Add the second peer to the crypto map and create a second tunnel-group with the second IP.
crypto map VPN 10 set peer
tunnel-group type ipsec-l2l
tunnel-group ipsec-attributes
pre-shared-key *****
tunnel-group type ipsec-l2l
tunnel-group ipsec-attributes
pre-shared-key *****
When the primary fails on the ASA, the tunnel will try to establish on the second peer ip.
Good luck.