AES-NI question for XG-1541
-
Hello
Apologies if this is a silly question but I've been running my XG-1541s (21.05.02 with update to 22.05 scheduled this weekend) with crypto set to AES-NI + BSD Cryptodev.
Is there any reason to change it to just AES-NI (or any reason not to?)
Thanks!
-
@scottcall https://docs.netgate.com/pfsense/en/latest/config/advanced-misc.html#cryptographic-thermal-hardware
“ Loads both the AES-NI and BSD Crypto Device modules together, which is the optimal configuration in most cases. Choose this unless a specific environment or configuration is found to work better without it.”
:) -
The best is Intel Quick Assist if your Hardware supports it.
-
That doc is a bit old really. Loading AES-NI by itself is better in anything after 22.01. The BSD crypto device is not used by anything usefully from that point on. OpenVPN (OpenSSL) will use AES-NI directly if the CPU supports it OpenVPN with DCO enabled will use it with the AES-NI module loaded as will IPSec.
And yes anything with QAT support should use that instead.Steve