• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Best Crypto Accelerator?

Scheduled Pinned Locked Moved Hardware
9 Posts 4 Posters 15.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H
    HypeTelecon
    last edited by Oct 23, 2008, 9:40 PM

    What would be the best PCI/PCIe Crypto Accelerator that pfSense would be capable of using for IPSec 3DES offloading?

    1 Reply Last reply Reply Quote 0
    • W
      wallabybob
      last edited by Oct 24, 2008, 10:30 AM

      The answer probably depends on the data rate at which you want to encrypt.

      1 Reply Last reply Reply Quote 0
      • M
        MeatPuppet
        last edited by Oct 24, 2008, 2:31 PM Oct 24, 2008, 2:26 PM

        I have had real good experience with HiFn, they have cards for most any requirements and not to mention price range.
        I am running a HiFn DS100 under Linux, using the "OpenBSD/FreeBSD Cryptographic Framework (OCF)" port for Linux, and it works really well.

        The BSD application cryptotest (running on Slackware Linux) gives me the following results:

        des:
        0.005 sec, 2    des crypts, 65280 bytes, 28023181 bytes/sec, 213.8 Mb/sec

        3des:
        0.004 sec, 2   3des crypts, 65280 bytes, 31271856 bytes/sec, 238.6 Mb/sec

        aes256
        0.004 sec, 2   aes256 crypts, 65280 bytes, 32007845 bytes/sec, 244.2 Mb/sec

        The card has NIST certified hardware implementations of the most widely used algorithms (AES, DES, 3DES, SHA, HMAC);
        not to mention a True Hardware RNG, which is my main reason for investing, I am in serious need of entropy…

        The BSD/Linux driver supports up to 64 cards working toghether, and they also have much more powerful cards than the DS100 (the cheapest of the bunch) if that is needed,
        the driver is also Open Source, which is a key factor.

        Since I am mainly a Linux zealot, I do not know if this card works with pfSense, but considering the driver is actually written for freeBSD and then ported to Linux I would almost dare to assume so.

        Best Regards,
        MeatPuppet

        1 Reply Last reply Reply Quote 0
        • H
          HypeTelecon
          last edited by Oct 24, 2008, 6:47 PM

          What would be the best place to purchase these cards from?

          @MeatPuppet:

          I have had real good experience with HiFn, they have cards for most any requirements and not to mention price range.
          I am running a HiFn DS100 under Linux, using the "OpenBSD/FreeBSD Cryptographic Framework (OCF)" port for Linux, and it works really well.

          The BSD application cryptotest (running on Slackware Linux) gives me the following results:

          des:
          0.005 sec, 2    des crypts, 65280 bytes, 28023181 bytes/sec, 213.8 Mb/sec

          3des:
          0.004 sec, 2   3des crypts, 65280 bytes, 31271856 bytes/sec, 238.6 Mb/sec

          aes256
          0.004 sec, 2   aes256 crypts, 65280 bytes, 32007845 bytes/sec, 244.2 Mb/sec

          The card has NIST certified hardware implementations of the most widely used algorithms (AES, DES, 3DES, SHA, HMAC);
          not to mention a True Hardware RNG, which is my main reason for investing, I am in serious need of entropy…

          The BSD/Linux driver supports up to 64 cards working toghether, and they also have much more powerful cards than the DS100 (the cheapest of the bunch) if that is needed,
          the driver is also Open Source, which is a key factor.

          Since I am mainly a Linux zealot, I do not know if this card works with pfSense, but considering the driver is actually written for freeBSD and then ported to Linux I would almost dare to assume so.

          Best Regards,
          MeatPuppet

          1 Reply Last reply Reply Quote 0
          • D
            dotdash
            last edited by Oct 24, 2008, 8:46 PM

            I've had good results with the vpn1411 http://www.soekris.com/vpn1401.htm

            1 Reply Last reply Reply Quote 0
            • M
              MeatPuppet
              last edited by Oct 24, 2008, 8:54 PM Oct 24, 2008, 8:51 PM

              I picked up mine from eBay, it is selling for around the $100-150 mark, depending if you can be bothered to wait or not… It should be noted that most of these are PCI64 cards, but personally I only find this to be an advantage.

              Best Regards,
              MeatPuppet

              1 Reply Last reply Reply Quote 0
              • H
                HypeTelecon
                last edited by Oct 27, 2008, 2:53 PM

                Is there a PCIe based crypto accelerator that will work with FreeBSD? I'm looking for something with a little more horse power.

                1 Reply Last reply Reply Quote 0
                • D
                  dotdash
                  last edited by Oct 27, 2008, 4:01 PM

                  Hifn makes the 255, which is a PCIe card based on the 8155 chip. I'm not sure if it's supported in FreeBSD though, and they are significantly more expensive than the PCI cards.

                  1 Reply Last reply Reply Quote 0
                  • H
                    HypeTelecon
                    last edited by Oct 29, 2008, 5:23 PM

                    Can anyone confirm or deny that this particular card is supported by FreeBSD 6.2?

                    @dotdash:

                    Hifn makes the 255, which is a PCIe card based on the 8155 chip. I'm not sure if it's supported in FreeBSD though, and they are significantly more expensive than the PCI cards.

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received