Stop all interesting traffic on both sides, then clear the tunnels on both ends with vpn tu and clear crypto isakmp sa and clear crypto ipsec sa.
Now try initiating interesting traffic from the Check Point side only, do all needed tunnels come up and work?
Again stop all interesting traffic on both sides, then clear the tunnels on both ends with vpn tu and clear crypto isakmp sa and clear crypto ipsec sa.
Now try initiating interesting traffic from the Cisco side only, do all needed tunnels come up and work? My guess is one or the other of these tests will fail which indicates a Phase 2 subnet/Proxy-ID negotiation mismatch. You need to ensure that either end can successfully initiate all needed tunnels to the other end.
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm