For the sake of knowledge and for future viewers, this is what I did:
- engaged a local IT guy to prepare a laptop connected via hotspot and Teamviewer so that I could reach the firewalls from within the network -> this has been CRUCIAL since I lost the connectivity once changed the SIC on the firewall, since it does a cpstop/cpstart and basically blocked the traffic from outside...
- configured the second default route on the nodes (both set to metric "None")
- cpconfig on standby node, reset SIC, it restarts the services, "fw unloadlocal" to reset the policy locally
- changed the IP of the node on SmartConsole, reset SIC, Initialize with new password -> connected
- same for the active node
- changed the cluster VIP
- I didn't Get the topology, just modified the IPs of the changed interfaces+VIP
- renewed the VPN certificate to match the new VIP
- installed the policy on the cluster and other clusters in the VPN community
Everything works!
Thanks all