>and then configure the secondary with the same IP on both?
No. Well, I guess you could as long as you only plug in one at a time. But generally, no.
Lets take a step back - do you even need to use virtual IP mode. Because if the answer is no, things get simpler.
I probably use virtual IP mode on only 10% of deployments.
Virtual IP mode:
* Can made AutoVPN fail over a little bit faster.
* Makes client VPN failover a little bit faster.
* Is a must for third party site to site VPN connections where you need HA.
* It makes all outbound web browsing appear to always come from a single IP address, rather than two IP addresses.
Is any of the above "a must" for you?