> Source: [sk177128](https://support.checkpoint.com/results/sk/sk177128)

# sk177128 - VPND CPU usage is very high when the VPN blade is not enabled

| Property | Value |
|----------|-------|
| Solution ID | sk177128 |
| Date Created | 2022-03-10 |
| Last Modified | 2022-03-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- * When the VPN software blade is not enabled, output of the "`top`" command shows high CPU usage for the "`vpnd`" process.  
  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk177128/VPND_HIGH_CPU202112311505133.png)  
* After `vpnd` debug is enabled, the *$FWDIR/log/vpnd.elg* log file is flooded with CPTLS messages. **Note:** The IP address in the log entry is reversed. This is the IP address associated with the Captive Portal URL.  

  ```
  [vpnd 7385 4102367120]@CP-FW2[11 Dec 19:07:17][CPTLS] getRenegParams: lookup for key : <12.0.10.10, 63763, 1.1.168.192, 443, 6> 
  [vpnd 7385 4102367120]@CP-FW2[11 Dec 19:07:17][CPTLS] getRenegParams: return_value == NULL 
  [vpnd 7385 4102367120]@CP-FW2[11 Dec 19:07:17][CPTLS] storeRenegParams: storing key : <12.0.10.10, 63763, 1.1.168.192, 443, 6> 
  [vpnd 7385 4102367120]@CP-FW2[11 Dec 19:07:17][CPTLS] storeRenegParams: added. 
  [vpnd 7385 4102367120]@CP-FW2[11 Dec 19:07:17][CPTLS] cptls_handle_msg: done. msg=HS_NEW 
  ```

* After filtering logs in SmartConsole for **"blade:Identity Awareness"** , many log entries show "*Redirect'* .  

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk177128/IDA_LOG_REDIRECT2202112311459562.png)

## Cause

The `vpnd` process is responsible for the SSL/TLS negotiation of MultiPortal features such as Captive Portal, UserCheck Portal, and Mobile Access Portal. The high number of Captive Portal redirections overwhelms the `vpnd `process of the Security Gateway.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
