Hi
I'm running a pair of HA 5585-X firewalls in multi context mode, one of the security context is configure with an IPSEC tunnel to two sites using a primary/secondary peer crypto map for backup VPN traffic(all out the same interface). As these are running multi context SLA monitor is not support therefore I can not use VPN prempt (http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118087-technote-asa-00.html) to failback the primary VPN when the remote peer IP address is again reachable.
Does anyone have a way of do this with EEM without using SLA Monitor?
Thanks
Gavin