Best practise IKEv2 IPsec pfSense to Windows client with NEtgate 6100
-
What's best practise to connect a Windows client to pfSense 23.05.1 for best performance and security while using QAT crypto. I'm running AES256CGM with SHA256 and DH14 but single downstream is ranging between 50-100 MBit/s (capable of 300 MBit/s). Upstream (from Windows client to pfSense) is bit better with 120-150 MBit/s.
-
@mrsunfire When using QAT there is very very little difference between the ciphers for mobile clients (which ususally has a bit of latency). Your settings are fine and very secure - you will not see noticable better throughput on other ciphers. Perhaps a little ekstra if you attempt to maximise throughput with 10 iPerf3 sessions, but for real world use - no difference.