We've done a number of setups like this for support customers that work great.
The HA functionality you linked isn't relevant to this type of circumstance, that's for active/active clustered machines.
Dynamic DNS is likely to be a requirement with any solution along these lines that offers multi-WAN failover on both sides, as that's the only way you can tell endpoints where they need to be connecting. Strictly referring to IPsec tunnel mode, if you go with transport mode, tunnels and a routing protocol, that's not a requirement. Which options are workable will depend on what the remote endpoints are, since OpenVPN isn't an option, I presume they're third party IPsec devices.