Just define a AAA server group as follows (or you cna use an existing one if you have it defined already):
aaa-server protocol tacacs
aaa-server host x.x.x.x
Then under you VPN tunnel-group just assign the aaa-server to it as follows:
tunnel-group type ipsec-ra
tunnel-group general-attributes
authentication-server-group