• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

AES-NI and OpenVPN?

Scheduled Pinned Locked Moved Hardware
45 Posts 5 Posters 5.3k Views 6 Watching
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N Offline
    N8LBV @stephenw10
    last edited by Apr 29, 2023, 6:15 PM

    @stephenw10 Thanks! excellent clarifcations.
    -Steve

    I feel more like I do now.

    N 1 Reply Last reply Apr 29, 2023, 6:18 PM Reply Quote 0
    • N Offline
      N8LBV @N8LBV
      last edited by Apr 29, 2023, 6:18 PM

      Laptop single nic OpenVPN HTTP throughput test.
      35Watt Laptop CPU from Jan 2009. NO-AES-NI.

      Intel® Core™2 Duo Processor T6400
      2M Cache, 2.00 GHz, 800 MHz FSB
      c2.jpg

      I feel more like I do now.

      N 1 Reply Last reply Apr 29, 2023, 6:26 PM Reply Quote 0
      • N Offline
        N8LBV @N8LBV
        last edited by Apr 29, 2023, 6:26 PM

        Same test through dual NAT no OpenVPN.
        That early 2009 laptop (running PFsense) has a Broadcom NIC on the mainboard.
        nat.jpg

        I feel more like I do now.

        1 Reply Last reply Reply Quote 0
        • R Offline
          RobbieTT @stephenw10
          last edited by Apr 29, 2023, 6:43 PM

          @stephenw10 said in AES-NI and OpenVPN?:

          The line in the system information widget currently shows if the CPU is reporting it supports AES-NI. It shows as active if the kernel module is loaded.

          Just out of curiosity, why would the kernel module not be loaded?

           2023-04-29 at 19.39.18.png

          ☕️

          J D 2 Replies Last reply Apr 29, 2023, 7:18 PM Reply Quote 0
          • J Offline
            JimBob Indiana @RobbieTT
            last edited by JimBob Indiana Apr 29, 2023, 7:25 PM Apr 29, 2023, 7:18 PM

            @robbiett Good question. Mine since I can remember said “Inactive”. I played with the VPN configuration options yesterday and today, says “Active”.

            I didn’t actually do a VPN.

            CPU Type Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
            Current: 2800 MHz, Max: 3601 MHz
            8 CPUs: 1 package(s) x 4 core(s) x 2 hardware threads
            AES-NI CPU Crypto: Yes (active)
            QAT Crypto: No
            Hardware crypto AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS

            R D 2 Replies Last reply Apr 29, 2023, 8:03 PM Reply Quote 0
            • R Offline
              RobbieTT @JimBob Indiana
              last edited by Apr 29, 2023, 8:03 PM

              @jimbob-indiana I had presumed (and we all know where assumptions lead) was that QAT was being preferred* over AES-NI; now I am not so sure.

              ☕️


              *As it is rather excellent

              1 Reply Last reply Reply Quote 0
              • D Offline
                Dobby_ @RobbieTT
                last edited by Dobby_ Apr 29, 2023, 11:30 PM Apr 29, 2023, 11:14 PM

                @robbiett

                please have a look at the Intel QAT, because this is loaded instead of the AES-NI!!!! You can use AES-NI or Intel QAT
                but not both!

                1682793716026-2023-04-29-at-19.39.18.jpg

                #~. @Dobby

                Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                R 1 Reply Last reply Apr 30, 2023, 9:36 AM Reply Quote 0
                • D Offline
                  Dobby_ @JimBob Indiana
                  last edited by Apr 29, 2023, 11:33 PM

                  @jimbob-indiana said in AES-NI and OpenVPN?:

                  Good question. Mine since I can remember said “Inactive”. I played with the VPN configuration options yesterday and today, says “Active”.

                  Mine fresh installed says "active" too!
                  You can see with no configured VPN actual!

                  AES-NI.jpg

                  #~. @Dobby

                  Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                  PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                  PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                  J 1 Reply Last reply Apr 30, 2023, 3:34 PM Reply Quote 1
                  • R Offline
                    RobbieTT @Dobby_
                    last edited by Apr 30, 2023, 9:36 AM

                    @dobby_ said in AES-NI and OpenVPN?:

                    @robbiett

                    please have a look at the Intel QAT, because this is loaded instead of the AES-NI!!!! You can use AES-NI or Intel QAT
                    but not both!

                    Err, I did.

                    I literally stated my assumption that QAT was preferred over AES-NI and the graphic showing QAT (active) & AES-NI (inactive) is my own (!!!!...?).

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      JimBob Indiana @Dobby_
                      last edited by Apr 30, 2023, 3:34 PM

                      @dobby_ I have no idea why mine said Inactive and now says Active. All I did was mess with the vpn stuff just to see what is required.

                      D 1 Reply Last reply Apr 30, 2023, 5:58 PM Reply Quote 0
                      • D Offline
                        Dobby_ @JimBob Indiana
                        last edited by Apr 30, 2023, 5:58 PM

                        @jimbob-indiana said in AES-NI and OpenVPN?:

                        @dobby_ I have no idea why mine said Inactive and now says Active. All I did was mess with the vpn stuff just to see what is required.

                        I was only changing the settings in the filed shown below
                        in the picture (red arrow), after that the AES-NI was shown
                        permanent as "active" and this also with no configured VPN! I was choosing both entries from the menue:
                        AES-NI & CryptoDev

                        So I think since that, the CryptoDev is taking contact to the
                        AES-NI and there fore it will be announced as "active".

                        AES_NI Cryptodev.jpg

                        #~. @Dobby

                        Turris Omnia - 4 Ports - 2 GB RAM / TurrisOS 7 Release (Btrfs)
                        PC Engines APU4D4 - 4 Ports - 4 GB RAM / pfSense CE 2.7.2 Release (ZFS)
                        PC Engines APU6B4 - 4 Ports - 4 GB RAM / pfSense+ (Plus) 24.03_1 Release (ZFS)

                        1 Reply Last reply Reply Quote 0
                        • S Offline
                          stephenw10 Netgate Administrator
                          last edited by Apr 30, 2023, 7:49 PM

                          The active/inactive label only indicates whether or not the module is loaded. Not whether it's actually in use.

                          Technically you could load both modules but since both would attempt to register for the same crypto algorithms the result would be confusing. So the webgui only offers the choice to load one of them.

                          R 1 Reply Last reply May 1, 2023, 12:01 PM Reply Quote 2
                          • R Offline
                            RobbieTT @stephenw10
                            last edited by May 1, 2023, 12:01 PM

                            @stephenw10 Hey, an assumption turned out right! My journey into full pfSense nirvana continues. 😇

                            1 Reply Last reply Reply Quote 1
                            45 out of 45
                            • First post
                              45/45
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received