I have private PPP link between two sites connected to two L3 switches as routed port. Traffic between these two LANs is sailing smoothly via the PPP link bidirectional. I have also implemented IPSec VPN tunnel between the same two sites via the internet as backup in case the private link failed. In this case, the tunnel is working great.
When the PPP link restored on the L3 switch the LAN traffic continue to pass through the tunnel.
How do I configure the firewall or the switch to drop the IPSec tunnel when the PPP link restore?
The trick here is my internet ASA5520 firewall at both sites doesn’t know this route because it is part of the LAN. Can sla monitor and tracking with ACL will work? If so, any advice
PPP link address 10.10.10.1/30 on L3 switch
ASA 192.168.1.1 outside
PPP link address 10.10.10.2/30 on L3 switch