Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.5.0 OpenVPN no AES-NI

    Scheduled Pinned Locked Moved 2.5 Development Snapshots (Retired)
    14 Posts 5 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ
      jimp Rebel Alliance Developer Netgate
      last edited by

      Did you set AES-NI under System > Advanced, Misc. in the crypto module options?

      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • H
        hec
        last edited by

        Yes i tried both - AES-NI and BSD Cyptodev

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          Any messages in the system log about aesni? Check /var/log/dmesg.boot specifically.

          You should see a line like this:

          Aug 10 10:37:45 pfSense kernel: aesni0: <AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS> on motherboard
          

          Is it enabled in your BIOS?

          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • H
            hec
            last edited by

            Yes it is enabled in the BIOS as you see above the CPU does report the correct features

            I only see the CPU features in the dmesg.boot.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              Is aesni loaded in kldstat output?

              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • H
                hec
                last edited by

                kldstat
                Id Refs Address                Size Name
                 1   19 0xffffffff80200000  38d7128 kernel
                 2    2 0xffffffff83ad9000     a448 opensolaris.ko
                 3    1 0xffffffff83ae4000   3ba750 zfs.ko
                 4    1 0xffffffff8423d000     1000 cpuctl.ko
                 5    1 0xffffffff8423e000     8c90 aesni.ko
                 6    1 0xffffffff84247000     37e8 cryptodev.ko
                
                
                1 Reply Last reply Reply Quote 0
                • M
                  mervincm
                  last edited by

                  This post is deleted!
                  1 Reply Last reply Reply Quote 0
                  • yon 0Y
                    yon 0
                    last edited by

                    I have reported this issue before.

                    2.png

                    1 Reply Last reply Reply Quote 0
                    • H
                      hec
                      last edited by

                      OK so there is an patch for ssl but this patch is causing problems as i read.

                      OpenSSL was patched in 2018 but this bug exists in pfsense in 2020? Or is there another bug which is causing this?

                      1 Reply Last reply Reply Quote 0
                      • Bob.DigB
                        Bob.Dig LAYER 8
                        last edited by Bob.Dig

                        In 2.4.* it is also not showing and, as far as I remember, never was (Hyper-V), so I hope it is working automagically.

                        1 Reply Last reply Reply Quote 0
                        • jimpJ
                          jimp Rebel Alliance Developer Netgate
                          last edited by

                          AES-NI will never show on the OpenVPN page. OpenVPN/OpenSSL will detect and use AES-NI automatically.

                          The only place you can pick AES-NI from a list is under System > Advanced on the Misc tab to tell the system whether or not to load the kernel module. Primarily that will affect IPsec, not OpenVPN.

                          Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                          Need help fast? Netgate Global Support!

                          Do not Chat/PM for help!

                          1 Reply Last reply Reply Quote 2
                          • H
                            hec
                            last edited by

                            Thank you for the clarification.

                            But why is there the option if it will be NEVER shown in the OpenVPN configuration?

                            1 Reply Last reply Reply Quote 0
                            • jimpJ
                              jimp Rebel Alliance Developer Netgate
                              last edited by

                              Those are two completely different sets of crypto controls. One for the operating system in general, and one specifically for OpenVPN. There are many more uses for crypto on pfSense than OpenVPN.

                              AES-NI never shows in OpenVPN because it isn't a relevant option. It is not considered a crypto "engine" to OpenVPN or OpenSSL, because it uses it automatically. Some devices have to be selected manually.

                              Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                              Need help fast? Netgate Global Support!

                              Do not Chat/PM for help!

                              1 Reply Last reply Reply Quote 3
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.