Hi, both solutions would not cause problems
if i'll
choose failover pair then i'll have a problem with dynamic routing.
If you're going Active / Passive you can have dynamic Routing - if you go Active / Active you can´t have VPN anyway so this is no solution
if i'll
choose failover pair then i'll have a problem with dynamic routing.
Afaik (sorry it´s been a while with load balancing) the client stays connected to the ASA that it connects first (persistent) and you can automaticaly redistribute a /32 route into your routing Process.
If you don´t like this option you can create different pools on your VPN ASAs and do some statice routing.
Hope I did not mix up to many facts - HTH you
cheers Michael