If it is in the same subnet as the primary you can't (no need to anyway), all traffic is going to be coming from the primary IP. If you have a different subnet with its own gateway you can but you'll need a few rules to simulate source routing and manually create the config in ipsec.conf-default