Router freezes frequently for a short time

2021-12-08 Thread Joosep
ound 130K - peaks do not seem to correlate to the outages; number of pf states are in the range of 200k to 400k, well below configured limit of 1M; If anybody has any suggestions where to look for next clues, i would be grateful. Kind Regards Joosep

sha1 and md5 broken with Broadcom 5862 CA and IPSec?

2011-12-29 Thread Joosep
host0 was running 4.7 and host1 4.9. Problem occurs with SHA1 and MD5, which are both supported by CA. When using SHA2(that is not supported by CA) everything works. Problem exist with tunnel and transport mode. Any debugging hints and ideas to get sha1 working are welcome, Joosep CA in question

Re: OpenBSD ipsec gateway behind a router

2011-11-14 Thread Joosep
of signature.asc] Hi! I think the problem in your case is HMAC-SHA2 incompatibility between releases before 4.7 and 4.7(and upwards) releases. Please check this link http://www.openbsd.org/faq/upgrade47.html#hmac-sha2 regards, Joosep

Re: iked+CARP/ active,passive

2011-10-15 Thread Joosep
. Not sure about the reason for this yet. //maxim Hi! There is a patch for 4.8 and 4.9 that probably fixes your timeouts problem. Please read this thread: http://marc.info/?l=openbsd-miscm=130959664208980w=2 It's not a critical bugfix, so it's not on the errata page, but it is in the cvs. Joosep

Re: IPSEC/SSL accelerator

2011-05-18 Thread Joosep
ofcourse vary depending on packet size and other factors), wich was twice as much as without it. We used iperf with UDP protocol for testing. All the best, Joosep

Re: IPSEC/SSL accelerator

2011-05-18 Thread Joosep
the limiting factor here is main cpu not the CA card. I have done the same tests with 1,8 GHz opteron and in that case the result was around 270mbps. Joosep

Re: IPSEC/SSL accelerator

2011-05-18 Thread Joosep
Hi! ubsec0 at pci5 dev 0 function 0 Broadcom 5862 rev 0x01: 3DES MD5 SHA1 AES PK, apic 9 int 0 (irq 10) Joosep On Wed, May 18, 2011 at 8:56 PM, Maxim Bourmistrov m...@alumni.chalmers.sewrote: How does it look in dmesg for this card? Sent from my iPhone On May 18, 2011, at 10:42, Joosep

strange behaviour with amd64, 3des and crypto accelerator

2011-02-11 Thread Joosep
the best, Joosep