Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    pfsense plus - crypto Accelerator Wireguard / OpenVPN / IPsec

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 3 Posters 299 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mikey_s
      last edited by

      I have an Atom system that has QAT extension (Intel Atom C3558) I've just acquired a Sophos XG330 Rev2 and it's go 10Gb SFP+ interfaces.

      The CPU in the system is an Intel i5-6500, which will support AES and IIMB. If I recall QAT doesn't accelerate Wireguard?

      I have Wireguard for mobiles, OpenVPN with DCO for a laptop and IPSec for S2S with Unifi devices (Unifi terrible for VPN speeds)....

      I have a travel router too that is also configured for Wireguard and OpenVPN based on what restrictions might be in place.

      stephenw10S 1 Reply Last reply Reply Quote 0
      • stephenw10S Offline
        stephenw10 Netgate Administrator @mikey_s
        last edited by

        @mikey_s said in pfsense plus - crypto Accelerator Wireguard / OpenVPN / IPsec:

        If I recall QAT doesn't accelerate Wireguard?

        That's correct. For the QAT in C3K (1.7) at least it doesn't support ChaCha-Poly used by Wireguard. Later QAT versions an though. If the FreeBSD driver supports them.

        tinfoilmattT M 2 Replies Last reply Reply Quote 1
        • tinfoilmattT Offline
          tinfoilmatt LAYER 8 @stephenw10
          last edited by

          If the FreeBSD driver supports them.

          We see what you did there.

          stephenw10S 1 Reply Last reply Reply Quote 0
          • M Offline
            mikey_s @stephenw10
            last edited by

            @stephenw10

            Ok many thanks, I moved the plus license to the XG330 Rev2. Hopefully I didn’t make the wrong decision.

            Just looking at Skylake CPUs with a view of swapping out the i5-6500. Looking at the t range with high clock speed. T range have on TDP values.

            1 Reply Last reply Reply Quote 0
            • stephenw10S Offline
              stephenw10 Netgate Administrator @tinfoilmatt
              last edited by

              @tinfoilmatt said in pfsense plus - crypto Accelerator Wireguard / OpenVPN / IPsec:

              If the FreeBSD driver supports them.
              

              We see what you did there.

              Well there are some newer CPUs with QAT that are not yet supported at all by the driver shipped in pfSense. So YMMV!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.