Hi Bro
Please do correct me if I’m wrong, your question is, if Site1 is completely down, how do LAN users in Site 3 access to the LAN in Site 1 via Site 2, am I right so far?
I’m assuming Site 1 and Site 2 are sharing the same LAN i.e. Hub and Site 3 is a spoke.
Are you using Cisco FW or Cisco Routers as the VPN Servers, in this scenario? If you're using Cisco Routers, then you should look into Cisco IPSEC over GRE solution but if you're using Cisco FW, then you could employ something like this;
crypto map VPN 10 match address TEST
crypto map VPN 10 set peer 202.188.1.5 203.198.76.3
crypto map VPN 10 set transform-set SITE-to-SITE_VPN
Warm regards,
Ramraj Sivagnanam Sivajanam