Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    no AES on ZFS

    Scheduled Pinned Locked Moved General pfSense Questions
    15 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ?
      A Former User
      last edited by A Former User

      Hello

      I've noticed that AES on ZFS always inactive.

      No matter what I do..

      Could anyone tell me why?

      Thanks!
      AESonZFS.jpg

      NogBadTheBadN 1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad @A Former User
        last edited by NogBadTheBad

        @dealornodeal

        System -> Advanced -> Miscellaneous enable it and reboot maybe ?

        Screenshot 2021-04-28 at 11.12.45.png

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        ? 1 Reply Last reply Reply Quote 0
        • ?
          A Former User @NogBadTheBad
          last edited by

          @nogbadthebad

          doesn't help

          1 Reply Last reply Reply Quote 0
          • V
            vjizzle
            last edited by

            Hi. If the platform you are running pfSense supports AES you should be able to select it in System -> Advanced -> Miscellaneous.

            As far as I know a reboot is not necessary and the option looks like this:

            cryptographic_setting.png

            JKnottJ ? 2 Replies Last reply Reply Quote 0
            • JKnottJ
              JKnott @vjizzle
              last edited by

              @vjizzle

              Mine's set for AES-NI CPU-based Acceleration and shows enabled on the Dashboard.

              PfSense running on Qotom mini PC
              i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
              UniFi AC-Lite access point

              I haven't lost my mind. It's around here...somewhere...

              ? 1 Reply Last reply Reply Quote 0
              • ?
                A Former User @JKnott
                last edited by A Former User

                @jknott

                what ZFS version do you have?

                I have stripe with no redundancy... no disk / swap encription

                1 Reply Last reply Reply Quote 0
                • ?
                  A Former User @vjizzle
                  last edited by

                  @vjizzle

                  Hi

                  Actually I had this issue before on different hardware.

                  Typically UFS always fine with AES crypto

                  1 Reply Last reply Reply Quote 0
                  • V
                    vjizzle
                    last edited by vjizzle

                    I don't think this is a ZFS thing. I am running ZFS on my main pfSense and it detects AES just fine:

                    CPU Type	Intel(R) Core(TM) i5-7267U CPU @ 3.10GHz
                    4 CPUs: 1 package(s) x 2 core(s) x 2 hardware threads
                    AES-NI CPU Crypto: Yes (active)
                    
                    Hardware crypto	AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS
                    
                    Disk usage: 
                         /	
                    1% of 113GiB - zfs
                         /tmp	
                    0% of 113GiB - zfs
                         /var	
                    0% of 113GiB - zfs
                         /zroot	
                    0% of 113GiB - zfs
                         /var/run	
                    5% of 3.4MiB - ufs in RAM
                    

                    On my main unit I am running pfSense version 2.5.0. What version of pfSense are you running? Maybe try another version? Or some BIOS setting?

                    ? 2 Replies Last reply Reply Quote 0
                    • ?
                      A Former User @vjizzle
                      last edited by A Former User

                      @vjizzle

                      I am on version 2.4.5-RELEASE-p1

                      1 Reply Last reply Reply Quote 0
                      • ?
                        A Former User @vjizzle
                        last edited by A Former User

                        @vjizzle

                        I will update to 2.5.1 and return with result

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          vjizzle @A Former User
                          last edited by

                          @dealornodeal

                          Please make sure that you have a working backup of your current config (2.4.5-p1) and an iso / img saved for version 2.4.5-p1 in case you need to return to that version.

                          For me 2.5.1 was a no-go because multi-wan setup with port forwarding is broken. Consider that if you have a need for multi-wan. Otherwise goodluck!

                          ? 1 Reply Last reply Reply Quote 0
                          • ?
                            A Former User @vjizzle
                            last edited by

                            @vjizzle

                            thank you for advice, however same result here
                            AES-NI CPU Crypto: Yes (inactive)

                            V ? 2 Replies Last reply Reply Quote 0
                            • V
                              vjizzle @A Former User
                              last edited by

                              @dealornodeal
                              Still no option to select AES in System -> Advanced -> Misc?

                              Then maybe it has something to do with your hardware.

                              1 Reply Last reply Reply Quote 0
                              • ?
                                A Former User @A Former User
                                last edited by

                                but as people say.. there is no bad thing without a good thing...

                                finally I learnd some new stuff about pfsense

                                looks like they are working under registered trademark of Electric Sheep Fencing, LLC

                                Pretty self-explanatory
                                sheeps.jpg

                                ? 1 Reply Last reply Reply Quote 0
                                • ?
                                  A Former User @A Former User
                                  last edited by

                                  I have reinstalled pfsense on zfs without swap encryption, dashboard shows AES is active.
                                  Consider this question as closed.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.