You will need an IP for each physical box, so you are only going to have three IPs that will fail over.
Lets say .249 is the gateway, 250 could be one firewall, 251 the second, leaving you with 252, 253, and 254.
You might be able to share IPs using port forwards and have enough. You can terminate multiple IPSec tunnels on one CARP VIP.