Live data from Hacker News

PfSense 2.5 and AES-NI

netgate.com

1–10 of 90 posts

Re: PfSense 2.5 and AES-NI

#3
If I had to guess, I'd say Netgate is working on an SD-WAN service of sorts. Many players in this market are displacing the edge firewall, and offering a built-in service of their own or in partnership with a third-party might be a smart move.

Re: PfSense 2.5 and AES-NI

#5

Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.

If this was a move to sell more hardware, why wouldn't we make the decision for 2.4 (which is imminent) rather than 2.5, which is based on FreeBSD 12, when 12.0R isn't even scheduled?

Re: PfSense 2.5 and AES-NI

#6
post #3

If I had to guess, I'd say Netgate is working on an SD-WAN service of sorts. Many players in this market are displacing the edge firewall, and offering a built-in service of their own or in partnership with a third-party might be a smart move.

What if we just added and SD-WAN implementation to pfSense?

Re: PfSense 2.5 and AES-NI

#7
post #5

Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.

If this was a move to sell more hardware, why wouldn't we make the decision for 2.4 (which is imminent) rather than 2.5, which is based on FreeBSD 12, when 12.0R isn't even scheduled?

[deleted]

Re: PfSense 2.5 and AES-NI

#8
post #4

Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.

Indeed, AES-NI is very rare. Few computers if any have it. Edit: /s ... ?!

I might be mistaken, but I thought it was in every non pentium/celeron/atom chip after 2010 and every chip after 2015 with some extensions.

My desktop and laptop have them and they're mid-high end but not upper high end.

Re: PfSense 2.5 and AES-NI

#9
post #4

Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.

Indeed, AES-NI is very rare. Few computers if any have it. Edit: /s ... ?!

Why do you say that? According to [1], AES-NI is not that rare.

[1] https://en.wikipedia.org/wiki/AES_instruction_set

Re: PfSense 2.5 and AES-NI

#10
TL, DR: If you are building a pfSense box with an x86 chip made in the past ~7 years [1], stop reading and carry on.

Those of you on a power budget, and want e.g. VPN support at closer to wire speeds, you're being advised to select a CPU with AES-NI to get hardware crypto offload. It's great we have software crypto in the first place, but under load it's likely to put a cap on your max throughput.

Kudos to pfSense/Netgate announcing this ahead of time.

[1] https://en.wikipedia.org/wiki/AES_instruction_set#Supporting...

Post reply on HN