Hi @Andi1, is there more to your network on the LAN side, like a switch or something? If you just have a link between the MXs then it’s not a recommended solution.
If you only have a single link to the primary MX I’m going to suggest that when this is failing you are getting a dual active scenario as both devices believe they should be active - i.e. neither is receiving a VRRP keep-alive from the other. Ultimately this is likely what is causing the issue, not sure exactly how, but guessing it’s likely to do with the VPN tunnels that are brought up and the routes that end up in the hub routing table.