Configure a DNAT to remap the traffic of floating IP (192.168.1.253, not interface IP) accessing the firewall from the Internet to the traffic of a particular machine (192.168.2.100) in the LAN.
Floating IP always on Active firewall
After HA failover