> Source: [sk168297](https://support.checkpoint.com/results/sk/sk168297)

# sk168297 - Large scale support in VPN Remote Access Visitor-Mode

| Property | Value |
|----------|-------|
| Solution ID | sk168297 |
| Date Created | 2020-08-05 |
| Last Modified | 2022-06-29 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * Slowness when connected with Remote Access VPN in Visitor Mode.
* Accelerated connections interrupted upon roaming from NAT-T to Visitor Mode.
* The vpnd process consumes CPU at high level on the Security Gateway when many Remote Access VPN clients are connected in Visitor Mode.

## Cause

Usually, when the Remote Access VPN Client connects to the Security Gateway, the VPN tunnel is established on port 4500. When this port is unreachable for some reason, the Remote Access VPN Client switches automatically to Visitor Mode (Roaming), where the packets destined to port 4500 are encapsulated and sent to port 443 on the Security Gateway.
Visitor Mode packets are handled by the VPN daemon (vpnd) in the User Space, unlike NAT-T packets that are handled by the Kernel. Handling Visitor Mode packets in the User Space increases the overhead on the system, and consequently affects the performance of Remote Access VPN connections.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
