Well, I learned something new today as well : - )
Yes, it is possible...see below, my lab R81.20 jumbo 26, no vpn blade.
Andy
https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Top...
[Expert@CP-TEST-FIREWALL:0]# enabled_blades
fw urlf appi ips mon
[Expert@CP-TEST-FIREWALL:0]# ps aux|grep ike
admin 7683 0.0 0.0 34916 5484 ? Ss Oct16 2:15 spike_detective
admin 9452 0.1 0.1 258308 42048 ? Sl Oct16 3:40 iked 0
admin 9453 0.1 0.1 258296 41740 ? Sl Oct16 3:36 iked 1
admin 9454 0.1 0.1 258308 41716 ? Sl Oct16 3:40 iked 2
admin 15503 0.0 0.0 2652 568 pts/2 S+ 13:39 0:00 grep --color=auto ike
[Expert@CP-TEST-FIREWALL:0]# vpn iked disable
vpn: disabling 'iked'...
vpn: reconfiguring system...
Installing Security Policy LAB-POLICY on all.all@CP-TEST-FIREWALL
IPS package: Compiled OK.
Fetching Security Policy from local succeeded
vpn: 'iked' is now disabled.
[Expert@CP-TEST-FIREWALL:0]# ps aux|grep ike
admin 7683 0.0 0.0 34916 5484 ? Ss Oct16 2:15 spike_detective
admin 16106 0.0 0.0 2652 572 pts/2 S+ 13:41 0:00 grep --color=auto ike
[Expert@CP-TEST-FIREWALL:0]# fw ver
This is Check Point's software version R81.20 - Build 012
[Expert@CP-TEST-FIREWALL:0]# cpinfo -y fw1
This is Check Point CPinfo Build 914000234 for GAIA
[FW1]
HOTFIX_R81_20_JUMBO_HF_MAIN Take: 26
HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE
HOTFIX_GOT_TPCONF_AUTOUPDATE
FW1 build number:
This is Check Point's software version R81.20 - Build 012
kernel: R81.20 - Build 014
[Expert@CP-TEST-FIREWALL:0]#