• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenSSL not loading full SafeXcel capabilities.

Scheduled Pinned Locked Moved Hardware
35 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    stephenw10 Netgate Administrator
    last edited by Mar 17, 2025, 2:11 AM

    Not yet. I was away this weekend.

    J 3 Replies Last reply Mar 21, 2025, 9:41 PM Reply Quote 1
    • J
      JonathanLee @stephenw10
      last edited by Mar 21, 2025, 9:41 PM

      @stephenw10 I think it has to do with fstab use or .eli for swap, but even if I turned off .eli it still does not work.

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • J
        JonathanLee @stephenw10
        last edited by Mar 27, 2025, 1:52 PM

        @stephenw10 Any word, if you need a copy of my config that is no problem.

        Make sure to upvote

        1 Reply Last reply Reply Quote 0
        • J
          JonathanLee @stephenw10
          last edited by JonathanLee Apr 1, 2025, 9:55 PM Apr 1, 2025, 9:55 PM

          @stephenw10 I just wanted to follow up on this. I was able to get SafeXcel to increment with use of setting Squid proxy to use the sslengine as devcrypto. Don’t know if that helps

          Make sure to upvote

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Apr 1, 2025, 9:59 PM

            Hmm, interesting so you see interrupts there but not when calling it via openssl-speed?

            J 1 Reply Last reply Apr 2, 2025, 4:45 PM Reply Quote 0
            • J
              JonathanLee @stephenw10
              last edited by JonathanLee Apr 2, 2025, 4:46 PM Apr 2, 2025, 4:45 PM

              @stephenw10 yes, I can see interrupts when using squid’s ssl engine directive when doing ssl intercept, but when the OpenVPN use it will not increment. I keep thinking it is because I use .Eli in the fstab file for the swap encryption, but if that was the case why does it increment when I use .Eli and squid’s ssl engine directive? Weird right ? And it does improve performance with the certificate stuff.

              Squid custom option.
              ssl_engine devcrypto

              Make sure to upvote

              G 1 Reply Last reply Apr 3, 2025, 8:19 AM Reply Quote 1
              • G
                Gertjan @JonathanLee
                last edited by Apr 3, 2025, 8:19 AM

                @JonathanLee said in OpenSSL not loading full SafeXcel capabilities.:

                I can see interrupts when using squid’s ssl engine directive when doing ssl intercept, but when the OpenVPN use it will not increment.

                Seems normal and understandable to me.
                The OpenVPN app connects only to the OpenVPN server, and the connection is created if authentication worked out fine.
                I don't see the MITM (pfSense) doing that : emulating and OpenVPN server authentication so it can intercept.

                And its a waste of time trying to decrypt a OpenVPN stream, OpenVPN can't be 'MITMed', not with the hardware that exist in 2025.
                Maybe the quantum pfSense version in the future ? 😊

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Apr 3, 2025, 12:54 PM

                  No it's when using pfSense as an OpenVPN server or client with an encryption algorithm that safeXcel supports. Or at least should support.

                  G 1 Reply Last reply Apr 3, 2025, 1:02 PM Reply Quote 0
                  • G
                    Gertjan @stephenw10
                    last edited by Apr 3, 2025, 1:02 PM

                    @stephenw10

                    Ah, overlooked that.
                    I thought, while reading : an OpenVPN connection flowing through pfSense that does Squid stuff ...

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    J 1 Reply Last reply Apr 3, 2025, 8:54 PM Reply Quote 1
                    • J
                      JonathanLee @Gertjan
                      last edited by Apr 3, 2025, 8:54 PM

                      @Gertjan I am attempting to offload the encryption to the SafeXcel chip, I have had it running in the past with OpenVPN again I am also testing use of it with squid and my swap partition, but of those cause the interrupts to be incremented, but all the sudden OpenVPN will not use the SafeXcel chip anymore and it did with this version a couple months ago. Something is different as it should utilize it like it did in the past. I originally thought it could only be used by one component, that could be fstab file and use of .eli to encrypt the swap and or using it with squid for acceleration of ssl certificates, but they both work, all the sudden OpenVPN won’t increment the counters anymore. It’s weird because from what I am told OpenVPN should do this automatically, the new versions of software remove use of hardware crypto and OpenVPN but I can’t even run tests it acts like the chip does not load. That’s where it has confusion it should still see the counters increment in the system but it does not. It does drastically improve performance with the “ssl engine” directive in squid. Again not many people use .eli at the end of the swap config in fstab. So it’s kind of a trial and error thing. Goal faster vpn access to my private NAS.

                      Make sure to upvote

                      1 Reply Last reply Reply Quote 0
                      35 out of 35
                      • First post
                        35/35
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received