No. Oracle has predetermined the configuration parameters that work with the IPSec VPN service. Your IPsec VPN can't be established if there is a mismatch.
If your CPE is behind a NAT device, you can provide Oracle with your CPE's IKE identifier so that Oracle can use the same value on the Oracle side. For more information, see Changing the CPE IKE Identifier That Oracle Uses.
No. You must initiate it from your end.
No. Packets from the VCN have the private IP address of the instance as a source IP address. Oracle cannot change the source IP address to the private or public IP address of the DRG.
Yes. Traffic for all the subnets in the VCN attached to your DRG is routed over both tunnels.
You can have a maximum of eight tunnels from a unique CPE IP address per region. If you want more than eight tunnels, either use a different IP address for the additional ones, or use a different CPE device (recommended).