Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Encryption hardware

    Scheduled Pinned Locked Moved Hardware
    5 Posts 5 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • OceanwatcherO
      Oceanwatcher
      last edited by

      We have a firewall based on this:

      https://www.supermicro.nl/products/system/1U/5018/SYS-5018A-FTN4.cfm

      As far as I know, there should be a chip that can assist with encryption on this board. How do we enable this? Where in pfSense 2.3.1 can we set it up?

      Regards,

      Oceanwatcher
      2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

      1 Reply Last reply Reply Quote 0
      • E
        edwardwong
        last edited by

        I guess you are talking about AES-NI feature of the CPU?

        1 Reply Last reply Reply Quote 0
        • K
          Keljian
          last edited by

          support for quickassist is not yet baked into pfsense (coming soon)

          1 Reply Last reply Reply Quote 0
          • MikeV7896M
            MikeV7896
            last edited by

            I believe there's an option in System > Advanced on one of the tabs to enable AES-NI support. Then you'll want to use the AES-GCM encryption algorithm for IPSEC to take advantage of the hardware acceleration. OpenVPN doesn't (yet?) support AES-GCM, so you won't see any performance increase due to AES-NI for OpenVPN.

            It is starting to sound like FreeBSD QuickAssist support might not show up for Rangeley processors.
            https://forum.pfsense.org/index.php?topic=108255.0 (posts on page 2 and 3 specifically)
            https://www.reddit.com/r/PFSENSE/comments/4earbc/intel_quickassist_availability/

            The S in IOT stands for Security

            1 Reply Last reply Reply Quote 0
            • ?
              Guest
              last edited by

              As far as I know, there should be a chip that can assist with encryption on this board.

              There is not a really extra chip for it, but more a CPU or SoC register that offers AES-NI and over that
              it would be able to speed up the IPSec performance if the AES-GCM mode will be chosen.

              How do we enable this? Where in pfSense 2.3.1 can we set it up?

              I think in the version 2.3.1 it is an issue about that and so I personally would be more looking
              to go with the version 2.2.6 (64Bit) instead of the version 2.3.1.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.