We have a 2811 terminating the T1 at our remote office. The 2811 also terminates the VPN tunnel between the remote office and the main office. To provide redundancy for the Internet connection DSL was terminated on the 2811. I configured new crypto map with the exact same settings as the crypto map for the T1 and added a NAT statement for the inside interface to use the DSL interface. When I shut down the T1 interface, the tunnel becomes active on the DSL interface and I can see the status when I do sh crypto isa sa but no traffic is being sent thru the new tunnel. Pings to the internal network at the main office fail.