> >> I bought a Soekris Net5501 with a cryptographic card VPN1411 > >> (Authentication, SHA-1 and MD5, Public Key, RSA, DSA, SSL, IKE and DH, > >> Hardware random number generator) and I would like to know if any > >> configuration is needed in OpenBSD kernel to use this card when > >> cryptography is necessary. > >> > >> eg. When a VPN IPSec is done. > > > > You might want to check that it's not actually slower when you use the card. > > > > > > Some basic benchmarking would be appreciated, for the sake of the > list. As a newcomer I am really interested in understanding the > cryptohardware framework. > > I would have never said accelerated hardware could perform any worse. > Interesting point Stuart.
Of course it can perform worse, in the wrong situation. The cards are very fast, but they require 'setup' to do each operation. It's is like getting in to your car to go buy something at the store right next to your house. Do a small enough operation, and the 'overhead' becomes unbearable.

