Just wanted to share our unfortunate experiences with 23800 appliance that decided to die this weekend.
Actual RMA process went quite smooth and we installed the new box and even backup restore procedure was smooth sailing. All looked great till we got to last couple of "minor" checks - SNMP functionality and IA Captive Portal.
SNMPv3 issue.
We were able to poll VS0 but polling other VSes ended up in no response message. Many hours of troubleshooting including this article https://community.checkpoint.com/t5/Security-Gateways/R80-40-snmpv3/m-p/91926# led to nothing. Eventually we worked out that
/etc/snmp/vsx-proxy/snmpd.vsx.proxy.conf
file was empty after backup restore. Which is actually responsible for internal SNMP comms between VS0 and other VSes. Checking backup archive we can see that all files from that directory are actually missing. Seems a bug to me. Solution was to copy same file from the other node in the cluster.
Captive Portal
We do use IA a lot and Captive Portal is fairly essential. It was "dead" after backup restore. The idea from SNMP fault led us to check relevant directories in backup archive and both were missing or empty!
/opt/CPsuite-R80.40/fw1/nacportal/wrapper/*
/opt/CPNacPortal/*
Attempted a manual copy as per https://community.checkpoint.com/t5/Security-Gateways/IA-Captive-Portal-missing-after-upgrade-to-R80... but unfortunately it did not help. Still no solution and TAC case open. Will update here once we have it.
Sorry guys but I wanted to tag you here as you helped in past! @Adi_Babai and @Royi_Priov 🙂
If you have used VSX backup restore - let us know if it went ok for you!