When fabric connect is down where does the L2VSN route to? I didn’t create a static route for the L2VSN but there is a quad zero route pointing to the upstream FW where the ISP lives. Anyone have experience with L2VSN HA? I want to build path redundancy for a L2VSN - primary path is private circuit and backup would be VPN IPSec tunnel. I don't need fabric capabilities for this traffic so routing over the tunnel would be fine. Both circuits on the far end terminate essentially on a FW where the IP GW lives.