Bug #15020
closedpfSense 2.7.1 No Hardware Crypto Acceleration in OpenVPN
0%
Description
After update to pfSense 2.7.1 only "No Hardware Crypto Acceleration" available in OpenVPN on all my instances (usually Intel Xeon E5). pfSense running in VM (esxi 6.7U3).
In settings (Advanced-Miscellaneous-Cryptographic Hardware) is "AES-NI and BSD Crypto Device (aesni, cryptodev)" selected.
Dashboard says:
CPU Type Intel(R) Xeon(R) CPU E5-2670 0 @ 2.60GHz
AES-NI CPU Crypto: Yes (active)
QAT Crypto: No
Hardware crypto AES-CBC, AES-CCM, AES-GCM, AES-ICM, AES-XTS
Updated by Jim Pingle about 1 year ago
- Status changed from New to Not a Bug
The "Hardware Crypto" option hasn't done much of anything in OpenVPN in a long time. OpenVPN/OpenSSL will use what it can detect and operate automatically, there is no need to manually select anything.
Updated by I Ivanov about 1 year ago
Perhaps it is worth removing this option completely so as not to be misleading?
Even better - display OpenVPN hardware encryption usage status