PC Engines apu2 experiences
-
Why pfsense 2.5 shows "AES-NI CPU Crypto: No" when in 2.4.x there was YES on APU2? Also on 2.5 there is in other line: Hardware crypto AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS
-
@sikita said in PC Engines apu2 experiences:
Why pfsense 2.5 shows "AES-NI CPU Crypto: No" when in 2.4.x there was YES on APU2?
Anything to do with this problem? If so, it appears to be fixed in 2.5.1.
-
@bigsy Ok, thank you. Seems to be GUI bug and does not involve using HW crypto.
-
@sikita I am on pfSense 2.5.0 and here it says:
Do you have AES-NI enabled?
-
Can anyone share there System / Advanced / Networking on a APU2
Mine are
as these are the defaults, grabbed them from a VM installation, which is not quit the same setup.
The old and not anymore recommend settings from https://teklager.se/en/knowledge-base/apu2-1-gigabit-throughput-pfsense/ are quit different!
...and there is a new settings present in 2.5.0. " hn ALTQ support"
Could anyone elaborate on all these or there settings?
-
There are no hn NICs on any APU so it makes no difference. You can disable it.
Steve
-
I performed all the bootloader and other tweaks mentioned in various threads throughout the years on my <= 2.45-p1 installation and now I don't remember what they all are. It would be great if somebody could post what things to look for (to remove?) when you update your apu2 from 2.4.5 --> 2.5.0.
At the moment because of the performance issues, I'm not upgrading.
-
@valnar said in PC Engines apu2 experiences:
when you update your apu2 from 2.4.5 --> 2.5.0.
Hi,
With that, I would wait a little longer
here,....you will find a lot of useful info if you even decide to upgrade...
https://teklager.se/en/knowledge-base/
https://teklager.se/en/knowledge-base/apu2-1-gigabit-throughput-pfsense/+++edit:
and of course
https://pcengines.github.io/ -
Smooth update to pfSense 2.5.1 CE
-
Updated to bios coreboot v4.13.05.
-
@qinn Fine !
I am still on 2.4.5_1.
Did you notice any performance degradation ? -
@flok No, so far not.
-
I received an email notification about v4.14.0.2 and this IMPORTANT message was included:
To update the firmware and keep the runtime configuration unchanged please use the following command:
flashrom -p internal -w apuX_v4.14.0.2.rom --fmap -i COREBOOT
The persistent runtime configuration works only when migrating from versions v4.14.0.1 and later. The feature is not yet supported on apu1. Flashrom version needs to be v1.1 or newer.I did the upgrade from v4.14.0.1 with that new command without any issues. However, for the longest time this is what I've been using:
flashrom -p internal -w apuX_v4.14.0.2.rom
What is the difference?
-
@kevindd992002
I'm not by any means an expert on coreboot, butflashrom -p internal -w apuX_v4.14.0.2.rom
will overwrite the entire flash chip with the new rom file.
flashrom -p internal -w apuX_v4.14.0.2.rom --fmap -i COREBOOT
The flash chip has various partitions defined in a 'flashmap' format and this command specifies which area to overwrite. This probably allows for user altered settings such as seabios boot order changes to persist and not get overwritten during the coreboot update, but I haven't tried it out.
-
@bigsy said in PC Engines apu2 experiences:
@kevindd992002
I'm not by any means an expert on coreboot, butflashrom -p internal -w apuX_v4.14.0.2.rom
will overwrite the entire flash chip with the new rom file.
flashrom -p internal -w apuX_v4.14.0.2.rom --fmap -i COREBOOT
The flash chip has various partitions defined in a 'flashmap' format and this command specifies which area to overwrite. This probably allows for user altered settings such as seabios boot order changes to persist and not get overwritten during the coreboot update, but I haven't tried it out.
That's what I thought. However, with the 1st command I have never seen any seabios setting get changed when I use it to update my APU2. I'm wondering if it's really better to use the 2nd command from this point moving forward.
-
@kevindd992002 If you look at the changes to the pcEngines fork of SeaBIOS, the addition of 'support for persistent bootorder in FMAP region' has only been in the most recent release of SeaBIOS v1.14.0.1 and similarly for sortbootorder v4.6.21.
-
@bigsy I see. So we're just preserving boot order here? Since I just have one boot device in my APU2, then it wouldn't matter to me.
-
For the APU2C4, why is it that when I have a serial cable connected between its serial port and a computer, its USB ports don't work? I have a UPS plugged in to one of its USB ports and I use the NUT package in pfsense. As soon as I connect to the hardware through the serial port (using putty), the USB port does not work. Unplugging the serial cable fixes the issue and that's why I know it's the one causing it. This is happening for both of my APU2C4 boxes.
-
@kevindd992002 said in PC Engines apu2 experiences:
connected between its serial port and a computer, its USB ports don't work?
Hmmmm, I haven't seen it yet, it is true we don't even connect to MOBO in this multiple way...
Have you tried to remove NUT? (of course temporarily)
-
@daddygo said in PC Engines apu2 experiences:
@kevindd992002 said in PC Engines apu2 experiences:
connected between its serial port and a computer, its USB ports don't work?
Hmmmm, I haven't seen it yet, it is true we don't even connect to MOBO in this multiple way...
Have you tried to remove NUT? (of course temporarily)
I haven't yet but I see the usb disconnect message in the terminal itself so I figured it's a board issue. I also use the USB port only for NUT so removing it will be a moot point but I can still try for the sake of troubleshooting.