Subject: Re: IPsec performance
To: Jun-ichiro itojun Hagino <itojun@iijlab.net>
From: Secret Asian Man <cchen@nougat.org>
List: tech-security
Date: 07/19/2000 12:16:40
  by mail.netbsd.org with SMTP; 19 Jul 2000 19:16:42 -0000
	id 2DE08640A; Wed, 19 Jul 2000 12:16:41 -0700 (PDT)
Date: Wed, 19 Jul 2000 12:16:40 -0700
From: Secret Asian Man <cchen@nougat.org>
To: Jun-ichiro itojun Hagino <itojun@iijlab.net>
Cc: Ignatios Souvatzis <ignatios@cs.uni-bonn.de>, tls@rek.tjls.com,
	tech-security@netbsd.org, tech-net@netbsd.org, tech-kern@netbsd.org
Subject: Re: IPsec performance
Message-ID: <20000719121640.A7989@marzipan.nougat.org>
References: <20000719103407.D29090@theory.cs.uni-bonn.de> <200007191151.e6JBp3q01594@itojun.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
In-Reply-To: <200007191151.e6JBp3q01594@itojun.org>; from itojun@iijlab.net on Wed, Jul 19, 2000 at 08:51:02PM +0900

On Wed, Jul 19, 2000 at 08:51:02PM +0900, Jun-ichiro itojun Hagino wrote:
> 
> >> 	basically, blowfish uses very big intermediate data and we cant
> >> 	hold it on the stack.  we endup using static memory pool and
> >> 	hence we need spl locks.  we'll try to correct it.
> >Thats specific to blowfish?
> 
> 	yes.

I'm not quite sure; With DES between two 466Mhz Celerons with 100basetx-fdx betwixt them, I'm only seeing (at best) 1.8MB/sec...

With CAST-128 I'm seeing around 1.2MB/sec...

This is using -current, with a FTP transfer which yields 8MB/sec in non-encrypted mode...

?

-- 
Christopher Kyin-hwa Chen <cchen@nougat.org>
<http://www.nougat.org/~cchen/>
"Hail to the king, baby." --Ash