Check Point offers provisioning for VPN setups of Spark [SMB] Security Gateways. Any type of Security Gateway can be added to SMP as "externally managed gateway", only for IPsec [Site to Site] VPN purposes. This article describes the procedure.

For Security Gateways not managed by SMP, it's mandatory to install CA's (CA stands for Certificate Authority) to decrypt VPN traffic. The format of these certificates is specified by the X. 509 or the so called EMV standard.
For the procedure and recommendations, please refer to: sk177545