Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    23.09.01 Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed

    Scheduled Pinned Locked Moved OpenVPN
    41 Posts 6 Posters 7.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Try disabling iimb. That will try to register against many of the same ciphers.

      JonathanLeeJ 1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee @stephenw10
        last edited by

        @stephenw10 I did that same results dang. Please let me know if you find a advanced option for customers like me.

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Do you actually see a reduction in throughput though? Or an increase in CPU usage?

          JonathanLeeJ 1 Reply Last reply Reply Quote 0
          • JonathanLeeJ
            JonathanLee @stephenw10
            last edited by

            @stephenw10 yes with use on 22.05.01.

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Like throughput is lower in 23.09.1 compared to 23.05.1?

              JonathanLeeJ 1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee @stephenw10
                last edited by

                @stephenw10 let me test again hold on I turned 23.09.01 on again.

                Nope it’s 130kbs with dsl on 23.09.01
                It’s 123kb in 23.05.01

                Just checked with my pdfs again.

                Make sure to upvote

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Hmm, those seem very low numbers. I can't imagine you'd be able to see the difference at those rates.

                  JonathanLeeJ 1 Reply Last reply Reply Quote 1
                  • JonathanLeeJ
                    JonathanLee @stephenw10
                    last edited by JonathanLee

                    @stephenw10 low bill too :) that ID error is why I think it has issues would ath0 cause this ?

                    Make sure to upvote

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      No this is nothing to do with the ath card or newer 2100s without the crypto cert device. OpenSSL no longer supports BSD cryptodev as an engine so the option to select it was removed from OpenVPN for all hardware.

                      Which ID error are you referring to?

                      JonathanLeeJ 1 Reply Last reply Reply Quote 0
                      • JonathanLeeJ
                        JonathanLee @stephenw10
                        last edited by JonathanLee

                        @stephenw10
                        IMG_0053.png

                        The id error shows on 23.09.01 every time does not show in 23.05.01

                        Make sure to upvote

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Ah OK. That seems unlikely to be related to the crypto hardware. If you disable safeXcel but keep DCO enabled does it still show?

                          JonathanLeeJ 1 Reply Last reply Reply Quote 0
                          • JonathanLeeJ
                            JonathanLee @stephenw10
                            last edited by

                            @stephenw10 I have to swap boot environments when my wife goes to work after that I can check.

                            To confirm you want me to disable the chip on the advanced menu?

                            Make sure to upvote

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              Yes, then boot so the safexcel module is not loaded. Then check the openvpn logs again. I expect that ID error to still be present.

                              JonathanLeeJ 1 Reply Last reply Reply Quote 0
                              • JonathanLeeJ
                                JonathanLee @stephenw10
                                last edited by

                                @stephenw10 side note, can I do a boot environment and load 24 dev os or will that cause issues going back to 23.09?

                                Make sure to upvote

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  Yes you can do that. There's no problem booting back to 23.09.1.

                                  JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                  • JonathanLeeJ
                                    JonathanLee @stephenw10
                                    last edited by JonathanLee

                                    @stephenw10

                                    Yes this is as you expected. It still occurs with the hardware disabled.

                                    Make sure to upvote

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Ok digging into that. I can only see one other reference to that kind of ID error.

                                      Is that process an OpenVPN server?

                                      How are the clients defined?

                                      JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                      • JonathanLeeJ
                                        JonathanLee @stephenw10
                                        last edited by JonathanLee

                                        @stephenw10

                                        I also see this id error in my 23.05.01 ssd on connects. I didn’t notice it until today

                                        Make sure to upvote

                                        PippinP 1 Reply Last reply Reply Quote 0
                                        • PippinP
                                          Pippin @JonathanLee
                                          last edited by Pippin

                                          I see no error in the logs posted above but that aside.....

                                          The message

                                          dco_update_peer_stat: invalid peer ID 0 returned by kernel
                                          

                                          is not related to the issue described.
                                          This can happen if userland has already forgotten a peer and kernel sends "post-disconnect stats" which seems to be the case

                                          openvpn server 'ovpns1' user 'LeeFamilyVPN'address 'x.x.x.x' disconnected
                                          

                                          right after the message.

                                          I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
                                          Halton Arp

                                          1 Reply Last reply Reply Quote 1
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by stephenw10

                                            Yup that's not an error that should ever prevent the service starting or cause connection issues etc.
                                            Or has anything to do with hardware crypto support.

                                            JonathanLeeJ 1 Reply Last reply Reply Quote 1
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.