OpenVPN on OpenBSD with hw crypto acceleration

2006-04-12 Thread Marek Nixworx
Hi, I have an OpenVPN server interconnecting 5 networks with data center using permanent PtP links - each network has about 30 PCs. Also there is about 30 road-warrior OpenVPN clients. Average traffic on each PtP link is 1-2Mbit/s. The server and end-points of permanent PtP links are currently

Re: OpenVPN on OpenBSD with hw crypto acceleration

2006-04-12 Thread Marek Nixworx
Thank you, can you explain me please, why aren't PCI/miniPCI cards sufficient ? I'd like to use same hardware and only add PCI card on server and end-points.. Thanx Marek 2006/4/12, Stuart Henderson [EMAIL PROTECTED]: On 2006/04/12 11:27, Marek Nixworx wrote: I've read about OpenBSD's

Re: OpenVPN on OpenBSD with hw crypto acceleration

2006-04-12 Thread Siegbert Marschall
Hi, I have an OpenVPN server interconnecting 5 networks with data center using permanent PtP links - each network has about 30 PCs. Also there is about 30 road-warrior OpenVPN clients. Average traffic on each PtP link is 1-2Mbit/s. The server and end-points of permanent PtP links are

Re: OpenVPN on OpenBSD with hw crypto acceleration

2006-04-12 Thread Stuart Henderson
On 2006/04/12 11:57, Marek Nixworx wrote: can you explain me please, why aren't PCI/miniPCI cards sufficient ? I'd like to use same hardware and only add PCI card on server and end-points.. There's a lot more overhead involved with the PCI cards which are serviced by interrupt-handlers (rather

Re: OpenVPN on OpenBSD with hw crypto acceleration

2006-04-12 Thread Marek Nixworx
End-points are running on ibase's network security appliance hardware: http://www.ibasetechnology.net/EN/fwa7204.html - the only way to put some hw accel to this is miniPCI - that's why I've asked about it before.. The central server is some Fujitsu-Siemens server with free PCI slot You

Re: OpenVPN on OpenBSD with hw crypto acceleration

2006-04-12 Thread Stuart Henderson
On 2006/04/12 15:30, Marek Nixworx wrote: End-points are running on ibase's network security appliance hardware: http://www.ibasetechnology.net/EN/fwa7204.html More powerful than Geode-based boards then - you probably need to try it for yourself on the hardware with your packet mix, then, and