IPSec Redundancy - Tunnel Mode

I have two ipsec tunnels setup with a partner who uses cisco. Tunnels are up and working. Also, I know this would be easier with Transport mode using a GRE or IPIP tunnel, but it is hard to convince a customer of that, most of the new generation of Cisco guys are really Cisco Wizard pros. I am aware that interesting traffic is determined before routing, but isn’t there any way to persuade traffic to use a second tunnel if it cannot cross the primary ipsec connection. It is tough, because even if the ipsec tunnel hasn’t negotiated phase I and II, the policy still directs traffic towards it regardless of its state. Im sure i could create a pre-NAT sub-net and route it towards a loop-back interface with a higher cost path, but that is really messy. I just find it it hard to believe there is no solid solution for ipsec redundancy. Don’t laugh at my Linux diagram skills. ( its all god gave me to work with.. LOL ) Looking at the diagram, traffic does not route to the second router [ MK2] , because the policy exists on both routers and [ MK1 ] intercepts the traffic before routing takes places and forwards traffic. I do realize i could easily go out Tunnel 2 where the first hop resides, but how would you get traffic to route Tunnel 1 if the ipsec Tunnel failed. Regardless of what tunnel i use, i still need a way to failover traffic.
Any help is appreciated to address the existing problem. No could of, should of, or would of’s, since that is not constructive to the issue at hand.


| Tunnel 2 ( IpSec) [ Cisco 1 ]
|
[ local node ]------ [ MK 1 ] ------ [ MK 2 ] ------------------------------------------ [ Cisco 2 ]
Tunnel 1 ( IpSec ) -