<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Problem with SafeNet SafeXcel-1141]]></title><description><![CDATA[<p dir="auto">I installed pfSense 2.0.1 on two WatchGuard x-core (x700 and x1000)<br />
pfSense seems to have recognized the hardware crypto on board (SafeNet SafeXcel-1141)<br />
I created a ipsec vpn on seemingly without problems</p>
<p dir="auto">I would like to use the hardware crypto in this boxes</p>
<p dir="auto">in the first attempt I configured the encryption algorithm for both phase 1 and phase 2 for 3des and SHA1 hashing algorithm. the vpn almost always worked, unfortunately sometimes they go down and to either of the firebox (the x700) hung. only solution forced reboot via physical switch.</p>
<p dir="auto">second attempt: AES 254bit in phase 1 and phase 2: the fastest up the vpn, but after a few minutes of use it froze the other firebox (x1000) and vpn down</p>
<p dir="auto">third attempt: blowfish in phase 1 and phase 2: everything is OK …. at least so far.</p>
<p dir="auto">NB SafeNet SafeXcel-1141 does not support the blowfish algorithm, so I guess that pfSense does not use crypto hardware with the blowfish algorithm.</p>
<p dir="auto">I think pfSense 2.0.1 version not interface well with SafeNet SafeXcel-1141.</p>
]]></description><link>https://forum.netgate.com/topic/41802/problem-with-safenet-safexcel-1141</link><generator>RSS for Node</generator><lastBuildDate>Tue, 14 Apr 2026 08:36:14 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/41802.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 08 Feb 2012 14:26:52 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 15 Feb 2012 22:24:44 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jimp">@<bdi>jimp</bdi></a>:</p>
<blockquote>
<p dir="auto">http://redmine.pfsense.org/issues/2196</p>
</blockquote>
<p dir="auto">TY!</p>
]]></description><link>https://forum.netgate.com/post/320573</link><guid isPermaLink="true">https://forum.netgate.com/post/320573</guid><dc:creator><![CDATA[mwp]]></dc:creator><pubDate>Wed, 15 Feb 2012 22:24:44 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 15 Feb 2012 22:11:06 GMT]]></title><description><![CDATA[<p dir="auto">http://redmine.pfsense.org/issues/2196</p>
]]></description><link>https://forum.netgate.com/post/320570</link><guid isPermaLink="true">https://forum.netgate.com/post/320570</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 15 Feb 2012 22:11:06 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 15 Feb 2012 22:01:54 GMT]]></title><description><![CDATA[<p dir="auto">I'm sure there must be a way of disabling it within the crypto framework but I'm not sufficiently familiar with it.</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/320563</link><guid isPermaLink="true">https://forum.netgate.com/post/320563</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 15 Feb 2012 22:01:54 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 15 Feb 2012 21:29:10 GMT]]></title><description><![CDATA[<p dir="auto">Same issues here.. Threw me off a little as everything worked fine in monowall.<br />
Decided to install PF on the X1000 and BAM no more ipsec (well it works it just wont pass traffic).</p>
<p dir="auto">I did notice that the crypto card is showing active on the dashboard (it was not being used in monowall!)</p>
<p dir="auto">So I guess the solution here is to just pop the card out?<br />
Is there a way to disable it in the webUI or via shell?</p>
]]></description><link>https://forum.netgate.com/post/320555</link><guid isPermaLink="true">https://forum.netgate.com/post/320555</guid><dc:creator><![CDATA[mwp]]></dc:creator><pubDate>Wed, 15 Feb 2012 21:29:10 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 08 Feb 2012 19:38:04 GMT]]></title><description><![CDATA[<p dir="auto">In fact blowfish appears to be the <a href="http://forum.pfsense.org/index.php/topic,27780.msg144750.html#msg144750" target="_blank" rel="noopener noreferrer nofollow ugc">fastest encryption</a> choice. Don't know how secure it is or how well supported it may be by the other end of your connection.</p>
<p dir="auto">Is it not possible to disable encryption offloading?</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/319335</link><guid isPermaLink="true">https://forum.netgate.com/post/319335</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 08 Feb 2012 19:38:04 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 08 Feb 2012 18:05:23 GMT]]></title><description><![CDATA[<p dir="auto">What would you recommend the immediate?<br />
use the Blowfish encryption algorithm, or physically uninstall the Hardware crypto card and then use the encryption algorithm AES?</p>
]]></description><link>https://forum.netgate.com/post/319316</link><guid isPermaLink="true">https://forum.netgate.com/post/319316</guid><dc:creator><![CDATA[romapao]]></dc:creator><pubDate>Wed, 08 Feb 2012 18:05:23 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 08 Feb 2012 15:08:09 GMT]]></title><description><![CDATA[<p dir="auto">It appears as thought the SafeXel 1141 should be fully supported by the safe(4) driver and it looks as though it is from the dmesg output on a Firebox X-Core. However, if you read through the X-Core thread, I don't think anyone has ever successfully setup a VPN using it. Indeed from memory some testing showed that, although it appeared to be in use, it didn't have any result on the VPN throughput.  :(</p>
<p dir="auto">Steve</p>
]]></description><link>https://forum.netgate.com/post/319276</link><guid isPermaLink="true">https://forum.netgate.com/post/319276</guid><dc:creator><![CDATA[stephenw10]]></dc:creator><pubDate>Wed, 08 Feb 2012 15:08:09 GMT</pubDate></item><item><title><![CDATA[Reply to Problem with SafeNet SafeXcel-1141 on Wed, 08 Feb 2012 14:29:36 GMT]]></title><description><![CDATA[<p dir="auto">We are at the mercy of FreeBSD there. If there is a problem, it's with FreeBSD's drivers for that chip.</p>
<p dir="auto">What does the crypto card show up as in the boot log? (/var/log/dmesg.boot)</p>
]]></description><link>https://forum.netgate.com/post/319267</link><guid isPermaLink="true">https://forum.netgate.com/post/319267</guid><dc:creator><![CDATA[jimp]]></dc:creator><pubDate>Wed, 08 Feb 2012 14:29:36 GMT</pubDate></item></channel></rss>