Last month I was delivering a SNAA course for one of our customers. Although I am not a big fan of this course, it is the right choice if you want learn advanced NAT, Routing and any kinds of VPN supported on the appliance.
Let me share you one of the scenarios which you may face.
(Тhe example is present in the VPN Support Sommunity site.)
Here is a sample configuration for a VPN/IPsec with Open Shortest Path First (OSPF) on Cisco Adaptive Security Appliance which allows OSPF unicast to run over an existing VPN connection. You no longer need to configure a Generic Routing Encapsulation (GRE) tunnel.