Please bear with me as I explain.
I'm setting up a new site-2-site VPN tunnel with another company where I need to use the VPN tunnel as our primary means of communication between us. We also have a direct routed connection with this company, however, over a slower link and using static routes.
I need to setup the VPN tunnel to be our primary connection method unless the VPN tunnel loses connection and is unable to reestablish, then fall back to the direct DS3 connection.
I know that if I do this using RRI, the route never gets removed even if the connection isn't established. My thought was to use an IP SLA and track a device on the other side of the VPN tunnel but I'm confused on how to make this happen.
We are running EIGRP on this ASA 5585-X if that helps/matters and this firewall is dedicated to just VPN sessions.