I am currently still under investigation with Symantec.
We have narrowed it down a very little, but there is no solution or workaround yet.
I have considered rolling back to MR3, but then we have to downgrade the management server and other clients as well, which is not easy to do.
This issue appears only when the VPN is connected. When you close the VPN, it drops again.
The CPU usage stays normal, until Symantec wants to 'talk' to the management server.
As soon as the clients connect to the management server, the cpu goes up to 50% (e.g. when you ask for 'update policy')
Disabling the Symantec client, does not help.
Only by closing the VPN or stopping the SMC service, this can be resolved.
I have installed a new client package without the firewall, with no result.
The issue does not show on the management server, or on the RRAS server, which both also have SEPP installed.
This meaning, the issue is in the Symantec Management Client itself, or at least I think.
I am currently trying to get some log files and a crash dump to their tech support, but I have some trouble creating them.
I'll keep you posted, when I know more.
Arno