[Openswan Users] [Ocf-linux-users] IPSec L2tpv3 throughput low using Netkey kernel stack

Vasanth Ragavendran ragavendrapec at gmail.com
Thu May 19 23:18:40 EDT 2011


Thank you all so much for responding.

On Wed, May 18, 2011 at 7:02 PM, David McCullough <
david_mccullough at mcafee.com> wrote:

>
> Jivin Paul Wouters lays it down ...
> > On Tue, 17 May 2011, Kim Phillips wrote:
> >
> > >>> but when the Sec driver is configured as module into the kernel the
> module doesn;t get inserted
> > >>> gives segmentation fault and if the Sec driver is configured as
> non-module type the kernel doesn't
> > >>> bootsup at all!
> > >>
> > >> David might be able to help with this. The ubsec driver is mostly used
> on linksys/asus machines,
> > >> perhaps yours is slightly different?
> > >
> > > Based on the freescale URL posted to users at openswan, I assume you're
> > > referring to the "SEC23DRVRS" driver?  That is a standalone driver,
> > > and won't be of use unless you're prepared to write code to
> > > integrate it into your IPsec stack.
> > >
>
Yeah i was mentioning about SEC23DRVRS apologies for mentioning it in short
form.
and as Paul has asked to test with a lower MTU say 1400, the thruput worsens
i get only
4.71Mbps however with MTU being 1500 i get the thruput as 14.7Mbps.

> > Known working (to me at least) IPsec offload configuration for the
> > > 8315 should be NETKEY with CONFIG_CRYPTO_DEV_TALITOS configured in
> > > a vanilla kernel.  To be able to tell whether h/w crypto offload is
> > > in operation, see 'grep talitos /proc/interrupts' run.
> >
>
As Kim had mentioned I had loaded the CONFIG_CRYPTO_DEV_TALITOS as a module
with the module in the kernel i am getting a lower throughput! I am getting
only 13.4Mbps however without the module inserted i get 14.7Mbps how could
this be possible and the results sounds really ridiculous to me! And when
the CONFIG_CRYPTO_DEV_TALITOS is loaded i am able to view it using grep
talitos /proc/interrupts. so the hardware accelerator is getting used
however resulting in a lower throughput! That's absurd am I missing
something here?

> Ah, i thought he meant the ubsec one. Talitos I believe is also supported
> with OCF and KLIPS
> > IPsec, but I'm sure David can confirm that.
>
> I tried even with KLIPS and ocf,cryptodev and ocf-talitos and even here i
get no better throughput its only 11.7Mbps! Why am I getting such a lower
throughputs?
Thank you so much everybody for helping out. Awaiting your replies to
proceed further.

Yeah, Kim wrote the driver,  but the in kernel one is more up to date ;-)
>
> Cheers,
> Davidm
>
> --
> David McCullough,      david_mccullough at mcafee.com,  Ph:+61 734352815
> McAfee - SnapGear      http://www.mcafee.com         http://www.uCdot.org
>



-- 
Thanks and Regards
R.Vasanth Ragavendran
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20110519/f6ba24c7/attachment-0003.html 


More information about the Users mailing list