Hi,
Yes, you can get routes advertised out the vpn3k public/private interface via RIP/OSPF, but they are not going to get encrypted, hence not much use, and this scenario is not going to be possible.
As an alternate, what you can do is to use a router inside the vpn3k, and use gre to encap OSPF/EIGRP on it, this way you can run routing protocol over the tunnel, and watch for the route, if it disappears, you can kick in your bri line.
thx
Afaq