No. Oracle has predetermined the configuration parameters that work with the IPSec VPN service. Your IPsec VPN can't be established if there is a mismatch.
No. You must initiate it from your end.
No. Packets from the VCN have the private IP address of the instance as a source IP address. Oracle cannot change the source IP address to the private or public IP address of the DRG.
Yes. Traffic for all the subnets in the VCN attached to your DRG is routed over both tunnels.
You can have a maximum of eight tunnels from a unique CPE IP address per region. If you want more than eight tunnels, either use a different IP address for the additional ones, or use a different CPE device (recommended).