I do have this option because the endpoint is a ZyWALL USG, which has support for dynamic clients. The solution could however be reformulated to having two tunnels with different priorities. In case the tunnel with the higher priority goes down, the one with the lower priority is activated. In my case their endpoints would be the same, but for others this does not have to be so. Subnet overlaps do not matter anymore when the tunnels are never both active at the same time.