around it. Nobody has to schedule a change window for the firewall — which is usually the difference between the project happening this week and never.
Gotchas
- Only one WAN participates in the drop-in bridge; every other WAN operates in normal NAT mode behind it.
- A handful of router features that assume NAT on the drop-in WAN are unavailable while Drop-in Mode is active — review what your design needs before committing.
- Test the failure story: pull the primary upstream and confirm sessions actually ride the backup WANs the way you expect.
Watch it done
Related reading
- Recipe: Drop-in Mode step-by-step — the worked example with screenshots.
- IP Passthrough — the other “don’t touch my firewall” option, for when the firewall must own the WAN IP directly.
- All WAN options & technologies