The answer is yes IF you setup the site-to-site VPN in "traditonal mode" instead of "simplified mode (aka VPN community)". In traditional mode, Checkpoint does not see the Cisco VPN peer as part of...