On Cisco you can setup the VPN tunnel as "initiator" or "responder" or "both". Depends what is config on their end and if there will be usecase when Cisco is responder (Check Point will be source of VPN communication).
If Cisco is only initiator, then you dont need to have NAT internal IPs in encryption domain.
If Check Point will be initiator, then NAT internal IPs must be part of local encryption domain AND ALSO on Cisco side as part of remote encryption domain (to match traffic selectors to be 1:1). Cisco has to be also configured not only as Initiator, but also responder (or both).
It is very important to have identical traffic selectors (encryption domains) on both ends.
Kind regards,
Jozko Mrkvicka