SG-5100 - which crypto hardware to enable?
-
For an SG-5100 running pfSense+, under System - Advanced - Miscellaneous - Cryptographic Hardware, which choice is the optimal setting of the following?
- None
- AES-NI CPU-based Acceleration
- AES-NI and BSD Crypto Device (aesni, cryptodev)
- BSD Crypto Device (cryptodev)
- Intel QuickAssist (QAT)
In case it is a factor, the box acts as a server for OpenVPN, IKEv2, and Wireguard connections.
-
QAT is your best bet since you are on Plus and the hardware is capable.