Postmortem
We had to revert to the old set of HA firewalls.
Timeline (all times EDT):
14:17: go-ahead from Marketplace Simulations to the web hosting provider
14:21: service stop; HA firewall pair replaced
14:41: access to www.marketplace-simulation.com re-established
15:11: access to game.ilsworld.com re-established
15:19: site to site VPN tunnels re-established; access to game.ilsworld.com lost
16:12: complete return to the old set of HA firewalls due to incorrectly working DNS for A records from 1:1 NAT in the new HA firewall set
Conclusion: working with the web hosting provider on finding out the differences between the old and the new firewalls in how DNS A records are translated for records found in the NAT table at the firewall.
The Marketplace Sysadmins