The tunnel is not dropped, but instead the packets that were encrypted will get dropped. Usually higher layer protocols capable of handling retransmissions will take care of the dropped packets. Same reason why Voice applications does not recommend CAR (rate-limitting) as a effective means for throttling bandwidth, as voice cannot handle dropped packets..
Sankar Nair
UC Solutions Architect
Pacific Northwest | CDW
CCIE Collaboration #17135 Emeritus