Its from those guidbedit settings I mentioned in the post. So, to make long story short, this had been the problem with Check Point, for I dont know, last 20 years : - )
So, here is really basic example...lets pretend you want CP to advertise /29 to Cisco and thats what Cisco is expecting...fantastic. Now, you do your enc domains, verify everything, install policy and realize its failing on phase 2.
Why you may wonder? Its because Cisco is EXPECTING /29, but CP will always try send largest possible subnet, which would be at least /24 or larger.
So, not shockingly enough, Im fairly positive unless you change those values I mentioned to false, you will 100% continue to see this behavior.
As a matter of fact, this was one of the questions on R81 CCSE exam last year, EXACTLY that : - )