> Source: [sk86560](https://support.checkpoint.com/results/sk/sk86560)

# sk86560 - High CPU utilization by PDPD daemon

| Property | Value |
|----------|-------|
| Solution ID | sk86560 |
| Date Created | 2012-10-18 |
| Last Modified | 2024-10-25 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- High CPU utilization by PDPD daemon.

## Cause

If the "`Assume that only one user is connected per computer`" option is selected, certain servers (such as Exchange servers, or Citrix servers) may overload the PDPD daemon with associations from multiple IP addresses. Events from such servers do not provide significant identity information.

It is important to note that when the "`Assume that only one user is connected per computer`" option is **unchecked** , if more than 7 (by default) users are associated to a single IP address, the address is considered a "`multi user host`" and is automatically excluded from ADQuery. In case this option **is** checked, this automatic exclusion is not performed.

For further information refer to [sk60301 (Identity Awareness AD Query)](http://supportcontent.checkpoint.com/solutions?id=sk60301).

## Solution

Identify all non-user IP addresses in the network (exchange Servers, Citrix Servers) and exclude them from ADQuery:

In the Active Directory Query window press "Advanced", and add either the Machine names to the excluded Users/Machines list, or the IP addresses to the excluded networks list.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk86560/Exemptusers.png "Exempting IPs from ADQuery")

To exclude a specific IP from AD Query, a Network Object with 32 mask is required, e.g. 255.255.255.255 network, for example:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk86560/Untitled1711190529.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
