Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Activating IPsec-MB Crypto

    Scheduled Pinned Locked Moved OpenVPN
    5 Posts 2 Posters 616 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      McMurphy
      last edited by

      The link below states OpenVPN benefits from IPSec-MB and AES-NI is an alterntive
      https://docs.netgate.com/pfsense/en/latest/hardware/cryptographic-accelerators.html#openvpn

      My Hardware shows it supports IPSec-MB however it is inactive.
      18.07.2024_08.36.53_REC.png

      In System => Advanced => Misc I do not have an option to activate IPSec-MB
      18.07.2024_08.38.31_REC.png

      I see the Option for QAT here even through the hardware shows it is not available.

      What is my best option to select here?

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @McMurphy
        last edited by

        @McMurphy IIMB is the checkbox in your screenshot. :)

        There is a write up in this section:
        https://docs.netgate.com/pfsense/en/latest/config/advanced-misc.html#cryptographic-thermal-hardware
        “Best” depends on a few things for instance algorithm.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        M 1 Reply Last reply Reply Quote 0
        • M
          McMurphy @SteveITS
          last edited by

          @SteveITS said in Activating IPsec-MB Crypto:

          IIMB is the checkbox in your screenshot. :)

          oh, that's a bit embarrassing :)

          Few more qns pls:

          1. Now I have IPSec-MB enabled what should be selected for crypto hardware?
          2. Should QAT be listed here if it is not an option for my hardware?
          3. When I enabled IPSec-MB do I need to restart pfSense for this to take effect?

          I am trying to improves the speeds to a site-site OVPN link. IPSec runs at approx 95Mbps whereas the best I can get form OVPN+DCO is 30Mbps

          S 1 Reply Last reply Reply Quote 0
          • S
            SteveITS Galactic Empire @McMurphy
            last edited by

            @McMurphy On https://docs.netgate.com/pfsense/en/latest/hardware/cryptographic-accelerators.html#supported-devices it says

            "QAT is ideal for use with IPsec and OpenVPN DCO. It is currently the fastest acceleration option for the algorithms it supports."

            Is this a Netgate model or your own hardware?

            I want to say if you enable QAT it might not say No anymore...I don't have one I can easily toggle though. I think it wouldn't be in the dropdown if it wasn't supported on the hardware.

            Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
            When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
            Upvote 👍 helpful posts!

            M 1 Reply Last reply Reply Quote 0
            • M
              McMurphy @SteveITS
              last edited by

              @SteveITS

              My own hardware.

              I did select QAT but it still shows as "No" on the dashboard so I guess it is not available.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.