Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    23.09.01 Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed

    Scheduled Pinned Locked Moved OpenVPN
    41 Posts 6 Posters 5.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by

      Hello fellow Netgate community members can you please help[?

      My Hardware Crypto is no longer showing up under OpenVPN configuration. My Netgate appliance was purchased with a crypto chip installed direct from Negate and it is no longer is being listing for OpenVPN use.

      Should I open a TAC ticket??? I just completed firmware reinstall and it's not listed

      Path --->23.05.01 new firmware -----> direct to update ----> loss of crypto acceleration.

      I show my chip on the menu however OpenVPN can't see it
      Screenshot 2024-01-08 at 5.28.16 PM.png

      Screenshot 2024-01-08 at 5.22.57 PM.png

      Make sure to upvote

      S 1 Reply Last reply Reply Quote 1
      • JonathanLeeJ
        JonathanLee
        last edited by

        Does anyone else that uses this chip have this issue? Even with other models??? This system isn't even 3 years old

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @JonathanLee
          last edited by

          @JonathanLee said in 23.09.01 Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed:

          My Hardware Crypto is no longer showing up under OpenVPN configuration.

          What do you mean by this?

          OpenVPN uses hardware if it sees it : https://docs.netgate.com/pfsense/en/latest/hardware/cryptographic-accelerators.html#openvpn

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          JonathanLeeJ 3 Replies Last reply Reply Quote 0
          • JonathanLeeJ
            JonathanLee @SteveITS
            last edited by

            @SteveITS

            Thanks for the reply,

            To provide clarity that was on 23.05.01

            On 23.09.01 it does not see it now

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • JonathanLeeJ
              JonathanLee @SteveITS
              last edited by

              @SteveITS said in 23.09.01 Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed:

              ttps://docs.netgate.com/pfsense/en/latest/hardware/cryptographic-accelerators.html#openvpn

              Screenshot 2024-01-08 at 6.09.46 PM.png

              I do have it active

              Make sure to upvote

              1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee @SteveITS
                last edited by

                @SteveITS should it still list it? Under 23.05.01 it would show the chip to select and use. Now it’s not listed

                Make sure to upvote

                S 1 Reply Last reply Reply Quote 0
                • S
                  SteveITS Galactic Empire @JonathanLee
                  last edited by

                  @JonathanLee I'm not clear what "it" is in your question?

                  a 2100 on 23.05.1:
                  Hardware crypto AES-CBC,AES-CCM,AES-GCM,AES-ICM,AES-XTS,SHA1,SHA256,SHA384,SHA512

                  a 2100 on 23.09.1:
                  Hardware crypto AES-CBC, AES-CCM, AES-GCM, AES-ICM, AES-XTS, ChaCha20-Poly1305, SHA1, SHA256, SHA384, SHA512

                  If you're talking about the Hardware Crypto dropdown in the OpenVPN settings I think it basically ignores that anyway?

                  https://docs.netgate.com/pfsense/en/latest/vpn/openvpn/configure-server-crypto.html#hardware-crypto
                  "If available, this option controls which hardware cryptographic accelerator will be used by OpenVPN. When left unspecified, OpenVPN will choose automatically based on what is available in the operating system to accelerate ciphers OpenVPN wants to use.

                  Some hardware acceleration, such as AES-NI, happens automatically in OpenVPN via OpenSSL and cannot be enabled or disabled by this option.

                  Note
                  In most common deployments this setting is unnecessary as the automatic behavior of OpenVPN is correct."

                  Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                  When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                  Upvote 👍 helpful posts!

                  JonathanLeeJ 2 Replies Last reply Reply Quote 1
                  • JonathanLeeJ
                    JonathanLee @SteveITS
                    last edited by

                    @SteveITS cool cool, maybe I was expecting fireworks or blinking leds or something, so I changed the firewall leds to be purple when the VPN state establishes, it helps me know when to not mess with it.

