I have a situation where my MX is the hub of a VPN mesh but it sits behind an ASA using dual ISP links for redundancy/backup using SLA monitor. The ASA's SLA feature will put the secondary link in the routing table if the primary fails, but both interfaces are up/up. I have seen where the MX device registers the backup IP/interface with the cloud, and starts forming VPN tunnels to remote sites with this IP, causing an async route and the VPN tunnel to fail.
I was thinking there might be a way to keep the ASA's interface in shutdown until it needs to fail over but I don't see a way to do that. I also don't see a way to for the MX device to stay on the primary ISP link until a failover occurs. Does anyone have any suggestions?