Our current situation is that we have an operational VPN tunnel between a Palo Alto PA 3020 at our primary site and a Cisco ASA 5505 at our satellite site. We have implemented ISP redundancy and redundancy for this tunnel on the PA 3020. I need to know how to add to the existing ASA5505 config so that if the primary site fails over to the secondary ISP connection the Cisco will switch the tunnel to the secondary peer IP address and I have never done this before. We are not concerned with any type of internet redundancy at the site with the ASA. It's only one way so that if the primary ISP goes down at the Palo Alto site the Cisco sees this and switches it's end of the tunnel to the new peer IP. Hope this is all clear. Thanks.