> Source: [sk181398](https://support.checkpoint.com/results/sk/sk181398)

# sk181398 - Windows terminal servers with Check Point MUHv2 agent have slow performance after an upgrade to VMware ESXi 7.0

| Property | Value |
|----------|-------|
| Solution ID | sk181398 |
| Date Created | 2023-09-05 |
| Last Modified | 2026-08-13 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Windows |

## Symptoms

- * After an upgrade to VMware ESXi 7.0, log in to the Windows terminal server that runs the Check Point MUHv2 agent takes more than 3 minutes.

* RDP to the terminal server takes more than 3 minutes to connect.

* Running `"gpupdate /force"` in CMD on the terminal server takes more than 3 minutes to complete.

* In the MUH Agent Client logs (On the Terminal Server Agent (MUH): Advanced \> click on "Collect information For technical support") you 
  can see that the logon function is called 3 minutes after the user connects. For example:  


  User connects:  
  `
  [ 5224 5228]@Host[9 Jul 11:46:39] [NAC_Manager (NAC::IS::TD::Events)] handleSessionEvent: handling session event`  
  `
  [ 5224 5228]@Host[9 Jul 11:46:39] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::handleSessionChangeEvent: 
  Session change event occured. Event type: WTS_REMOTE_CONNECT, session id: 6 `  


  After 3 minutes, the WTS_SESSION_LOGON function is called:  

  `
  [ 5224 5228]@Host[9 Jul 11:49:22] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::handleSessionChangeEvent: 
  Session change event occured. Event type: WTS_SESSION_LOGON, session id: 6`  
  `
  [ 5224 5228]@Host[9 Jul 11:49:22] [MUH2UserManager (NAC::IS::TD::Events)] NAC::CLIENT::MANAGER::MUH2UserManager::handleSessionChangeEvent: 
  checking session id - 6, user name - m, domain - P, win station - R, connect state - 0`

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
