Recently, in the Check Point MX Gaceta, a new video was uploaded about how to create a VPN Site to Site, with digital certificate authentication (Fast Track - VPN Site to Site con autenticación mediante Certificados Digitales - YouTube) and how a coincident, I was do it that scenario for a client a couple of days ago.
For that reason I want to add valious information for future projects who anyone can have with a similar scenario.
In my personal experience, plus to the video steps, in the client modem we put the connection as DMZ, this because the public IP address can pass to the checkpoint (a 730 in this case) and the communication with the central gateway can establish inmediatly.