• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to find out if my CPU is AES-NI capable ?

Scheduled Pinned Locked Moved General pfSense Questions
25 Posts 9 Posters 11.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    security_paranoid
    last edited by May 15, 2017, 3:52 PM

    How to find out if my CPU is AES-NI capable ?

    I am using Linux. Which command should I use ?

    1 Reply Last reply Reply Quote 0
    • P
      Pippin
      last edited by May 15, 2017, 3:57 PM

      cat /proc/cpuinfo

      I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
      Halton Arp

      1 Reply Last reply Reply Quote 0
      • S
        security_paranoid
        last edited by May 15, 2017, 4:09 PM

        @Pippin:

        cat /proc/cpuinfo

        Sorry I made a mistake while asking the question. I use LInux on the client PC. I am using pfSense on the router. How do I find out if my  CPU is  AES-NI capable from the pfSense web interface ?

        1 Reply Last reply Reply Quote 0
        • ?
          Guest
          last edited by May 15, 2017, 4:27 PM

          dmesg | grep -i cpu

          In my case AMD GX-412TC

          Then enter 'AMD GX-412TC info' into Google, should give you all the info you need.

          1 Reply Last reply Reply Quote 0
          • S
            security_paranoid
            last edited by May 15, 2017, 4:32 PM

            @marjohn56:

            dmesg | grep -i cpu

            In my case AMD GX-412TC

            Then enter 'AMD GX-412TC info' into Google, should give you all the info you need.

            I am a total newbie. Where do I type

            dmesg | grep -i cpu
            ```??
            1 Reply Last reply Reply Quote 0
            • ?
              Guest
              last edited by May 15, 2017, 4:36 PM

              If you have enabled ssh you can shell into pfsense and run it from there or you can run it from Diagnostics/Command Prompt.

              1 Reply Last reply Reply Quote 0
              • S
                security_paranoid
                last edited by May 15, 2017, 4:49 PM

                @marjohn56:

                If you have enabled ssh you can shell into pfsense and run it from there or you can run it from Diagnostics/Command Prompt.

                This is the output

                 CPU: AMD Athlon(tm) 64 X2 Dual Core Processor 5600+ (2913.32-MHz K8-class CPU)
                FreeBSD/SMP: Multiprocessor System Detected: 2 CPUs
                 cpu0 (BSP): APIC ID:  0
                 cpu1 (AP): APIC ID:  1
                cpu0: <acpi cpu="">on acpi0
                cpu1: <acpi cpu="">on acpi0
                powernow0: <powernow! k8="">on cpu0
                powernow1: <powernow! k8="">on cpu1
                SMP: AP CPU #1 Launched!</powernow!></powernow!></acpi></acpi> 
                

                Googled and found this info

                http://www.cpu-world.com/CPUs/K8/AMD-Athlon%2064%20X2%205600+%20-%20ADA5600IAA6CZ%20(ADA5600CZBOX).html

                Cant find AES-NI anywhere so its not AES-NI capable ? Or do I need to do more searching ?

                1 Reply Last reply Reply Quote 0
                • ?
                  Guest
                  last edited by May 15, 2017, 4:54 PM

                  @security_paranoid:

                  Cant find AES-NI anywhere so its not AES-NI capable ? Or do I need to do more searching ?

                  It's an old proc, see this on wiki.

                  https://en.wikipedia.org/wiki/AES_instruction_set

                  1 Reply Last reply Reply Quote 0
                  • S
                    security_paranoid
                    last edited by May 15, 2017, 5:01 PM

                    @marjohn56:

                    @security_paranoid:

                    Cant find AES-NI anywhere so its not AES-NI capable ? Or do I need to do more searching ?

                    It's an old proc, see this on wiki.

                    https://en.wikipedia.org/wiki/AES_instruction_set

                    Thanks for that link.

                    Just curious what will you do when pfSense drops support for non AES-NI processors ?

                    WIll you buy new hardware or move to a different firewall ? I am really frustrated with this development.

                    1 Reply Last reply Reply Quote 0
                    • ?
                      Guest
                      last edited by May 15, 2017, 5:04 PM

                      Mine supports it. PCEngines APU2C4

                      1 Reply Last reply Reply Quote 0
                      • S
                        security_paranoid
                        last edited by May 15, 2017, 5:07 PM

                        @marjohn56:

                        Mine supports it. PCEngines APU2C4

                        You are really lucky. I guess I will have to move to IPcop.

                        1 Reply Last reply Reply Quote 0
                        • ?
                          Guest
                          last edited by May 15, 2017, 5:10 PM

                          Or just replace your hardware.

