MTU issues usually only come in to play once all IKE negotiations are complete and IPSec starts, but it doesn't sound like you are getting that far. A few things:
1) Are you sure no NAT is configured in Maestro? If there is the two IKE peers will shift from UDP/500 to UDP/4500 at IKEv1 Main Mode packet 5 or at IKEv2 packet 3 (not 100% sure on the exact packet where the NAT-T switch happens for IKEv2). Are you seeing port 4500 at any point?
2) If there is no NAT, it may be a distribution issue of some kind. To confirm try forcing UDP ports 500/4500 traffic along with ESP/50 to always be handled by the SMO via the asg_excp_conf command as detailed below, although it sounds like you tried it with only one SGM active and the problem persisted so that is not a distribution issue.
https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Chassis_AdminGuide/Content/T...
3) Another option is to Fast Forward UDP ports 500/4500 and IP Proto 50 (ESP) directly through the Orchestrator, since the VPN traffic is encrypted and can't be inspected anyway:
https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Chassis_AdminGuide/Content/T...
Beyond that we'll need to see a packet capture of the IKE packets to figure out what is going on.
Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course