How to configure probes on VPN routes to disable when Ethernet Private Line was up

I need help with a following scenario. Customer has following setup.

Site-HQ to RemoteSite-A they have Ethernet private line connection as well as S2S VPN.

Site-HQ to RemoteSite-B, same setup.

RemoteSite-A to RemoteSite-B, same setup.

How would I configure probes on VPN routes to disable when Ethernet Private Line was up? So VPN routes are only utilized when EPL is down?

Thanks in advance!

Here is what you are looking for. https://www.sonicwall.com/support/knowledge-base/configuring-vpn-failover-using-static-routes-and-network-monitor-probes/170504720505274

I would make sure the VPN is a tunnel interface and implement a routing protocol between the two firewalls. VPN would be a higher cost and would kick in when the ethernet goes down. Just my own two cents.

Thank you all for helping me understand this. :folded_hands:

Thanks. I will look into this KB.

Allows for easy expansion!