Failover for Branch Connections in Secure Access Data Centers
For redundancy, customer branch devices should connect to both the primary and secondary hubs in Cisco Secure Assess data centers. They must have tunnel auto-reconnect enabled on the branch device and have a failure detection mechanism like Dead Peer Detection (DPD), IP SLA, BGP timeout, depending on their use case.
Under normal conditions, traffic flows through the primary data center. If the primary data center fails, traffic will route through the secondary data center. Switchover time depends on the nature of the primary tunnel failure and various timers.