PfSense 2.5 and AES-NI
netgate.com
PfSense 2.5 and AES-NI
1–10 of 90 posts
Re: PfSense 2.5 and AES-NI
#2Re: PfSense 2.5 and AES-NI
#3Re: PfSense 2.5 and AES-NI
#4Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.
Edit: /s ... ?!
Re: PfSense 2.5 and AES-NI
#5Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.
Re: PfSense 2.5 and AES-NI
#6If I had to guess, I'd say Netgate is working on an SD-WAN service of sorts. Many players in this market are displacing the edge firewall, and offering a built-in service of their own or in partnership with a third-party might be a smart move.
Re: PfSense 2.5 and AES-NI
#7Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.
If this was a move to sell more hardware, why wouldn't we make the decision for 2.4 (which is imminent) rather than 2.5, which is based on FreeBSD 12, when 12.0R isn't even scheduled?
Re: PfSense 2.5 and AES-NI
#8Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.
Indeed, AES-NI is very rare. Few computers if any have it. Edit: /s ... ?!
My desktop and laptop have them and they're mid-high end but not upper high end.
Re: PfSense 2.5 and AES-NI
#9Sounds like a move to sell more hardware. My pfsense barely does any crypto. This will push me over to openbsd.
Indeed, AES-NI is very rare. Few computers if any have it. Edit: /s ... ?!
Re: PfSense 2.5 and AES-NI
#10Those of you on a power budget, and want e.g. VPN support at closer to wire speeds, you're being advised to select a CPU with AES-NI to get hardware crypto offload. It's great we have software crypto in the first place, but under load it's likely to put a cap on your max throughput.
Kudos to pfSense/Netgate announcing this ahead of time.
[1] https://en.wikipedia.org/wiki/AES_instruction_set#Supporting...