Re: misc/132277: poor performance using criptodevice for IPSEC



The following reply was made to PR kern/132277; it has been noted by GNATS.

From: Patrick =?ISO-8859-15?Q?Lamaizi=E8re?= <patfbsd@xxxxxxxxxxxxx>
To: bug-followup@xxxxxxxxxxx
Cc: Vasile Marii <marii.vasile@xxxxxxxxx>
Subject: Re: misc/132277: poor performance using criptodevice for IPSEC
Date: Sat, 14 Mar 2009 13:05:52 +0100

Le Sun, 8 Mar 2009 20:00:11 GMT,
Patrick Lamaizière <patfbsd@xxxxxxxxxxxxx>:

I've made some tests on IPsec with glxsb and the performances are
very bad (around 14 Mbits).

I think the problem is that glxsb handles only one request at a time.
When it is busy, it blocks the Open Crypto Framework with ERESTART
and it unblocks the OCF when the previous request is completed. Then
the OCF has to wake up and to resubmit the request. It looks like
this performs very badly when using it with IPsec.

If glxsb processes the requests synchronously it performs quite
better, around 50 Mbits.

I've filled a PR with a patch for glxb(4): kern/132622

Regards.
_______________________________________________
freebsd-net@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • IPSEC with certificates on Windows XP (Certificate donīt have a private key )
    ... I have a question for the Microsoft CSP and IPSEC. ... I have installed a small network of 4 computers. ... computers and two windows 2000 computers. ... The program certreq.exe generate a certificate request. ...
    (microsoft.public.platformsdk.security)
  • Re: Create a computer certificate for non-connected machine?
    ... >> Another option would be to use web interface ... >> your VPN configuration. ... > in the request rather than being built from ... I've added the IPSec Offline Request template into my ...
    (microsoft.public.security)
  • Re: Granting Certs to XP Clients
    ... you're requesting a certificate to be used for IPSEC. ... certificates using DSS provider for IPSEC usage. ... failures that somehow prevent the CA from even processing the request: Use: ...
    (microsoft.public.win2000.security)
  • Re: Sonicwall TZ150/170
    ... SonicWall log zum IPSec SA, ... IKE negotiation complete. ... Received Quick Mode Request ... IKE Initiator: ...
    (microsoft.public.de.german.isaserver)
  • Re: Sonicwall TZ150/170
    ... SonicWall log zum IPSec SA, ... IKE negotiation complete. ... Received Quick Mode Request ... IKE Initiator: ...
    (microsoft.public.de.german.isaserver)