Bug #15149
closedHardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
0%
Description
The Hardware Crypto is no longer showing up under OpenVPN configuration. My Netgate appliance has a crypto chip installed from Negate it no longer is being listing for OpenVPN use
Files
Updated by Jonathan Lee 11 months ago
New firmware was installed also same issue
Updated by Jim Pingle 11 months ago
- Status changed from New to Not a Bug
The OpenVPN crypto hardware choice is not relevant and hasn't done anything meaningful in years. It should probably be removed.
If the dashboard shows it's present/active, it will be used when possible (e.g. with OpenVPN+DCO)
Updated by Jonathan Lee 11 months ago
Is there anything I can do because I have the older 2100 that has this chip, I understand the new 2100 does not come with one. It can still be useful correct if it is enabled? I am using DOC and have it active in the system. It did function or appeared to on 23.05.01. I just hate to see that chip not be used when it’s on an official Netgate appliance. I noticed the rack equipment and others use a crypt chip or card. Is this a version thing? I remember the you were working on the SMID commands a while back. If you need anything tested I have a system that is set up to use it.
Updated by Jim Pingle 11 months ago
If it's shown on the dashboard as active, and there is kernel encryption happening on the VPN (e.g. OpenVPN DCO, IPsec, WireGuard) and it's using one of the ciphers listed on the dashboard, then it would be used by the kernel automatically. You do not need to do anything extra.
You have both IPsec-MB and The crypto chip active so it's going to use whichever of those two methods supports the algorithm chosen for the VPN.
Updated by Jonathan Lee 11 months ago
- File 1704769488892-screenshot-2024-01-08-at-6.57.28-pm.png 1704769488892-screenshot-2024-01-08-at-6.57.28-pm.png added
@Jim Pingle
dco_update_peer_stat: invalid peer ID 0 returned by kernel
shows when using the crypto chip it's not getting to that ID..
It should go automatically it never showed this in 23.05.01
Please see attached the chip is not being used in my 2100 that was purchased with acceleration.
Updated by Jonathan Lee 11 months ago
25.05.01 It has no issues with that ID