Hi William Gutierres, Dameon Welch Abernathy is enjoing his time off this week.
To answer your questions:
Q: What if the endpoint DAIP is a Checkpoint Gateway?
A: No problem at all if the GW is centrally managed and is connected to the central GW. Just define it as a DIAP managed GW. Certificates are signed by the same CA, no problem, very standard configuration. SMS shoul be accessible from Internet on for standard Check POint network services.
Q: what if this specific DAIP Checkpoint is managed by a remote office?
A: I take it as it belongs to a different SMS in the remote office. In this case trust should be established between SMS CAs on each end. Both SMSs should also have CRL Distribution Point accessible from Internet, so each of the GWs on each side could validate a foreign certificate.