No ForeScout expert here, but I suspect that I can extrapolate what your client is trying to achieve.
They are likely trying to implement ForeScout NAC and use it to perform DNS forwarding for guests.
If this is the case and all Check Point devices have to do is to resolve the ForeScout devices names then you can even hard code them in Gaia of your Check Point devices.
If they are actually looking to use Check Point as forwarders, these capabilities are present in SMB appliances with embedded Gaia:
...but not in the enterprise models which rely on a dedicated external DNS infrastructure.
It is likely you can jury-rig something to make it work, but I would not recommend it.