What encryption are you using in phase 2?
Check Point appliances work better with AES due to AES NI CPU Instruction set with the Intel CPUs.
So if you are using 3DES (for whaever reason), change to AES128 at the very least.
Maybe there are other blades being applied to this traffic as well.
If I ever suspect that DPI may be the issue, try fast accelerating it to see if this alleviates the issues (on both FWs).
https://support.checkpoint.com/results/sk/sk156672
This is only to check if it's a VPN or DPI performance issue, it's up to you to keep this permanent or not.
Fast_acceleration disables all form of security blades (except firewall), so not recommended generally unless the traffic is 100 % trusted.
What are the "download protocols" ?
I assume it's HTTPS from the internet, but maybe it's CIFS / SMB over the tunnel?
Different blades with varying performance impact may be applied depending on the protocol.