> Source: [sk165853](https://support.checkpoint.com/results/sk/sk165853)

# sk165853 - High CPU utilization on one CPU core during high VPN traffic volume (Site-to-Site VPN or Remote Access VPN)

| Property | Value |
|----------|-------|
| Solution ID | sk165853 |
| Date Created | 2020-03-18 |
| Last Modified | 2025-09-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * High CPU usage on one CPU core when high number of end users are connected to the network through Remote Access VPN (RAS / C2S).
* High CPU usage on one CPU core when high IPSEC VPN (S2S) is used.
* A significant amount of the traffic is processed through medium path.
* cphwd_q_init_ke is causing high CPU when SecureXL is enabled in an environment with a lot of VPN traffic.
* One CPU that is an SND is being utilized much more while other CPUs are not.

## Cause

Each VPN connection is handled by a specific CoreXL Firewall instance.

CoreXL SND instances allocate the connections to the relevant CPU core based on the VPN tunnel.

You can verify the unequal CPU load in the CPView Utility (see [sk101878](https://support.checkpoint.com/results/sk/sk101878)) in:

* CPU \> Overview \> Host  
  Example:  
  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk165853/01202201201247241.jpg)
* Advanced \> SecureXL \> Network-per-CPU  
  Example:  
  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk165853/02202201201247482.jpg)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
