Advice on Configuring NAT Masquerading with ISP Failover

Hi all,
I have two ISPs in my Sophos UTM 9: a primary and a secondary line. Currently, I’ve set up masquerading for the primary line using the external interface, which was straightforward.
Now, I’d like to configure masquerading for the secondary line in case the primary one goes down.
My concern is that configuring masquerading for the secondary line might interfere with the current setup, potentially causing service disruption.
I'd appreciate your advice. Ultimately, my question is: if I create two NAT masquerading rules, one for the primary and one for the secondary, will Sophos automatically choose the masquerading rule for the active line?

Mauro