Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    23.09.01 Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed

    Scheduled Pinned Locked Moved OpenVPN
    41 Posts 6 Posters 6.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by JonathanLee

      In 23.09.01

      295a3eae-21bb-41ed-bbf0-c702dd20098f-image.png

      e43cf1de-9060-41a3-98b3-4aaf2027d51c-image.png

      ae8597c5-68d4-4b9f-bc2f-d95e671c68bd-image.png

      150e275b-0b62-444f-a95f-c55f1c42681e-image.png

      d5d06d15-b76f-4cff-a14a-df52200faf0d-image.png

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee
        last edited by

        62c9aa3a-9326-4a8b-a84b-533331151a5f-image.png

        It shows nothing for me, with

        DOC enabled or disabled
        encryption with removed chacha and enabled chacha
        IPsec-MB enabled or disabled

        23.09.01 I can't get it to run

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • JonathanLeeJ
          JonathanLee
          last edited by

          In 23.05.01:

          0b5a9c75-8b38-44e3-af18-5565434c24f1-image.png
          Chip working

          2610e023-b71a-4585-965d-8d9ebe1ea631-image.png
          Chip listed

          93648637-8571-44ec-8b7e-9de3d548adb2-image.png

          7d21ba8f-4a65-4650-aa82-818e31740ce4-image.png
          Listed the chip

          b8150d5c-53ef-4179-8d7f-dfaa2b551558-image.png
          increments on use now shows 80

          My device was purchased direct from Netgate and contains the chip.

          What should I do???

          Make sure to upvote

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            OpenSSL no longer supports the BSD cryptodev device as an 'engine'. Selecting it there does nothing so it was removed.

            SafeXcel should still be used for kernel mode crypto though so if you have DCO enabled.

            Steve

            JonathanLeeJ 1 Reply Last reply Reply Quote 0
            • JonathanLeeJ
              JonathanLee @stephenw10
              last edited by JonathanLee

              @stephenw10 I do have it enabled, though VM stat still shows no increments Or any status for the Chip what can be done to correct that? Thanks for the reply. Have a good day.

              Just for clarification the new 2100s ship without a cypher chip? My version was the more expensive 2100MAX it came with a SSD and the cypher chip. Is it possible the updates repos do not know difference between the older 2100? and the new 2100s?

              Like a hypothetical model 2100A and 2100B ????

              If so how can I get my chip to work the speed is drastically different on VPN use with it enabled.

              Make sure to upvote

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Try disabling iimb. That will try to register against many of the same ciphers.

                JonathanLeeJ 1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee @stephenw10
                  last edited by

                  @stephenw10 I did that same results dang. Please let me know if you find a advanced option for customers like me.

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Do you actually see a reduction in throughput though? Or an increase in CPU usage?

                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @stephenw10
                      last edited by

                      @stephenw10 yes with use on 22.05.01.

                      Make sure to upvote

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Like throughput is lower in 23.09.1 compared to 23.05.1?

                        JonathanLeeJ 1 Reply Last reply Reply Quote 0
                        • JonathanLeeJ
                          JonathanLee @stephenw10
                          last edited by

                          @stephenw10 let me test again hold on I turned 23.09.01 on again.

                          Nope it’s 130kbs with dsl on 23.09.01
                          It’s 123kb in 23.05.01

                          Just checked with my pdfs again.

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Hmm, those seem very low numbers. I can't imagine you'd be able to see the difference at those rates.

                            JonathanLeeJ 1 Reply Last reply Reply Quote 1
                            • JonathanLeeJ
                              JonathanLee @stephenw10
                              last edited by JonathanLee

                              @stephenw10 low bill too :) that ID error is why I think it has issues would ath0 cause this ?

                              Make sure to upvote

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                No this is nothing to do with the ath card or newer 2100s without the crypto cert device. OpenSSL no longer supports BSD cryptodev as an engine so the option to select it was removed from OpenVPN for all hardware.

                                Which ID error are you referring to?

                                JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                • JonathanLeeJ
                                  JonathanLee @stephenw10
                                  last edited by JonathanLee

                                  @stephenw10
                                  IMG_0053.png

                                  The id error shows on 23.09.01 every time does not show in 23.05.01

                                  Make sure to upvote

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Ah OK. That seems unlikely to be related to the crypto hardware. If you disable safeXcel but keep DCO enabled does it still show?

                                    JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                    • JonathanLeeJ
                                      JonathanLee @stephenw10
                                      last edited by

                                      @stephenw10 I have to swap boot environments when my wife goes to work after that I can check.

                                      To confirm you want me to disable the chip on the advanced menu?

                                      Make sure to upvote

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        Yes, then boot so the safexcel module is not loaded. Then check the openvpn logs again. I expect that ID error to still be present.

                                        JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                        • JonathanLeeJ
                                          JonathanLee @stephenw10
                                          last edited by

                                          @stephenw10 side note, can I do a boot environment and load 24 dev os or will that cause issues going back to 23.09?

                                          Make sure to upvote

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            Yes you can do that. There's no problem booting back to 23.09.1.

                                            JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.