Hi!
Does it really make sense to create another VPN tunnel between the same devices? I cannot imagine a situation where it is required/usefull.
Theoretically you might do it this way:
1. "set ignore-subnet-conflict" on the VR, where the Untrust interface is located.
2. create a new loopback interface and assign a free public IP from the Untrust network: xxx.xxx.xxx.xxx/32.
3. repeat 1 and 2 on the remote GW because you cannot configure two remote GWs with the same IP. If there are no free IPs on the remote GW, you can try to configure this alternative GW as a one of the type "Dynamic IP".
4. Terminate VPN on the loopback interfaces.
Kind regards,
Edouard