I have a customer who has a VPN connection for backup of their Production site and a VPN connection for their Disaster Recovery site. When we failover the Production Cisco 1720 our core directs their source address to our VPN host router (3845) and it routes that to the BU VPN connection ok but not to the
DR VPN connection if we also fail the BU VPN connection. I understand this is due to duplicate addressing in our encryption ACLs for the BU and DR IPSEC config. We have the Production source address in both ACLs. So my question is, without going to a secondary source ip address for DR (which my host will not support as the client, the application will not know about the secondary dynamically, only manually)how can we still use the one production source address and get that to route to the DR VPN when all the production is down, ie. a Disaster situation??????????