We switched firewall from M470 to M590 with Backup file , after migaration SSL VPN working fine but IKE2 not working as expect .
You probably used the Firebox default self-signed certificate in the IKEv2 configuration on the M470.
You need to download the new self-signed root certificate from the new M590 device and import this certificate to all IKEv2 client machines “Trusted Root Certification Authorities” store.
Easiest way is to download the IKEv2 client profile *.tgz file from the new M590 device and from this file copy the rootca certificate to all the IKEv2 client machines manually or AD GPO….
It's working as expect , thanks for information .