You could turn on the following event logs on the concentrator:
auth
authdbg
ike
ikedbg
ipsec
ipsecdbg
log event 1-9 and see the filterable event log as you establish connection with the checkpoint and see what is not matching in phase 1 and/or 2. Also try to see if you could modify the IKE proposal on the 3000 to use DH group 1 rather 2, as sometimes Checkpoint doesn't want group 2.