Chapter 11 IPsec VPN for FortiOS 5.0 : Protecting OSPF with IPsec : Creating a redundant configuration
  
Creating a redundant configuration
You can improve the reliability of the OSPF over IPsec configuration described in the previous section by adding a second IPsec tunnel to use if the default one goes down. Redundancy in this case is not controlled by the IPsec VPN configuration but by the OSPF routing protocol.
To do this you:
Create a second route-based IPsec tunnel on a different interface and define tunnel end addresses for it.
Add the tunnel network as part of the OSPF network and define the virtual IPsec interface as an additional OSPF interface.
Set the OSPF cost for the added OSPF interface to be significantly higher than the cost of the default route.