Designs for dual power failover in modem pools usually prepare for the wrong event. Most teams plan for a complete loss of supply, while the more common case is a partial failure that leaves the equipment running at a voltage it does not like.
This article covers what dual power protects and what it does not, why sizing has to come from peak draw, what transfer behaviour means for the queue, the choice between a second feed and a battery, and the testing that turns a power design from a drawing into a demonstrated capability.
What does dual power failover for modem pools actually protect?
The supply path, and only the supply path.
A second feed protects against the failure of a power supply, a breaker or a feed, and it protects against nothing else on the site.
That distinction matters because dual power is often bought as a general resilience measure. It does not protect against a failure of the cooling that keeps the room habitable, a failure of the network path the equipment depends on, or a failure of the site itself. Each of those removes the service regardless of how many feeds are present, and each requires a different design decision.
What dual power does well is remove the single most common hardware-level failure in a rack: one supply or one feed. The relevant resistibility and environmental expectations for telecom equipment are described in the ITU-T K.20 and ITU-T K.21 recommendations, with the underlying test regime in ITU-T K.44, and they are a useful reference for what equipment is expected to tolerate rather than for how a room should be arranged.
| Failure | Does dual power help? | What addresses it |
|---|---|---|
| One power supply fails | Yes | Dual supplies |
| One feed or breaker fails | Yes | Second feed on a different circuit |
| Whole site loses power | Only with a battery or generator | Local energy storage |
| Cooling fails | No | Thermal design and monitoring |
| Network path fails | No | Redundant connectivity |

Should the supply be sized from idle or peak?
From peak, measured rather than calculated.
A pool draws far more when every module transmits at once than it does at rest, and a supply sized on the idle figure will sag at exactly the moment it is needed.
The measurement is straightforward and rarely performed: read the current at the rack feed at idle, then during a full campaign, and record both. The difference is the figure the supply, the feed and the transfer equipment all have to accommodate, and it is usually several times the idle value. Where the equipment is specified against a harmonised terminal standard such as ETSI EN 301 511, the conditions assumed by the specification are the conditions the installation should reproduce.
Two refinements change the answer. The first is duration: a peak that lasts a second and a sustained load at eighty per cent of it are not equivalent for anything with a thermal or storage element. The second is margin: sizing exactly to the measured peak leaves nothing for a module that draws slightly more than its neighbours, and a small margin is cheaper than a fault that only appears during the busiest hour of the month.
Transfer behaviour and the gap in between
Some transfer is clean, and some is not.
Where the equipment holds both feeds simultaneously, the loss of one is invisible; where a switch moves the load from one feed to another, there is an interval during which the load has neither.
That interval is the detail that determines whether a power event is a nuisance or an outage. A pool whose modules restart during a transfer loses whatever was in flight, re-registers every card and spends time recovering, and the recovery is longer than the transfer itself. A pool whose modules ride through the transfer carries on. The two installations can look identical on a drawing and behave completely differently.
Establish which behaviour the equipment has before designing around it. The relevant question is whether the modules can tolerate the transfer interval, which is a property of the module and its supply design rather than something to be assumed. Where the answer is unknown, test it: a controlled transfer during a quiet period answers the question in minutes and produces a number the rest of the design can be based on.
The last item on the checklist is the one that keeps the rest accurate: name the person who owns the power design and the review date. A design without an owner drifts as feeds are re-labelled, breakers replaced and units added, and the drift is invisible until a transfer is attempted in earnest.
What happens to the queue during a transfer?
It survives if it lives above the equipment.
Messages held inside a device that restarts are lost with the restart, while messages held in the application are unaffected by anything that happens to the supply.
This is the same principle that applies to any redundancy design, and it matters most for power events, because a power event tends to be short and complete: everything at the site stops at once and comes back within seconds. A queue above the equipment converts that into a pause, and a queue inside the equipment converts it into losses that are difficult to reconstruct because the record of what was in flight went down with the device.
Where a device is expected to restart, the recovery behaviour deserves as much attention as the power design. Retry suppression during the restart avoids duplicate submissions, and a defined expiry prevents a queue from filling with messages that are no longer useful. Registration has to complete before traffic resumes, and the states involved are defined in 3GPP TS 24.301, which is worth knowing when estimating how long a restart actually costs.

Battery versus a second feed
They cover different failures and are not substitutes.
A second feed covers the failure of the first feed or its protection, while a battery covers the failure of the supply upstream of both.
The choice is usually driven by the duration of the event being designed for. A transfer to a second feed is fast and covers a breaker or a supply failure. A battery covers a short utility interruption of minutes, and it is sized on the load in watts and the time required, which is where the peak measurement from earlier becomes relevant again: a battery sized on idle draw will not hold the peak.
Where both are present, the interaction matters. A battery that is not tested is a battery whose capacity is unknown, since capacity degrades with age and temperature, and the first time the capacity is measured is usually the first time it is needed. A scheduled discharge test is the only way to keep the number current, and it belongs in the maintenance calendar rather than in the design document.
Testing the transfer rather than the equipment
Test by removing a feed, not by inspecting the rack.
