Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Gigabit OpenVPN, whats needed?

    Scheduled Pinned Locked Moved OpenVPN
    6 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bofr
      last edited by

      Hi.
      I tried searching for a good answer but found nothing definitive.
      Has anyone actually managed to get a box up to about gigabit speeds over openvpn aes-256-cbc?
      Right now the most speed I can get is about 550Mbps down, and thats using an FX-6300.
      Before I shell out loads of cash for a new machine I thought I would get some community input.

      It would be nice if this was achievable with some kind of low powered small formfactor but I kind of doubt it.

      Thanks.

      1 Reply Last reply Reply Quote 0
      • E
        ericnix
        last edited by

        Does Intel AES hardware crypto help?

        I have mine enabled, but unfortunately I only have a gig down (40 Mbps up) with my Comcast cable modem.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          OpenVPN spends so much time context switching that AES-NI can help a little but not a lot. Single-thread CPU performance helps the most.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • B
            bofr
            last edited by

            This is a lot more difficult than I thought.
            My current processor gets about 1400 points in single thread according to passmark.
            So I would need something with about twice that.
            https://www.cpubenchmark.net/singleThread.html
            Currently the only processor with that kind of oomph is the 8086 which otherwise seems waaay overpowered for a simple router.
            I think I will go with one of the pentium golds. About 1000 points more than now and under $100.

            1 Reply Last reply Reply Quote 0
            • B
              bofr
              last edited by

              $400 later and I now have a router based on a G5400.
              The other end of the vpn is currently under heavy load so I can't get a good measure but running at 300 mbps gives a cpu usage of about 30%, 100mbit about 10%.
              Extrapolating from that..this might actually work.
              Will report back later when I get some better speeds.

              1 Reply Last reply Reply Quote 0
              • V
                VAMike
                last edited by

                switch to aes-128-gcm

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.