Thank you for the details. I may need further clarification but I'll give it a shot.
Is there a reason to not have the VRRP interface / management IP be eth0 instead of the external interface (eth1/eth2)? Reason being is that the health check / VRRP communication would still be happening and the no new MWG needs to take over. This is why things failed on the client side (rather than external side).
Thank You for your suggestions. In test environment, I have moved VRRP interface on eth0 and changed ip addresses of management interfaces to eth0 network address pool.
In this scenario breakdown of switch-int-2 doesn't cause any production outage, hovewer breakdown of switch-ext-1 or switch-ext-2 does.
I think that very similar situation was described in this thread https://community.mcafee.com/message/260990#260990
Have you got any further solution to avoid production outage during network phisical layer problem in redundant environments ?