> Anyway, if I understand your proposal then this solves various kinds of
> single points of failure, but still leaves end users relying on a single
> ISP for service.

  Actually, what I was thinking is that a customer could have conventional
attachments with multiple ISP's (at single or multiple locations), each
with a tunnel to one of the aggrigation points (poosibly different
aggrigation points), and run BGP with private ASN's within the cloud of
the tunneled environment. This would not only provide true redundancy, but
would make transitioning to a new ISP for one, or more, of the connections
trivial--simply re-establish the tunnel. (Must be something I'm missing 

