Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HAProxy + Intel QAT

    Scheduled Pinned Locked Moved Cache/Proxy
    7 Posts 4 Posters 1.4k Views 4 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      justme2
      last edited by

      Anyone happen to know the status of movement to OpenSSL v1.1.x and HAProxy v1.8, so that Intel QAT can be utilized? Running Supermicro's 5019D-FN8TP with the Xeon D-2146NT CPU. This may be equally interesting for offloading in other components as well.

      Thanks!

      P 1 Reply Last reply Reply Quote 0
      • J Offline
        joelaue
        last edited by

        I haven't really been a pfSense user, but if this can be done with pfSense, I'm interested in this as well. As you suggest, the QAT offloading is available starting with HAProxy 1.8. This video provides details, with reference back to 01.org.

        1 Reply Last reply Reply Quote 0
        • P Offline
          PiBa @justme2
          last edited by

          openssl 1.1.x will be in pfSense 2.5.x.. first development snaphots should arrive 'soon' i guess.

          1 Reply Last reply Reply Quote 1
          • J Offline
            justme2
            last edited by

            Excellent news! Anxious to see it in operation.

            1 Reply Last reply Reply Quote 0
            • planedropP Offline
              planedrop
              last edited by

              Did you end up getting QAT to properly work on this platform?

              J 1 Reply Last reply Reply Quote 0
              • J Offline
                justme2 @planedrop
                last edited by

                Honestly, have not. Unfortunately, as with most things - priorities change with each week. Recently, have been more focused on "openvpn --show-engines" revealing nothing and whether or not that has material implications to other parts of pfSense as well. I'll need to check one device as it has QAT built-in for up to 40Gbps crypto/compression acceleration (Supermicro 5019D-FN8TP). When I get a chance to review, I'll let you know if the dashboard status has changed from "QAT Crypto: No" to "QAT Crypto: <positive response>". Then it would be a question of doing some bench mark work to determine what it means in context. The primary interests in this were for VPN (OpenVPN/WireGuard) and SSL offload (HAProxy). One of Intel's own whitepapers on the subject (https://networkbuilders.intel.com/solutionslibrary/accelerating-haproxy-with-intel-quickassist-technology) is rather interesting to see the differential. As with most things, it's likely "best case" for each bucket but interesting nonetheless.

                planedropP 1 Reply Last reply Reply Quote 1
                • planedropP Offline
                  planedrop @justme2
                  last edited by

                  @justme2 Gotcha, well this is a good start at least. I'm considering the same platform for a proper 10 gigabit system (WAN side with NAT) as my Netgate 6100 isn't keeping up with my new WAN provider. QAT is fairly important for me though as well.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.