Back for news ;-)
The HA Cluster has been tested in a separate way, behind an ISP router different from the first post (Sagem Livebox V5).
I added a small 8 ports switch between the ISP routeur & the WAN interface of each Opnsense box.
One modification has been done : the outbound rules where set as "Source : LAN Address" instead of "LAN Net" ==> My expert told me it wasn't relevant enough for the previous CARP_VIP/MacAddress issue we met.

For now, the HA Cluster is fully responsive, the failover works great, incoming VPN or incoming NAT rules are processed ;-) The only "trouble" I have is OpenVPN connection not kept during a failover, but this will be not a real problem for end users.
I will give you some feedback when I well go back on site.
The HA Cluster has been tested in a separate way, behind an ISP router different from the first post (Sagem Livebox V5).
I added a small 8 ports switch between the ISP routeur & the WAN interface of each Opnsense box.
One modification has been done : the outbound rules where set as "Source : LAN Address" instead of "LAN Net" ==> My expert told me it wasn't relevant enough for the previous CARP_VIP/MacAddress issue we met.

For now, the HA Cluster is fully responsive, the failover works great, incoming VPN or incoming NAT rules are processed ;-) The only "trouble" I have is OpenVPN connection not kept during a failover, but this will be not a real problem for end users.
I will give you some feedback when I well go back on site.
"