You can configure a static route as a secondary route in case the VPN tunnel goes down. When defining the route policies, the Allow VPN path to take precedence option allows you to create a secondary route for a VPN tunnel and gives precedence to VPN traffic having the same destination address object. This results in the following behavior:
To configure a static route as a VPN failover
Click + Add.
Type a descriptive name for the policy into the Name field.
Add the description in the Description field.
Select the Type and Metrics from the respective fields.
Select the appropriate Source, Destination, Service, Gateway, and Interface.
Define Metric as 1.
Select Allow VPN path to take precedence.
Click Save.