You may find this SK helpful which details how to completely banish 3DES from being used in any part of the Check Point product including Remote Access VPN, Gaia Portal, management API, etc. This is mentioned in my Gateway Performance Optimization class as improving performance, but certainly improves security as well:
sk113114: Check Point response to CVE-2016-2183 (Sweet32)
Might be able to deconstruct the provided commands and banish SHA1 and other weak ciphers too.
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm