Good morning.
R82 take 122, Quantum NGFW
We encountered a very strange problem. When we increased the gateway’s traffic processing, we noticed an unnatural increase in the gateway’s utilization, which manifested itself in inadequate VPND consumption. In the screenshot below, you can see how the situation looks when processing approximately 200 Mbps of traffic.

enabled_blades
fw urlf av appi ips identityServer SSL_INSPECT anti_bot ThreatEmulation content_awareness mon zero_phishing
As you can see, neither VPN, nor RA, nor mobile access is used.
Disabling the blades that indirectly use vpnd did not yield any results — inspection, zero phishing, and usercheck were disabled one by one, but this only led to opposite results; disabling usercheck resulted only in a utilization rate of around 99% on each fwk core.
debugging VPND doesn’t provide any insight — only hundreds of thousands of records of standard TLS encryption operations.
The most interesting thing is that the second gateway, which has similar settings and policies and is essentially a backup for this cluster, does not have similar problems, and the vpnd utilization there does not exceed 5%.
We submitted a ticket to TAC, but so far they haven’t been able to help us. Perhaps this is some kind of bug that other administrators are also experiencing?