Not sure where you get the idea of "big issue in production"?
I started my post with "I am setting up ...", which would indicate a completely new configuration. I was not able to find complete instruction in Checkpoint documentation which led to interpretation of some settings and I ran out of options to test, hence this post. I could also go to TAC, but I thought this is also the right place to discuss.
What exactly you would like to know about VTI config? My understanding is that VPN tunnel is up, VTI config is fine too, because I can receive and send traffic based on the log, however one direction is not processed by correct firewall rule and therefore dropped.