I am working with an MX 100 that has been configured in One Armed Mode behind a Checkpoint Firewall, with Hide Behind Nat. The MX is unable to form autovpn connections,
NAT type: Unfriendly. Thissecurity applianceis behind a VPN-unfriendly NAT, which can be caused by upstream load balancers or strict firewall rulesThat is the message from the VPN status page. Not sure what would be causing this on the Checkpoint.
In addition to the input from @PhilipDAth also make sure everything is good with your firewall rules. In particular, the MX appliances on both sides will need outbound UDP 9350 to talk to the VPN Registry.