1) configure ASA1 in single context router mode and ASA2 in single context transparent firewall mode. Configure the Transparent firewall (ASA2) to use management IP as 2.2.2.10.
2) Configure a IPSec VPN tunnel between ASA1 and ASA2 to secure the management traffic towards ASA2. This tunnel should be applied only for traffic sourced from R1's interface towards the management address of ASA2.
3) Configure another IPSec VPN tunnel between ASA1 and R3 to secure the traffic flow between R1's interface and the internal network of R3.
4) Configure "IPSec HairPinning" such that traffic sourced from R3's loopback towards the management interface of ASA2 uses the already established IPSec tunnels established in Objectives 2 and 3.
Courtesy (Rajesh)