Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    XG-7100 best practice OpenVPN and Hardware Crypto

    Scheduled Pinned Locked Moved Official Netgate® Hardware
    5 Posts 4 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RicoR
      Rico LAYER 8 Rebel Alliance
      last edited by

      Hi,

      I'm still not 100% sure about the "best" Hardware Crypto settings for my XG-7100 in OpenVPN.
      System -> Advanced -> Misc -> Cryptographic Hardware is set to "AES-NI and BSD Crypto Device".
      At the Moment I got 7 OpenVPN Instances (2 RAS, 5 Site-to-Site, 45 more Site-to-Site Instances coming very soon) with Hardware Crypto set to "No Hardware Crypto Acceleration". Possible Settings are "BSD cryptodev engine" and "Intel RDRAND engine".
      Encryption Algorithm for most of my Sites is AES-256-GCM, few of them AES-256-CBC.
      Any advice and reasons? I know this is some "ask 3 doctors and get 5 different answers" stuff...but maybe anyone can get more specific when it comes to the XG-7100. :-)

      Thanks!

      -Rico

      1 Reply Last reply Reply Quote 0
      • RicoR
        Rico LAYER 8 Rebel Alliance
        last edited by

        Seriously no opinion on this one? 😐

        -Rico

        1 Reply Last reply Reply Quote 0
        • M
          msf2000
          last edited by

          The XG-7100 has the Atom C3558 CPU in it, which means it support Intel AES-NI instructions. So, that is the best crypto setting in your case.

          1 Reply Last reply Reply Quote 0
          • C
            coreybrett
            last edited by

            I'm curious about this also.

            The only options are "BSD cryptodev engine" and "Intel RDRAND engine".

            "Intel AES-NI" is not an option.

            1 Reply Last reply Reply Quote 0
            • PippinP
              Pippin
              last edited by

              Do not select anything if CPU supports AES-NI.

              I gloomily came to the ironic conclusion that if you take a highly intelligent person and give them the best possible, elite education, then you will most likely wind up with an academic who is completely impervious to reality.
              Halton Arp

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.