From owner-freebsd-net@freebsd.org Thu Aug 9 05:37:54 2018 Return-Path: Delivered-To: freebsd-net@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id CECD81055F7B for ; Thu, 9 Aug 2018 05:37:54 +0000 (UTC) (envelope-from bu7cher@yandex.ru) Received: from forward105p.mail.yandex.net (forward105p.mail.yandex.net [IPv6:2a02:6b8:0:1472:2741:0:8b7:108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "forwards.mail.yandex.net", Issuer "Yandex CA" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4A85A8150C for ; Thu, 9 Aug 2018 05:37:53 +0000 (UTC) (envelope-from bu7cher@yandex.ru) Received: from mxback6j.mail.yandex.net (mxback6j.mail.yandex.net [IPv6:2a02:6b8:0:1619::10f]) by forward105p.mail.yandex.net (Yandex) with ESMTP id 770974084DA4; Thu, 9 Aug 2018 08:37:51 +0300 (MSK) Received: from smtp1j.mail.yandex.net (smtp1j.mail.yandex.net [2a02:6b8:0:801::ab]) by mxback6j.mail.yandex.net (nwsmtp/Yandex) with ESMTP id xLqWF7Rsc5-bpxqK3EA; Thu, 09 Aug 2018 08:37:51 +0300 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yandex.ru; s=mail; t=1533793071; bh=An6PvTyqVq2R5vHFsd3Z44+8Yz6Sk9jsF9VcqbUbHSA=; h=Subject:To:References:From:Message-ID:Date:In-Reply-To; b=e7bIKm9RriRYXrZrfLLWf/i8RBFO0eSn3f2sS5kmhpSFC9IjhYqfmUEP+qZGtWKmD RlJTifpYF8wBB9jgMtBbuS04jvfpcsWqAs+jWXGPZk86Xh8RjF8ee4qC538buyt6Yp q3KOrknf3zBg8N53COAj+QHsqRt2w0bWL2/ca4ko= Received: by smtp1j.mail.yandex.net (nwsmtp/Yandex) with ESMTPSA id ClC87W4Qrk-boCqStO6; Thu, 09 Aug 2018 08:37:50 +0300 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client certificate not present) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yandex.ru; s=mail; t=1533793070; bh=An6PvTyqVq2R5vHFsd3Z44+8Yz6Sk9jsF9VcqbUbHSA=; h=Subject:To:References:From:Message-ID:Date:In-Reply-To; b=R/Pj/ArAwQcOKibmHZfamEgevul28WSZQKNbqztav5M2+LDaBCnjH50ncZ5u6P3vN vwRmE9lyn0g06ky0CxeJ3uHgXkX+60bQqfujaXLIqvSQpuVW+BjyB++vq10LVb1rHZ hWAnDFB+KatjgWt7+St/30qnT/pij91RVgHa6ots= Authentication-Results: smtp1j.mail.yandex.net; dkim=pass header.i=@yandex.ru Subject: Re: Is if_ipsec/ipsec - AESNI accelerated ? To: "David P. Discher" , freebsd-net@freebsd.org References: From: "Andrey V. Elsukov" Openpgp: id=E6591E1B41DA1516F0C9BC0001C5EA0410C8A17A Autocrypt: addr=bu7cher@yandex.ru; prefer-encrypt=mutual; keydata= xsBNBEwBF1kBCADB9sXFhBEUy8qQ4X63Y8eBatYMHGEFWN9ypS5lI3RE6qQW2EYbxNk7qUC5 21YIIS1mMFVBEfvR7J9uc7yaYgFCEb6Sce1RSO4ULN2mRKGHP3/Sl0ijZEjWHV91hY1YTHEF ZW/0GYinDf56sYpDDehaBF5wkWIo1+QK5nmj3vl0DIDCMNd7QEiWpyLVwECgLX2eOAXByT8B bCqVhJGcG6iFP7/B9Ll6uX5gb8thM9LM+ibwErDBVDGiOgvfxqidab7fdkh893IBCXa82H9N CNwnEtcgzh+BSKK5BgvPohFMgRwjti37TSxwLu63QejRGbZWSz3OK3jMOoF63tCgn7FvABEB AAHNIkFuZHJleSBWLiBFbHN1a292IDxhZUBmcmVlYnNkLm9yZz7CwHsEEwECACUCGwMGCwkI BwMCBhUIAgkKCwQWAgMBAh4BAheABQJMB/ruAhkBAAoJEAHF6gQQyKF6MLwH/3Ri/TZl9uo0 SepYWXOnxL6EaDVXDA+dLb1eLKC4PRBBjX29ttQ0KaWapiE6y5/AfzOPmRtHLrHYHjd/aiHX GMLHcYRXD+5GvdkK8iMALrZ28X0JXyuuZa8rAxWIWmCbYHNSBy2unqWgTI04Erodk90IALgM 