A common request is to have all network traffic exit and return on a singular WAN interface (primary), but still have other interface(s) take over during a failure or outage, then have traffic return to the primary interface. This configuration requires WAN Balancer as well as WAN Failover.
WAN Balancer must be configured to send all traffic out of the specified primary interface. Go to WAN Balancer > Traffic Allocation to set your weighting: 100 for the primary WAN and 0 for the backup. This instructs the NGFW to use the primary WAN for all internet-bound traffic.
WAN Failover then must be configured to have tests per each interface, to test for any failures on any interface (Apps > WAN Failover > Tests). This can be viewed more in-depth under https://wiki.untangle.com/index.php/WAN_Failover. WAN Failover takes precedence over WAN Balancer in that when an interface failure occurs, the WAN Balancer rules that were previously configured no longer apply and all traffic will use the next listed interface indicated by interface ID (below shows  for external, and  for Failover.