Re: ipsec hardware recommendation

2023-09-14 Thread Marko Cupać
Hi, thank you for suggestions, took me some time to think about them and reply here. On Fri, 11 Aug 2023 14:19:44 - (UTC) Stuart Henderson wrote: > If you post your IPsec configuration, perhaps someone can suggest > whether the choice of ciphers etc could be improved. It can make > quite a

Re: ipsec hardware recommendation

2023-08-11 Thread David Gwynne
> On 11 Aug 2023, at 21:08, Marko Cupać wrote: > > Hi, > > I have star topology network where dozens of spokes communicate with > other spokes through central hub over GRE tunnels protected with > transport-mode ipsec. > > This worked great for years, but lately all the locations got

Re: ipsec hardware recommendation

2023-08-11 Thread Stuart Henderson
On 2023-08-11, Marko Cupać wrote: > Hi, > > I have star topology network where dozens of spokes communicate with > other spokes through central hub over GRE tunnels protected with > transport-mode ipsec. > > This worked great for years, but lately all the locations got bandwidth > upgrade

Re: ipsec hardware recommendation

2023-08-11 Thread Matthew Ernisse
On Fri, Aug 11, 2023 at 01:08:07PM +0200, Marko Cupać said: Are there any commands I can run which would indicate ipsec traffic is being throttled due to hardware being underspecced? top shows CPU is more than 50% idle. netstat shows ~1 Ierrs / Ifail (no Oerrs / Ifail) on interfaces that

ipsec hardware recommendation

2023-08-11 Thread Marko Cupać
Hi, I have star topology network where dozens of spokes communicate with other spokes through central hub over GRE tunnels protected with transport-mode ipsec. This worked great for years, but lately all the locations got bandwidth upgrade (spokes: 10Mbit -> 50Mbit, hub: 2x200Mbit -> 2x500Mbit),