It was more complicated than I thought. It took Checkpoint dealer two days to get it working and was not something that we could have done ourselves.
Some tips:
1. You need to activate Identity Awareness. Don't need to run wizard, but will need to mark off VPN in IA configuration tab of firewall.
2. Changes needed to be done via DBEdit.
3. We are using UPN from the SmartCard and via Activedirectory.
4. Make sure that the connection to AD servers is working well. We had problems of dedicated user locking in AD. The solution was a CLI command to force use of NTLMv2.
5. We also configured the firewall to distribute addresses from DHCP servers.