                          Pfsense 2.4 and previous versions will still work anyway.

                          1 Reply Last reply Reply Quote 0
                          • S
                            security_paranoid
                            last edited by May 15, 2017, 5:13 PM

                            @marjohn56:

                            Or just replace your hardware.

                            Pfsense 2.4 and previous versions will still work anyway.

                            I don't have the cash right now. If I run an old version of pfSense dont you think that will be a security risk?

                            1 Reply Last reply Reply Quote 0
                            • ?
                              Guest
                              last edited by May 15, 2017, 5:25 PM

                              @security_paranoid:

                              @marjohn56:

                              Or just replace your hardware.

                              Pfsense 2.4 and previous versions will still work anyway.

                              I don't have the cash right now. If I run an old version of pfSense dont you think that will be a security risk?

                              No I don't, Quote "The purpose of the instruction set is to improve the speed of applications performing encryption and decryption using the Advanced Encryption Standard (AES)"

                              In other words it speeds up certain functions, the same functions are still carried in software/firmware if you do not have AES, it's just more processor intensive.

                              Using AES you can do away with those software/firmware routines and it's all handled by the processor.

                              Even if you cannot upgrade to 2.5 pfSense will still be secure.

                              1 Reply Last reply Reply Quote 0
                              • F
                                fredfox_uk
                                last edited by May 15, 2017, 7:12 PM

                                There is still some considerable time until 2.5 is here and 2.4 is no longer supported, by which time you may be able to upgrade.

                                1 Reply Last reply Reply Quote 0
                                • S
                                  security_paranoid
                                  last edited by May 15, 2017, 8:51 PM

                                  @fredfox_uk:

                                  There is still some considerable time until 2.5 is here and 2.4 is no longer supported, by which time you may be able to upgrade.

                                  Thats good news.

                                  1 Reply Last reply Reply Quote 0
                                  • P
                                    pfBasic Banned
                                    last edited by May 16, 2017, 4:50 AM May 16, 2017, 4:47 AM

                                    At least in 2.4.0 BETA, you just look on your dashboard now  8).

                                    Cost wise this requirement has (IMO) been blown way out of proportion where home users are concerned.

                                    Very few home users have any need for a CPU exceeding the capabilities of a modern SoC celeron.
                                    You can pick those up new today for $55 (that's motherboard + CPU), so in 2-3 years when this requirement is actually relevant, you will probably be able to pick one up for <$30.

                                    For those home users that do need a powerful system, AES-NI has been around for something like a decade now. eBay is literally full of old SFF desktops from office buildings.

                                    http://www.ebay.com/itm/Lenovo-ThinkCentre-M91p-SSF-i5-2400-3-1GHz-8-GB-500GB-Windows-10-Free-Ship-/252930866220?hash=item3ae3dabc2c:g:Jd0AAOSwaeRZEzw-

                                    Just going off the CPU I use on pfSense and a quick eBay search, $120 gets you an i5-2400 (virtually the same passmark as an i3-7100[not that passmark is a great comparison, but you get the general idea]) with 8GB RAM and a HDD. Add $15 for an i340-t2 and you're set for probably 95%+ of home use scenarios for pfSense. This of course assumes that you are starting out with nothing, and it's today's prices. These things aren't getting more expensive.

                                    All that is to say that you do not need to spend a lot of money to get AES-NI, it's old tech by now.

                                    Capture.JPG
                                    Capture.JPG_thumb

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      apple4ever Banned
                                      last edited by May 21, 2017, 5:05 AM

                                      @security_paranoid:

                                      Thanks for that link.

                                      Just curious what will you do when pfSense drops support for non AES-NI processors ?

                                      WIll you buy new hardware or move to a different firewall ? I am really frustrated with this development.

                                      Well my hope is they will change their mind, because it's clearly an incorrect decision. After that, My first plan is to hack it in there, because the developers would have to go out of their way to remove support, so it shouldn't be too hard to add it back in. The second is to move to another firewall. It's too bad, I wanted to support the project via Gold, and was literally going to buy it the week the news hit.

                                      1 Reply Last reply Reply Quote 0
                                      • P
                                        pfBasic Banned
                                        last edited by May 21, 2017, 5:46 AM

                                        You would go to all that effort to avoid spending a few bucks on a cpu from the last decade?

                                        1 Reply Last reply Reply Quote 0
                                        • ?
                                          Guest
                                          last edited by May 21, 2017, 9:44 AM

                                          Bizarre…

                                          It's called evolution...

                                          1 Reply Last reply Reply Quote 0
                                          5 out of 25
                                          • First post
                                            5/25
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received