When policy route is used for failover IP-Sec tunnels die. Why?

I am a lucky guy! I have two fiber hookups to the internet. One is 500M/bit, te second 100M/bit. I would like to use the 500 as the main pipe and the 100 as a failover.

Therefor I have created two policy routes where if the 500 (Ge3) fials, the 100 (Ge2) takes over. In theory this works fine as I also changed the trunk to spill-over (user configured). When I activate the policy routes my IP-Sec VPN tunnels die however.

I have been looking if I can find a way to leave the tunnels up and running but cannot find a way.

What can be the problem?

