Here's my scenario. I have 2 locations. Each has an ASA that is multihomed to the internet. The sites are connected together L2L style with IPSEC tunnels, but currently only using one tunnel definition (basically the primary pipe at Site A and the primary pipe at Site B). I need to figure out a way to automatically switch over to the secondary pipe at Site A (probably connecting to the secondary pipe at site B) if the primary pipe fails at either location. I've tried this with 2 tunnel configurations and a tracked route, but it's problematic--if Site A tracks a pingable address and switches the routes for the internal interesting traffic for the tunnel, Site B might not see that issue, or see it at the same time. Ideas? If it helps I would note that I have additional sites that would need the same configuration. Any ideas are appreciated. m0b