> Source: [sk134092](https://support.checkpoint.com/results/sk/sk134092)

# sk134092 - VPND consumes high CPU during policy installation of R80.10 and higher

| Property | Value |
|----------|-------|
| Solution ID | sk134092 |
| Date Created | 2018-08-13 |
| Last Modified | 2020-10-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81 (EOS) |

## Symptoms

- * vpnd consumes high CPU (100% or more) during policy installation and afterwards.
* *vpnd.elg* prints "CPLDAPSDK" logs:


  ```
  
  [vpnd pid] [Date Time][CPLDAPSDK] outstanding referrals 0, parent count 0
  [vpnd pid] [Date Time][CPLDAPSDK] * msgid 27, origid 27, status InProgress
  [vpnd pid] [Date Time][CPLDAPSDK] outstanding referrals 0, parent count 0
  [vpnd pid] [Date Time][CPLDAPSDK] * msgid 26, origid 26, status InProgress
  [vpnd pid] [Date Time][CPLDAPSDK] outstanding referrals 0, parent count 0
  [vpnd pid] [Date Time][CPLDAPSDK] * msgid 25, origid 25, status InProgress
  [vpnd pid] [Date Time][CPLDAPSDK] outstanding referrals 0, parent count 0
  [vpnd pid] [Date Time][CPLDAPSDK] * msgid 24, origid 24, status InProgress
  [vpnd pid] [Date Time][CPLDAPSDK] outstanding referrals 0, parent count 0
  [vpnd pid] [Date Time][CPLDAPSDK] * msgid 23, origid 23, status InProgress
  [vpnd pid] [Date Time][CPLDAPSDK] outstanding referrals 0, parent count 0
  [vpnd pid] [Date Time][CPLDAPSDK] * msgid 22, origid 22, status InProgress
  ```

* Remote Access LDAP users are unable to connect when there is high CPU, and the following error message appears:   
  `"site is not responding"`
* Failover or service restart resolves the issue until the next policy installation.

## Cause

The high CPU is caused by a large amount of LDAP branches per checked user. Each user is being checked with any possible branch over the LDAP. Each check is asynchronous, and therefore Check Point sends all the needed requests. This might also cause high CPU on the LDAP server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
