Community discussions

MikroTik App
 
User avatar
carl0s
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Thu Jun 25, 2009 7:18 pm

SSTP hardware acceleration?

Fri May 05, 2017 11:32 pm

Hi. The new affordable routers with 'IPSec hardware encryption acceleration' (RB750Gr3).

.. can the hardware acceleration work for SSTP as well? or only IPSec?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: SSTP hardware acceleration?

Mon May 08, 2017 8:02 am

Hardware acceleration works only with ipsec.
 
ajack46
newbie
Posts: 37
Joined: Tue Mar 28, 2017 9:08 am

Re: SSTP hardware acceleration?

Mon May 08, 2017 10:00 am

Will work only for IPsec
 
User avatar
doneware
Trainer
Trainer
Posts: 647
Joined: Mon Oct 08, 2012 8:39 pm
Location: Hungary

Re: SSTP hardware acceleration?

Mon May 08, 2017 11:13 am

Hardware acceleration works only with ipsec.
just asking, why? As far as i know, usually the HW assists the cyphering, which is in this case AES (CBC or CTR) up to 256bits.
so what i would think it's just the code running on the CPU (read: current SSTP implementation) that doesn't use the hw capabilities.
does this sound reasonable (although it will not change the overall outcome of the discussion)?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: SSTP hardware acceleration?

Mon May 08, 2017 11:22 am

Because SSTP uses regular SSL lib which does not support HW acceleration. But it is possible that in future SSTP will also use HW enc.
 
User avatar
nz_monkey
Forum Guru
Forum Guru
Posts: 2104
Joined: Mon Jan 14, 2008 1:53 pm
Location: Over the Rainbow
Contact:

Re: SSTP hardware acceleration?

Mon May 08, 2017 12:36 pm

Because SSTP uses regular SSL lib which does not support HW acceleration. But it is possible that in future SSTP will also use HW enc.
Image

Everything happens in the future ;)
 
User avatar
carl0s
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Thu Jun 25, 2009 7:18 pm

Re: SSTP hardware acceleration?

Tue May 23, 2017 1:41 pm

Yes I did wonder the same. The hardware does encryption and usually with VPN types you can specify the encryption type, so long as we find one that is common between SSTP and what the hardware offers..

Anyway, yes, the Future... lots of things take a long time around here don't they :-)

It's just that SSTP is so firewall friendly.. I can send out small Hex boxes and not worry about firewalls being in the way.
 
idlemind
Forum Guru
Forum Guru
Posts: 1146
Joined: Fri Mar 24, 2017 11:15 pm
Location: USA

Re: SSTP hardware acceleration?

Tue Jun 20, 2017 5:47 pm

I wonder if the CHR sees increased performance on hypervisors with AES acceleration passthrough. Anyone have a pair of licensed units that could comment?
 
User avatar
mrz
MikroTik Support
MikroTik Support
Posts: 7056
Joined: Wed Feb 07, 2007 12:45 pm
Location: Latvia
Contact:

Re: SSTP hardware acceleration?

Wed Jun 21, 2017 11:43 am

from 6.39 changelog:
*) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;

So yes, CHR will have increased AES performance if v6.39 is installed, but this only works with IPSec, not SSTP.
 
User avatar
carl0s
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Thu Jun 25, 2009 7:18 pm

Re: SSTP hardware acceleration?

Wed Jun 21, 2017 11:49 am

from 6.39 changelog:
*) ipsec - enable aes-ni on i386 and x64 for cbc, ctr and gcm modes;

So yes, CHR will have increased AES performance if v6.39 is installed, but this only works with IPSec, not SSTP.

It would be super cool if you guys would work on rebuilding the SSTP stuff to use the hardware crypto :)
 
idlemind
Forum Guru
Forum Guru
Posts: 1146
Joined: Fri Mar 24, 2017 11:15 pm
Location: USA

Re: SSTP hardware acceleration?

Wed Jun 21, 2017 3:37 pm

Thanks mrz!
 
mywayteam
just joined
Posts: 2
Joined: Sun Dec 03, 2023 6:56 pm

Re: SSTP hardware acceleration?

Sun Dec 03, 2023 7:06 pm

Bump Up!
Any plans to implement it?

Who is online

Users browsing this forum: No registered users and 4 guests