Short answer based on my experience with OPSEC LEA 3.1: it's evil.
Even if you have the TA deployed on each HF with the same config, how do you sync them all so that they all know where to start to read from and you don't end up with duplicates or gaps?
Your best bet as far as I can tell would be to use Virtual Machines for that heavy forwarder and rely on whichever resiliency your VM team can provide: VM snapshots, backups, etc. Keep in mind your logs are stored in your CheckPoint CMAs for quite some time (depending on your configuration) so if a VM is unavailable for 1-2 hours it shouldn't be a massive disaster.
I don't know if v4.1 solves this problem as I'm not planning to upgrade any time soon.
Sorry it's probably not the answer you were looking. Maybe others can share their own experiences and help you a bit more.