                    Thanks for the reply

                    Make sure to upvote

                    1 Reply Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @SteveITS
                      last edited by JonathanLee

                      @SteveITS the device id shows error in 23.09.01 and it didn’t in 23.05.01

                      IMG_0053.png

                      Make sure to upvote

                      1 Reply Last reply Reply Quote 0
                      • JonathanLeeJ JonathanLee referenced this topic on
                      • JonathanLeeJ
                        JonathanLee
                        last edited by JonathanLee

                        In 23.09.01

                        295a3eae-21bb-41ed-bbf0-c702dd20098f-image.png

                        e43cf1de-9060-41a3-98b3-4aaf2027d51c-image.png

                        ae8597c5-68d4-4b9f-bc2f-d95e671c68bd-image.png

                        150e275b-0b62-444f-a95f-c55f1c42681e-image.png

                        d5d06d15-b76f-4cff-a14a-df52200faf0d-image.png

                        Make sure to upvote

                        1 Reply Last reply Reply Quote 0
                        • JonathanLeeJ
                          JonathanLee
                          last edited by

                          62c9aa3a-9326-4a8b-a84b-533331151a5f-image.png

                          It shows nothing for me, with

                          DOC enabled or disabled
                          encryption with removed chacha and enabled chacha
                          IPsec-MB enabled or disabled

                          23.09.01 I can't get it to run

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          • JonathanLeeJ
                            JonathanLee
                            last edited by

                            In 23.05.01:

                            0b5a9c75-8b38-44e3-af18-5565434c24f1-image.png
                            Chip working

                            2610e023-b71a-4585-965d-8d9ebe1ea631-image.png
                            Chip listed

                            93648637-8571-44ec-8b7e-9de3d548adb2-image.png

                            7d21ba8f-4a65-4650-aa82-818e31740ce4-image.png
                            Listed the chip

                            b8150d5c-53ef-4179-8d7f-dfaa2b551558-image.png
                            increments on use now shows 80

                            My device was purchased direct from Netgate and contains the chip.

                            What should I do???

                            Make sure to upvote

                            1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              OpenSSL no longer supports the BSD cryptodev device as an 'engine'. Selecting it there does nothing so it was removed.

                              SafeXcel should still be used for kernel mode crypto though so if you have DCO enabled.

                              Steve

                              JonathanLeeJ 1 Reply Last reply Reply Quote 0
                              • JonathanLeeJ
                                JonathanLee @stephenw10
                                last edited by JonathanLee

                                @stephenw10 I do have it enabled, though VM stat still shows no increments Or any status for the Chip what can be done to correct that? Thanks for the reply. Have a good day.

                                Just for clarification the new 2100s ship without a cypher chip? My version was the more expensive 2100MAX it came with a SSD and the cypher chip. Is it possible the updates repos do not know difference between the older 2100? and the new 2100s?

                                Like a hypothetical model 2100A and 2100B ????

                                If so how can I get my chip to work the speed is drastically different on VPN use with it enabled.

                                Make sure to upvote

                                1 Reply Last reply Reply Quote 0
                                • stephenw10S
                                  stephenw10 Netgate Administrator
                                  last edited by

                                  Try disabling iimb. That will try to register against many of the same ciphers.

                                  JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                  • JonathanLeeJ
                                    JonathanLee @stephenw10
                                    last edited by

                                    @stephenw10 I did that same results dang. Please let me know if you find a advanced option for customers like me.

                                    Make sure to upvote

                                    1 Reply Last reply Reply Quote 0
                                    • stephenw10S
                                      stephenw10 Netgate Administrator
                                      last edited by

                                      Do you actually see a reduction in throughput though? Or an increase in CPU usage?

                                      JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                      • JonathanLeeJ
                                        JonathanLee @stephenw10
                                        last edited by

                                        @stephenw10 yes with use on 22.05.01.

                                        Make sure to upvote

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          Like throughput is lower in 23.09.1 compared to 23.05.1?

                                          JonathanLeeJ 1 Reply Last reply Reply Quote 0
                                          • JonathanLeeJ
                                            JonathanLee @stephenw10
                                            last edited by

                                            @stephenw10 let me test again hold on I turned 23.09.01 on again.

                                            Nope it’s 130kbs with dsl on 23.09.01
                                            It’s 123kb in 23.05.01

                                            Just checked with my pdfs again.

                                            Make sure to upvote

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.