We do this all the time with IPSec encrypted IPIP tunnels. The main site has two internet connections, and a couple properly costed recursive routes. Each site has two IPIP tunnels with routes checking the far end of the IPIP. It works like a charm, people don’t even notice they’ve failed over.
But right now we’re in a demo situation with no choice but to use pure IPSec, so no routable interfaces. Thanks to Comcast’s brilliance, the demo of our voice product isn’t going so well. They’re up for a couple of hours, and then hard down. We’re trying to avoid just switching over to the T1 because they hit it pretty hard and the RTP will get choked out inbound. Plus the problem solving will make us look good.
So I set up a lab and tried to get this failover working, but despite the WAN failover working like a charm the IPSec can’t decide which SA to use. I’ve pretty much given up hope after some googling and fiddling, but maybe someone has made it work?
I know Mikrotik has done a lot of work on some possibly relevant features, so I’m using 6.23 in the lab.