Hello,
There is not enough information in Your OP to offer You a solution. The following points need to be clarified:
1/ do You expect Site A SRX210 to connect to Site B SRX 210 _ONLY_ when Site B SSG is down, or
2/ should Site A SRX 210 have 2 established IPSec tunnels to both Site B SRX 210 and Site B SSG at all times, and let the OSPF|BGP running inside IPSec tunnels figure out what is the best route from Site A to Your Site B intranet?
3/ if yes to 1 above, do You expect the Site A SRX210 to fail back to Site B SSG when Site B SSG is back up after outage? or
4/ are You happy with manual failback?
My personal preference would be [2], and I did such designs for 100+ sites with BGP across the tunnels, works fine for 3+ years.
HTH
Thx
Alex