> Source: [sk25766](https://support.checkpoint.com/results/sk/sk25766)

# sk25766 - Security Servers - daemon names and definitions

| Property | Value |
|----------|-------|
| Solution ID | sk25766 |
| Date Created | 2004-03-29 |
| Last Modified | 2014-12-08 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

Security Servers and processes are grouped by function:

|----------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon               | Description                                                                                                                                                                                   |
| Content and traffic management                                                                                                                                                                                      ||
| **`in.aftpd`**       | FTP Security Server.                                                                                                                                                                          |
| **`in.ahttpd`**      | HTTP Security Server.                                                                                                                                                                         |
| **`in.arlogind`**    | RLogin Security Server.                                                                                                                                                                       |
| **`in.atelnetd`**    | Telnet Security Server.                                                                                                                                                                       |
| **`in.asmtpd`**      | SMTP Security Server (used to receive SMTP messages).                                                                                                                                         |
| **`mdq`**            | Mail DeQueuer daemon (delivers mail messages queued by *in.asmtpd*).                                                                                                                          |
| **`in.emaild.mta`**  | E-Mail Security Server (Anti-Virus scanning of e-mails).                                                                                                                                      |
| **`in.emaild.pop3`** | POP3 Security Server (Anti-Virus scanning of incoming e-mails).                                                                                                                               |
| **`in.emaild.smtp`** | SMTP Security Server (Anti-Virus scanning of outgoing e-mails).                                                                                                                               |
| **`in.aufpd`**       | URL Filtering Protocol (UFP) daemon (communicates with UFP server).                                                                                                                           |
| **`in.ufclnt`**      | URL Filtering Protocol Client (starting in R71, part of URL Filtering engine in kernel).                                                                                                      |
| **`in.ufsrvr`**      | URL Filtering Protocol Server (starting in R71, part of URL Filtering engine in kernel).                                                                                                      |
| **`stormd`**         | SmartDefense / IPS Storm Center Module.                                                                                                                                                       |
| **`in.genericd`**    | The TCP 'genericd' resource invokes a daemon, which is not a Security Server, but rather the mediator between the client, the CVP Server and the destination server.                          |
| Authentication and load balancing                                                                                                                                                                                   ||
| **`in.asessiond`**   | Session Authentication Security Server Agent.                                                                                                                                                 |
| **`in.aclientd`**    | Client Authentication process (port 259).                                                                                                                                                     |
| **`in.ahclientd`**   | Client Authentication via Web (port 900). Executable starts when user initiates Client Authentication through a web browser.                                                                  |
| **`in.lhttpd`**      | Load Balancing daemon is the user mode process that handles HTTP requests, when the load balancing method is set to HTTP - listens for and redirects HTTP requests coming for load balancing. |
| **`in.pingd`**       | Load balancing or/and Client Authentication in Wait mode.                                                                                                                                     |
| IPsec VPN                                                                                                                                                                                                           ||
| **`vpnd`**           | Session Authentication Security Server Agent.                                                                                                                                                 |
| **`sdsd`**           | Software Distribution Server. Distributes software to SecureClient users.                                                                                                                     |
| **`dtpsd`**          | Desktop Policy Server. SecureClient users fetch policy from this Policy Server.                                                                                                               |
| **`dtlsd`**          | Desktop Log Server. Receives logs from SecureClient users.                                                                                                                                    |
| **`in.ahttpsd`**     | Clientless VPN daemon                                                                                                                                                                         |
| **`xrmd`**           | Extranet Manager Process. If Security Gateway is defined as Extranet Enabled Gateway, public key can be shared with this process.                                                             |

**Related solutions:**

* [sk97638 (Check Point Processes and Daemons)](http://supportcontent.checkpoint.com/solutions?id=sk97638)
* [sk52421 (Ports used by Check Point software)](http://supportcontent.checkpoint.com/solutions?id=sk52421)
* [sk34434 (stormd, sdsd and in.assesiond processes consume high CPU during Policy installation)](http://supportcontent.checkpoint.com/solutions?id=sk34434)
* [sk34673 (Zombie processes "SDS" and "STORMD" are consuming CPU at very high level)](http://supportcontent.checkpoint.com/solutions?id=sk34673)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
