Check out below:
https://support.checkpoint.com/results/sk/sk108600
Now, here is what I can tell you. Error you get, 99% of the time is related to phase 2, so something with enc. domains. Firewall is simply "telliong" you that packet SHOULD have been encrypted.
I gave below to few people here in the community and it always helped. If you check these valus in guidbedit, should be set to false. It simplty implies that CP would stop presenting largest possible subnet, even though its not supposed to. Not saying it would solve your issue, but it always helps.
ike_enable_supernet
ike_p2_enable_supernet_from_R80.20
ike_use_largest_possible_subnets
By the way, if you get confused, we can always do remote session.
Cheers,
Andy