Thanks for the answer, the checkpoint cluster itself has no dynamic ip
The topology is this:
The Router has receives the IP from the provider.
Behind it is the Cluster, with static IP on the Transport network. all connected over a switch( not relevant for this discussion).
The management is reachable over the internet so any incoming connection would have to be to the Public IP of the router.
My idea was to have the Cluster set as Dynamic and have both gateways fetch the policy, this way only outbound communication is required like on a normal DAIP single gateway solution.
I wanted to test this but the Dyn option is not available on the cluster object.