9JeHN9sFqTM6zalrMnTzlcmel4kcjT3lyYw3vOKgoYLtsLhKZSbJoVVVlvRlGBpHFJI5AoYJ SyfXoN0rcX6k9X7Isp2K50YjqxV4v78xluh1puhwZyC0p8IShPrmrp9Oy9JkMX90o6UAXdGU KfdExJuGJfUZOFBTtNIMNIAKfMTjhpRhxONIr0emxxDOwE0ETAEXWQEIAJ2p6l9LBoqdH/0J PEFDY2t2gTvAuzz+8zs3R03dFuHcNbOwjvWCG0aOmVpAzkRa8egn5JB4sZaFUtKPYJEQ1Iu+ LUBwgvtXf4vWpzC67zs2dDuiW4LamH5p6xkTD61aHR7mCB3bg2TUjrDWn2Jt44cvoYxj3dz4 S49U1rc9ZPgD5axCNv45j72tggWlZvpefThP7xT1OlNTUqye2gAwQravXpZkl5JG4eOqJVIU X316iE3qso0iXRUtO7OseBf0PiVmk+wCahdreHOeOxK5jMhYkPKVn7z1sZiB7W2H2TojbmcK HZC22sz7Z/H36Lhg1+/RCnGzdEcjGc8oFHXHCxUAEQEAAcLAXwQYAQIACQUCTAEXWQIbDAAK CRABxeoEEMihegkYCAC3ivGYNe2taNm/4Nx5GPdzuaAJGKWksV+w9mo7dQvU+NmI2az5w8vw 98OmX7G0OV9snxMW+6cyNqBrVFTu33VVNzz9pnqNCHxGvj5dL5ltP160JV2zw2bUwJBYsgYQ WfyJJIM7l3gv5ZS3DGqaGIm9gOK1ANxfrR5PgPzvI9VxDhlr2juEVMZYAqPLEJe+SSxbwLoz BcFCNdDAyXcaAzXsx/E02YWm1hIWNRxanAe7Vlg7OL+gvLpdtrYCMg28PNqKNyrQ87LQ49O9 50IIZDOtNFeR0FGucjcLPdS9PiEqCoH7/waJxWp6ydJ+g4OYRBYNM0EmMgy1N85JJrV1mi5i Message-ID: Date: Thu, 9 Aug 2018 08:37:04 +0300 User-Agent: Mozilla/5.0 (X11; FreeBSD amd64; rv:52.0) Gecko/20100101 Thunderbird/52.9.1 MIME-Version: 1.0 In-Reply-To: Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="Uf2Hhj2k6cBpKr8PtEMawmb8aBllDHAAG" X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.27 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 09 Aug 2018 05:37:55 -0000 This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --Uf2Hhj2k6cBpKr8PtEMawmb8aBllDHAAG Content-Type: multipart/mixed; boundary="eLsGDHc7TdApySAvFeZAV7FG48CkFICad"; protected-headers="v1" From: "Andrey V. Elsukov" To: "David P. Discher" , freebsd-net@freebsd.org Message-ID: Subject: Re: Is if_ipsec/ipsec - AESNI accelerated ? References: In-Reply-To: --eLsGDHc7TdApySAvFeZAV7FG48CkFICad Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: quoted-printable On 09.08.2018 06:57, David P. Discher wrote: > I=E2=80=99m suspecting that IPSec in FreeBSD is not leveraging AESNI on= Intel. Is this correct ? IPsec uses crypto(9) framework that works by default without any acceleration. You need to load aesni(4) kernel module to enable acceleration. Also, you need to recreate security associations after module loading to take effect. --=20 WBR, Andrey V. Elsukov --eLsGDHc7TdApySAvFeZAV7FG48CkFICad-- --Uf2Hhj2k6cBpKr8PtEMawmb8aBllDHAAG Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Comment: Using GnuPG with Thunderbird - https://www.enigmail.net/ iQEzBAEBCAAdFiEE5lkeG0HaFRbwybwAAcXqBBDIoXoFAltr0wAACgkQAcXqBBDI oXp/bgf8D3YGjRMylF0OfpgfQPSZDbfR7VS7pe0fdeqgXIiqZa1jwqPBr3bPGbrR JQLWTHpWLE1NRsCZT5qRSIKwBeqggLpiDDWmK6YGf4jqHqs3X8RMQFi+eK/L+dUV XR+IShei/yOGJDwBNzk+3bLa2FWyyQDkG05rqva500gaSX3I/OBmHM0EVQ+e4hYp 0zF11UraSouM3H2sXgu2k9eL/QrvjOF3ytbN0hjnqhgJD3ulhh0JhHxVjg6TVVAC xSFPWHCLwez1IsGrYvMIhjIRBMBFQ1XeZRXjOkWSthjtzBU5MLGK4S7iIHZRi7qh Qa/KopyWh7LzkfU591vBLLMb8X59Pw== =C0+G -----END PGP SIGNATURE----- --Uf2Hhj2k6cBpKr8PtEMawmb8aBllDHAAG--