The Fortigate will silently drop your Phase 2 proposal if the Proxy-IDs (subnets) proposed by the Check Point do not exactly match the configuration on the Fortigate. When the Fortigate initiates, its Phase 2 proposal will be accepted by the Check Point even if it doesn't match the VPN domain subnets exactly. See scenario 1 of this SK for the solution: sk108600: VPN Site-to-Site with 3rd party
In R80.40+ you can customize the VPN domains per VPN Community in the SmartConsole to send the exact Phase 2 Proxy-IDs the Fortigate is expecting, without having to hack the user.def file as described above.
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com