Hi,
May be you have been provided with 2 public IP addresses because one is the failover for the other. In that case, you can
configure 2 vpn peer for the same crypto map.
crypto map MYVPN 1 ipsec-isakmp
set peer PUBIP_ONE
set peer PUBIP_TWO
set transform-set TRANSFORM-SET
match address 100
qos pre-classify
In that case, the router would try to negociate the VPN with the first IP and if it fails, it would try with the second.
If the tunnel traffic is initiate by the ASA, any of the two addresses that begin to negociate the tunnel would managed to negociate.
Vincent