There's no way for an IPsec SA to be active (checkmark in green dot), Antonio, unless the associated IKE was successful. Other than these lines in the log, what problem are you having?
Cheers - Bob
I had in the past similar problems with customers using Checkpoint.
There were 2 isse causes:
Checkpoint per deafult tries superneting (10.0.0.0/8-effect). There is an option to switch this off
One customer had selected transport- and not tunnel mode (/32-effect)
Sorry, I have no ceckpoint to give more information, I only had some experience with cutomers.