Core issue
This happens because tunnel protection is not supported in crypto connect mode on the CAT 6500.
The Tunnel Protection IPSec profile does work on the CAT 6500, but only for one tunnel.
Resolution
As a workaround, use the crypto map command and plain Generic Routing Encapsulation (GRE) tunnels without the tunnel protection command on them.
Note: Tunnel protection works only in VRF mode.
Refer to Configuring the IPSec VPN SPA for additional information.