Hi, you will have to configure a VPN tunnel if you require ipsec. GRE tunnel are useful if you require routing through your tunnel because they will transmit multicast packets use to maintain routing tables. Have a look at the document below it contain a configuration for VPN tunnel on pix firewall. HTH
As others said, the *best* way of doing this is to use VPN between your PIX firewalls. You'll also want to upgrade your firewall OS and upgrade to the 3DES license (free). Also using two static routes will not work. A static route will never disappear from the routing table so the other route will never "take over". You will need to run a routing protocol internally then set your static route for the VPN a little higher than the IGP AD.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...