Bug #15149
closed
Hardware Crypto showing No Hardware Crypto Acceleration for system with crypto chip installed
Added by Jonathan Lee 11 months ago.
Updated 11 months ago.
Affected Plus Version:
23.09.1
Affected Architecture:
SG-2100
Description
The Hardware Crypto is no longer showing up under OpenVPN configuration. My Netgate appliance has a crypto chip installed from Negate it no longer is being listing for OpenVPN use
Files
New firmware was installed also same issue
- Status changed from New to Not a Bug
The OpenVPN crypto hardware choice is not relevant and hasn't done anything meaningful in years. It should probably be removed.
If the dashboard shows it's present/active, it will be used when possible (e.g. with OpenVPN+DCO)
Is there anything I can do because I have the older 2100 that has this chip, I understand the new 2100 does not come with one. It can still be useful correct if it is enabled? I am using DOC and have it active in the system. It did function or appeared to on 23.05.01. I just hate to see that chip not be used when it’s on an official Netgate appliance. I noticed the rack equipment and others use a crypt chip or card. Is this a version thing? I remember the you were working on the SMID commands a while back. If you need anything tested I have a system that is set up to use it.
If it's shown on the dashboard as active, and there is kernel encryption happening on the VPN (e.g. OpenVPN DCO, IPsec, WireGuard) and it's using one of the ciphers listed on the dashboard, then it would be used by the kernel automatically. You do not need to do anything extra.
You have both IPsec-MB and The crypto chip active so it's going to use whichever of those two methods supports the algorithm chosen for the VPN.
@Jim Pingle
dco_update_peer_stat: invalid peer ID 0 returned by kernel
shows when using the crypto chip it's not getting to that ID..
It should go automatically it never showed this in 23.05.01
Please see attached the chip is not being used in my 2100 that was purchased with acceleration.
25.05.01 It has no issues with that ID
Also available in: Atom
PDF