Patrick, MAC address don't come into play at Layer 3. The only way I can think of this happening is if you're using a FQDN for the IPSEC gateway. In this case the firewall is doing exactly what its supposed to. If you don't have it set to clean up active tunnels when the peer gateway address changes then you would have a tunnel that is up but doesn't work such as in your case.