A dual-feed installation is demonstrated by transferring the load deliberately and measuring what the equipment did, including how long the interruption lasted.
Three figures should come out of the test: the duration of the interruption as seen by the equipment, the number of messages lost, and the time until the pool was delivering again. The third is always the largest and is the one that matters to a service commitment, because it includes registration and queue recovery rather than only the electrical event. Physical and environmental controls that support this kind of design are organised in NIST SP 800-53 Rev. 5, and they are a useful structure for recording what the installation is designed to tolerate.
Run the test on a schedule and after any change to the power arrangement. A transfer that worked at commissioning can stop working when a feed is re-labelled, a breaker is replaced or a supply is swapped for a different model, and none of those changes are recorded unless someone writes them down.
A power design checklist
The checklist covers the decisions that are cheap to make before installation and expensive to change afterwards, in the order they are usually settled. Two of the items, the independence of the feeds and the size of the circuit, determine what the deployment can survive; the rest determine how quickly a fault is diagnosed and repaired.
- Measure idle and peak current at the rack feed and record both.
- Size supplies, feeds and any battery from the peak figure with a margin.
- Confirm whether the equipment rides through a transfer or restarts during one.
- Establish where the message queue lives and confirm it survives a restart.
- Define retry suppression and message expiry for the restart case.
- Test the transfer and record interruption duration, losses and recovery time.
- Schedule discharge tests for any battery and record the measured capacity.
- Re-test after any change to the power arrangement.
Radio characteristics under load are described in 3GPP TS 45.005, and they explain why the peak figure is not a rounding error: transmission is the load, and the load is what the power design has to carry.
Finally, record what the design assumes about the site. A plan that protects the pool against a feed failure and says nothing about cooling, connectivity or access is not wrong, it is incomplete, and the incompleteness surfaces as an argument during an incident about whether the outage was in scope. Writing the assumptions down takes ten minutes and settles that argument in advance.
Measure the peak before you size the supply. Send your rack load figures, transfer behaviour and battery requirement to service@telarvo.com, or review the published configurations on the SMS modem range and the SMS modem solution page. Telarvo publishes the SK-SMS gateway range, the TYH modem pools and the TGW SMS machine on its product pages, and the configurations referenced above come from those listings.
FAQ
Does dual power remove the need for a battery?
No, they cover different failures. Dual feeds protect against a failure of one feed or its protection, while a battery covers an interruption of the supply upstream of both. Where the event being designed for is a utility interruption of minutes, only local energy storage addresses it. The two are complementary, and the choice depends on which event the service commitment names.
Why did the pool lose messages during a power transfer?
Because the messages were held inside equipment that restarted. A transfer that interrupts supply causes devices to reboot, and anything in flight is lost with the reboot. Keeping the queue above the equipment converts the same event into a pause rather than a loss. The application then decides what to resend, which is a decision it can make with evidence.
How long should the pool take to recover after a power event?
Measure it rather than estimate it. Recovery includes the electrical transfer, the device boot, registration on the network and queue drain, and the last of those is usually the largest. Record the total from a real test, because it is the figure a service commitment is judged against. Repeat the measurement after any change to the power path. The same test also shows whether the two paths behave the same way, which is not guaranteed.
How often should a battery be tested?
On a schedule, because capacity degrades with age and temperature and an untested battery has an unknown capacity. A discharge test at a defined interval keeps the figure current, and the result belongs in the maintenance record rather than only in the design document. The test also confirms that the load is still connected to the battery it is supposed to protect.
{
“@context”: “https://schema.org”,
“@type”: “FAQPage”,
“mainEntity”: [
{
“@type”: “Question”,
“name”: “Does dual power remove the need for a battery?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “No, they cover different failures. Dual feeds protect against a failure of one feed or its protection, while a battery covers an interruption of the supply upstream of both. Where the event being designed for is a utility interruption of minutes, only local energy storage addresses it. The two are complementary, and the choice depends on which event the service commitment names.”
}
},
{
“@type”: “Question”,
“name”: “Why did the pool lose messages during a power transfer?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Because the messages were held inside equipment that restarted. A transfer that interrupts supply causes devices to reboot, and anything in flight is lost with the reboot. Keeping the queue above the equipment converts the same event into a pause rather than a loss. The application then decides what to resend, which is a decision it can make with evidence.”
}
},
{
“@type”: “Question”,
“name”: “How long should the pool take to recover after a power event?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Measure it rather than estimate it. Recovery includes the electrical transfer, the device boot, registration on the network and queue drain, and the last of those is usually the largest. Record the total from a real test, because it is the figure a service commitment is judged against. Repeat the measurement after any change to the power path. The same test also shows whether the two paths behave the same way, which is not guaranteed.”
}
},
{
“@type”: “Question”,
“name”: “How often should a battery be tested?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “On a schedule, because capacity degrades with age and temperature and an untested battery has an unknown capacity. A discharge test at a defined interval keeps the figure current, and the result belongs in the maintenance record rather than only in the design document. The test also confirms that the load is still connected to the battery it is supposed to protect.”
}
}
]
}