ISP1 connected to Mikrotik CRS125 (ver. 6.37) It's my core switch/router and link to the internet for Users.
ISP2 connected to Cisco PIX515E. It's my edge firewall-router for Servers and IPSec termination point.
I have branch office (Cisco 892) that was connected through Cisco PIX515E through ISP2, but there slow ISP(2) and I decided to build IPSec to branch office through IPS1 (fast internet) directly from Mikrotik. I've made it and IPSec between Cisco 892 (branch) and Mikrotik CRS125 (main office) works.

Now I trying to setup redundency on the case if ISP1 will fail. I configured route tracking on Mikrotik, Cisco PIX and Cisco 892 (branch). When I disconnect IPS1 route tracking works fine, but traffic unable to reach Branch-office until I disable ipsec-policies on Mikrotik =(
How I can disable ipsec-policied on Mikrotik automatically when ISP1 is failed and route tracking to branch is triggered?