I have seen customers terminating both the VPN tunnels on single public facing IP address on ASA with Amazon setup. The point of setting other tunnel is leveraging redundancy so you can terminate the VPN on single interface but that would provide redundancy only on Amazon side, not on ASA side.
If you need to make it fully redundant, I ll suggest to setup another interface on ASA with public IP although if you just need to get it up and running, one public interface on ASA is enough.
Regards,
Dinesh Moudgil
P.S. Please rate helpful posts.
Cisco Network Security Channel - https://www.youtube.com/c/CiscoNetSec/