07-29-2022 02:45 AM
You must redirect IPSec traffic throught to tunnel with staticly or PBF metod. Static routing with different metrics should be work.
But if you want to use PBF with tunnel monitor profile which monitoring remote Phase-2 site IP, you should use different zone between IPSec tunnels.
Check this kb for dual redundant IPSec,
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POO0CAO