• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

OpenVPN: engine cryptodev?

Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
4 Posts 3 Posters 4.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    cyboc
    last edited by Dec 17, 2010, 11:17 PM

    Hi,

    According to the page Are cryptographic accelerators supported, you are supposed to put "engine cryptodev" in the advanced configuration section of your OpenVPN configuration if you want to take advantage of the AMD Geode LX Security Block on the Alix for doing AES-128-CBC crypto in hardware.

    Is this "engine cryptodev" setting still required in pfSense 2 or is it sufficient just to check the "Use glxsb" checkbox on the System | Advanced | Miscellaneous page (in addition to choosing AES-128-CBC in the OpenVPN config)?

    1 Reply Last reply Reply Quote 0
    • C
      cyboc
      last edited by Dec 17, 2010, 11:40 PM

      It seems like "engine cryptodev" is still required. With it enabled, I see "openvpn[4600]: Initializing OpenSSL support for engine 'cryptodev'" in the OpenVPN log upon startup of the OpenVPN server. Without "engine cryptodev", I do NOT see that log entry.

      1 Reply Last reply Reply Quote 0
      • C
        cmb
        last edited by Dec 18, 2010, 3:40 AM

        That checkbox only affects loading of the driver, to make OpenVPN use it you have to specify it.

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Dec 20, 2010, 4:46 PM

          I added a ticket to remind us to add a checkbox on the openvpn config pages to add this to the config in future versions:

          http://redmine.pfsense.org/issues/1120

          Even if someone has crypto hardware they may want to disable its use for testing/comparison (People often install an older accelerator card in fast hardware only to find out it's actually slower than using the CPU directly.)

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          1 out of 4
          • First post
            1/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received