Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    no AES on ZFS

    Scheduled Pinned Locked Moved General pfSense Questions
    15 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad @A Former User
      last edited by NogBadTheBad

      @dealornodeal

      System -> Advanced -> Miscellaneous enable it and reboot maybe ?

      Screenshot 2021-04-28 at 11.12.45.png

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      ? 1 Reply Last reply Reply Quote 0
      • ?
        A Former User @NogBadTheBad
        last edited by

        @nogbadthebad

        doesn't help

        1 Reply Last reply Reply Quote 0
        • V
          vjizzle
          last edited by

          Hi. If the platform you are running pfSense supports AES you should be able to select it in System -> Advanced -> Miscellaneous.

          As far as I know a reboot is not necessary and the option looks like this:

          cryptographic_setting.png

          JKnottJ ? 2 Replies Last reply Reply Quote 0
          • JKnottJ
            JKnott @vjizzle
            last edited by

            @vjizzle

            Mine's set for AES-NI CPU-based Acceleration and shows enabled on the Dashboard.

            PfSense running on Qotom mini PC
            i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
            UniFi AC-Lite access point

            I haven't lost my mind. It's around here...somewhere...

            ? 1 Reply Last reply Reply Quote 0
            • ?
              A Former User @JKnott
              last edited by A Former User

              @jknott

              what ZFS version do you have?

              I have stripe with no redundancy... no disk / swap encription

              1 Reply Last reply Reply Quote 0
              • ?
                A Former User @vjizzle
                last edited by

                @vjizzle

                Hi

                Actually I had this issue before on different hardware.

                Typically UFS always fine with AES crypto

                1 Reply Last reply Reply Quote 0
                • V
                  vjizzle
                  last edited by vjizzle

                  I don't think this is a ZFS thing. I am running ZFS on my main pfSense and it detects AES just fine:

                  CPU Type	Intel(R) Core(TM) i5-7267U CPU @ 3.10GHz
                  4 CPUs: 1 package(s) x 2 core(s) x 2 hardware threads
                  AES-NI CPU Crypto: Yes (active)
                  
                  Hardware crypto	AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS
                  
                  Disk usage: 
                       /	
                  1% of 113GiB - zfs
                       /tmp	
                  0% of 113GiB - zfs
                       /var	
                  0% of 113GiB - zfs
                       /zroot	
                  0% of 113GiB - zfs
                       /var/run	
                  5% of 3.4MiB - ufs in RAM
                  

                  On my main unit I am running pfSense version 2.5.0. What version of pfSense are you running? Maybe try another version? Or some BIOS setting?

                  ? 2 Replies Last reply Reply Quote 0
                  • ?
                    A Former User @vjizzle
                    last edited by A Former User

                    @vjizzle

                    I am on version 2.4.5-RELEASE-p1

                    1 Reply Last reply Reply Quote 0
                    • ?
                      A Former User @vjizzle
                      last edited by A Former User

                      @vjizzle

                      I will update to 2.5.1 and return with result

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        vjizzle @A Former User
                        last edited by

                        @dealornodeal

                        Please make sure that you have a working backup of your current config (2.4.5-p1) and an iso / img saved for version 2.4.5-p1 in case you need to return to that version.

                        For me 2.5.1 was a no-go because multi-wan setup with port forwarding is broken. Consider that if you have a need for multi-wan. Otherwise goodluck!

                        ? 1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User @vjizzle
                          last edited by

                          @vjizzle

                          thank you for advice, however same result here
                          AES-NI CPU Crypto: Yes (inactive)

                          V ? 2 Replies Last reply Reply Quote 0
                          • V
                            vjizzle @A Former User
                            last edited by

                            @dealornodeal
                            Still no option to select AES in System -> Advanced -> Misc?

                            Then maybe it has something to do with your hardware.

                            1 Reply Last reply Reply Quote 0
                            • ?
                              A Former User @A Former User
                              last edited by

                              but as people say.. there is no bad thing without a good thing...

                              finally I learnd some new stuff about pfsense

                              looks like they are working under registered trademark of Electric Sheep Fencing, LLC

                              Pretty self-explanatory
                              sheeps.jpg

                              ? 1 Reply Last reply Reply Quote 0
                              • ?
                                A Former User @A Former User
                                last edited by

                                I have reinstalled pfsense on zfs without swap encryption, dashboard shows AES is active.
                                Consider this question as closed.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.