IPSEC loop

I have 2 locations, each having 2 uplinks from 2 providers. provider 1 on both locations and provider 2 on both locations.

all uplinks are FO.


I want to configure 2 ipsec (with ah) policies + eoip + bridge so that both location are in the same layer 2 domain (computers in location 2 should be able to get ip from dhcp location 1).

i want to have 2 eoip tunnel over ipsec, but that would create a loop. how can i overcome this?

thanks.

Enable RSTP to prevent loops