[Openswan Users] [Ocf-linux-users] IPSec L2tpv3 throughput low using Netkey kernel stack

Vasanth Ragavendran ragavendrapec at gmail.com
Thu May 19 23:18:40 EDT 2011

Thank you all so much for responding.

On Wed, May 18, 2011 at 7:02 PM, David McCullough <
david_mccullough at mcafee.com> wrote:

> Jivin Paul Wouters lays it down ...
> > On Tue, 17 May 2011, Kim Phillips wrote:
> >
> > >>> but when the Sec driver is configured as module into the kernel the
> module doesn;t get inserted
> > >>> gives segmentation fault and if the Sec driver is configured as
> non-module type the kernel doesn't
> > >>> bootsup at all!
> > >>
> > >> David might be able to help with this. The ubsec driver is mostly used
> on linksys/asus machines,
> > >> perhaps yours is slightly different?
> > >
> > > Based on the freescale URL posted to users at openswan, I assume you're
> > > referring to the "SEC23DRVRS" driver?  That is a standalone driver,
> > > and won't be of use unless you're prepared to write code to
> > > integrate it into your IPsec stack.
> > >
Yeah i was mentioning about SEC23DRVRS apologies for mentioning it in short
and as Paul has asked to test with a lower MTU say 1400, the thruput worsens
i get only
4.71Mbps however with MTU being 1500 i get the thruput as 14.7Mbps.

> > Known working (to me at least) IPsec offload configuration for the
> > > 8315 should be NETKEY with CONFIG_CRYPTO_DEV_TALITOS configured in
> > > a vanilla kernel.  To be able to tell whether h/w crypto offload is
> > > in operation, see 'grep talitos /proc/interrupts' run.
> >
As Kim had mentioned I had loaded the CONFIG_CRYPTO_DEV_TALITOS as a module
with the module in the kernel i am getting a lower throughput! I am getting
only 13.4Mbps however without the module inserted i get 14.7Mbps how could
this be possible and the results sounds really ridiculous to me! And when
the CONFIG_CRYPTO_DEV_TALITOS is loaded i am able to view it using grep
talitos /proc/interrupts. so the hardware accelerator is getting used
however resulting in a lower throughput! That's absurd am I missing
something here?

> Ah, i thought he meant the ubsec one. Talitos I believe is also supported
> with OCF and KLIPS
> > IPsec, but I'm sure David can confirm that.
> I tried even with KLIPS and ocf,cryptodev and ocf-talitos and even here i
get no better throughput its only 11.7Mbps! Why am I getting such a lower
Thank you so much everybody for helping out. Awaiting your replies to
proceed further.

Yeah, Kim wrote the driver,  but the in kernel one is more up to date ;-)
> Cheers,
> Davidm
> --
> David McCullough,      david_mccullough at mcafee.com,  Ph:+61 734352815
> McAfee - SnapGear      http://www.mcafee.com         http://www.uCdot.org

Thanks and Regards
R.Vasanth Ragavendran
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.openswan.org/pipermail/users/attachments/20110519/f6ba24c7/attachment-0003.html 

More information about the Users mailing list