A VLAN trunk only works if both ends are configured the same way.
If you plug the WatchGuard interface with a Trunk into a switch port, then that switch port must:
- Support VLANs
- Be configured as a trunk with the same VLANs as the WatchGuard
Same with both Check Point devices, both on the WatchGuard side of things and on the Cisco side of things.
Also, on the gateway topology, the interface that should be marked as external is eth1.10 (the VLAN interface) not eth1 (the physical one).
On a separate note, load sharing configurations (while supported) are generally not advised.
If the cluster members exceed 50% utilization and one node fails, the other member will become overloaded (which may cause a complete outage).