Let's say you have the following scenario, you have an email gateway that all emails are received and then processed for Antivirus and Antispam or any other rules you may have. The benign ones are then delivered to your email server ie MS Exchange.
The new setup:
Your CheckPoint Gateway Firewall with the NGTX license gets the MTA role. You need to change the configuration on your Email Gateway to deliver the emails instead of your Exchange Server to your CP NGTX FW with the MTA role. For emails with attachments your CP FW will send the attachments to your Threat Emulation appliance (if you have one) or to the Cloud. Once the verdict comes back then your CP FW will send the emails if benign to your MS exchange server.
In short you are placing your FW with the MTA role between your current setup. Your FW then is sending the files for scanning to the TE appliance.
1) Be careful with the allowed file sizes on your CP MTA to always be larger than your Email Gateway and Exchange server.
2) When sending out from your organisation you can keep the same setup ie. from Exchange to your Email gateway.
3) It is preferable to have an email gateway in front so it will take all the heavy load first. Remember, your TE is for the files that everything else believe that are benign.