No VTI with BGP and I am sure Check Point does not support Failover or redundancy. Its becuase even if Check Point has multiple ISP interfaces the settings on VPN Link selection allows only IP address to negotiate with Peer and in this case there is only one IP address can be configured. Again once the tunnel is up between peers then VTI IP addresses negotiate route tables.
Hence I am pretty sure VPN redundancy can not be achieved with VTI from Check Point end. I was wondering about policy based VPN using DPD.
Thanks and Regards,
Blason R
CCSA,CCSE,CCCS