Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    AES-NI or IPsec-MB

    Scheduled Pinned Locked Moved OpenVPN
    7 Posts 3 Posters 525 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Antibiotic
      last edited by Antibiotic

      HELLO, WHAT SHOULD ME USE WITH OpenVPN DCO. BOTH OF THEM OR ONLY ONE OF THEM?SHOULD MEVKEEP ON IN ADVANCED SETTINGS, BOTH OF THEM?OR ONLY ONE OF THEM?

      pfSense plus 24.11 on Topton mini PC
      CPU: Intel N100
      NIC: Intel i-226v 4 pcs
      RAM : 16 GB DDR5
      Disk: 128 GB NVMe
      Brgds, Archi

      M 1 Reply Last reply Reply Quote 0
      • M
        mcury Rebel Alliance @Antibiotic
        last edited by

        @Antibiotic There is a very good documentation @ https://docs.netgate.com/pfsense/en/latest/config/advanced-misc.html#cryptographic-thermal-hardware

        If you have any doubts after reading it, feel free to ask.
        Not that I'll know the answer, but someone else might.

        dead on arrival, nowhere to be found.

        A 1 Reply Last reply Reply Quote 0
        • A
          Antibiotic @mcury
          last edited by

          @mcury I HAVE READ THIS A LONG TIME AGO. THE QUESTION IS BOTH OF THEM KEEP ON. WHAT METOD WILL USE OPENVPN?OR HOW TO CHECK?

          pfSense plus 24.11 on Topton mini PC
          CPU: Intel N100
          NIC: Intel i-226v 4 pcs
          RAM : 16 GB DDR5
          Disk: 128 GB NVMe
          Brgds, Archi

          M 1 Reply Last reply Reply Quote 0
          • M
            mcury Rebel Alliance @Antibiotic
            last edited by

            @Antibiotic said in AES-NI or IPsec-MB:

            @mcury I HAVE READ THIS A LONG TIME AGO. THE QUESTION IS BOTH OF THEM KEEP ON. WHAT METOD WILL USE OPENVPN?OR HOW TO CHECK?

            e64df6d3-fa98-4911-9854-3d8ebc2ad2c2-image.png

            c3844a24-116e-470a-b001-3d66b6693c47-image.png

            You don't have QAT, so ignore that.
            If you are using OpenVPN DCO with ChaCha20-Poly1305, enable IPsec-MB.
            If you are using OpenVPN DCO with AES-GCM, enable IPSec-MB.
            If your device don't support both of the options above, enable AES-NI.

            I personally would run iperf tests to confirm which is better for your hardware.

            dead on arrival, nowhere to be found.

            A 1 Reply Last reply Reply Quote 1
            • A
              Antibiotic @mcury
              last edited by

              @mcury said in AES-NI or IPsec-MB:

              ChaCha20-Poly1305

              thank you, will any benefits to use ChaCha20-Poly1305 instead AES-GCM, with PSec-MB regarding speed increasing?

              pfSense plus 24.11 on Topton mini PC
              CPU: Intel N100
              NIC: Intel i-226v 4 pcs
              RAM : 16 GB DDR5
              Disk: 128 GB NVMe
              Brgds, Archi

              M 1 Reply Last reply Reply Quote 0
              • M
                mcury Rebel Alliance @Antibiotic
                last edited by

                @Antibiotic said in AES-NI or IPsec-MB:

                thank you, will any benefits to use ChaCha20-Poly1305 instead AES-GCM, with PSec-MB regarding speed increasing?

                The best way to find out is to create a openvpn server in pfSense, connect two devices to it in different networks, fire up openvpn at both sides to the openvpn server in pfSense and run iperf test, monitoring CPU usage of the firewall.

                Take in consideration also the clients connecting to it, if there is no acceleration at the client side, ChaChaPoly-1305 would be easier for the client.

                dead on arrival, nowhere to be found.

                1 Reply Last reply Reply Quote 0
                • JonathanLeeJ
                  JonathanLee
                  last edited by

                  I use the SafeXcel and disable the IPsec-MB Crypto, it is much faster with OpenVPN connections that way for my 2100. I use to have both enabled but it caused a slower connection for some reason. The way I look at it, if you have a dedicated crypto chip use it and deactivate the other.

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.