HomeFreeBSD

Turning on IPSEC used to introduce a slight amount of performance

Description

Turning on IPSEC used to introduce a slight amount of performance
degradation (7%) for host host TCP connections over 10Gbps links,
even when there were no secuirty policies in place. There is no
change in performance on 1Gbps network links. Testing GENERIC vs.
GENERIC-NOIPSEC vs. GENERIC with this change shows that the new
code removes any overhead introduced by having IPSEC always in the
kernel.

Differential Revision: D3993
MFC after: 1 month
Sponsored by: Rubicon Communications (Netgate)

Details

Provenance
gnnAuthored on
Parents
rS290027: MFC r289269:
Branches
Unknown
Tags
Unknown