As per my understanding site-to-site IPSec forms Tunnel only when interesting traffic is generated from actual source (say spoke towards DC) thats match ACL and RRI is used at DC end. I want to understand is there anyway to achieve bi-direction IPSec tunnel in RRI technology or in any other technology in site-to-site VPN where headend routers are in redundancy.