Duo trusted endpoints device checks only work when we show an interactive Duo prompt in a browser window.
https://duo.com/docs/checkpoint This configuration adds Duo via RADIUS and does not feature an interactive Duo prompt in a browser window. Therefore, this configuration does not support trusted endpoint checks.
If you were to federate logins for Checkpoint VPN to Duo SSO via SAML, that would show an interactive Duo prompt and therefore would support trusted endpoint checks. We don't have a named SSO application for Checkpoint or step-by-step instructions specific to Checkpoint today, but you can use a Duo SSO generic SAML application and these SAML config for VPN instructions from Checkpoint to deploy this configuration.
Duo, not DUO.