Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Hardware Crypto device.

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    6 Posts 4 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      David Handelman
      last edited by

      HI All,
      The 2.0 is rocks, I decided to upgrade my vpn throughput.
      I have two Broadcom BCM5825 that has no driver in 1.2X version,
      So I decided to try the 2.0 Beta 4, which has the driver for this card.
      The two Pfsenses are connected with 1Gb circuit and I'm unable to cross the 250Mb, I'm using AES-256 which supported by the card.
      How can I verify that the hardware crypto is used? I have read that in 1.2X version it was written under the platform.

      Many Thanks
      David,

      1 Reply Last reply Reply Quote 0
      • J
        jasonlitka
        last edited by

        I've not used 2.0 yet with HW crypto, but it takes a lot of CPU power for 1 Gbit/s.  What kind of hardware are you using (CPUs, RAM, NICs)?

        I can break anything.

        1 Reply Last reply Reply Quote 0
        • D
          David Handelman
          last edited by

          I'm using an old hardware intel 5100 Server dual quad core xeon 1.6Ghs with 16Gb of ram with Intel NICS.
          Without encryption I can transfer easily 700Mb, but with IPSEC I need more power and I hope to get it from the crypto card,
          Thanks
          David,

          1 Reply Last reply Reply Quote 0
          • dotdashD
            dotdash
            last edited by

            I'm not familiar with what the hardware is supposed to push, but often times modern CPUs can do a better job in software. Also, check out the man page:
            @FreeBSD:

            Broadcom BCM5823  A BCM5822 with AES capability.
              Broadcom BCM5825  Faster version of the BCM5823.

            BUGS
                The BCM5801 and BCM5802 have not actually been tested.  The AES capabil-
                ity of the BCM5823 is not yet supported; it is awaiting public disclosure
                of programming information from Broadcom.

            1 Reply Last reply Reply Quote 0
            • D
              David Handelman
              last edited by

              Thank You,
              So I should be able use 3DES or DES with it? Is there any simple test I can do like openssl speed to make sure?

              Thanks Again,,

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                Does the driver show up in dmesg?

                We have to add code to show the crypto devices in the dashboard, and I'm not sure we've seen one of those yet.

                You can try some of the openssl tests shown here:
                http://doc.pfsense.org/index.php/Are_cryptographic_accelerators_supported

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.