Hi Martin,
In my setup I used AES-128 encryption with pre-shared key based
authentication.
On the following hashed mark point, can you please give me a bit more
detail about how should we make the following into effect i,e enabling
AES-NI or AES-GCM? Should we do it using ipsec.conf config files or we
need something else?
##
AES-NI is quite powerful and should allow you to increase your
throughput. However, running AES in GCM mode is preferable, as using a
traditional HMAC integrity function could become the bottleneck
otherwise.
##
Thanks,
Shahreen
Shahreen Noor Ahmed
Network Support Department
Adax Europe Ltd
url: www.adax.com
e-mail: [email protected]
Direct line: +44(0)118 952 2804
On 02/07/2014 10:56, Martin Willi wrote:
Hi,
By stressing with traffic it seems I can achieve maximum 43% line rate
for larger Pkt size (1400b) and only 28% line rate for smaller packet
size (256b).
Looking at the top output it seems that only 1 core is occupied and
reaches to 100% of consumption.
This is what to expect, and has been discussed a few times, for example
at [1].
Regards
Martin
[1]https://www.mail-archive.com/[email protected]/msg07386.html
_______________________________________________
Users mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/users